Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1204487

Re: [PATCH] ipc,sem: fix use after free on IPC_RMID after a task using same semaphore set exits

Path csiph.com!eternal-september.org!feeder.eternal-september.org!aioe.org!bofh.it!news.nic.it!robomod
From Manfred Spraul <manfred@colorfullife.com>
Newsgroups linux.kernel
Subject Re: [PATCH] ipc,sem: fix use after free on IPC_RMID after a task using same semaphore set exits
Date Mon, 10 Aug 2015 21:10:01 +0200
Message-ID <pW0Cl-6RM-29@gated-at.bofh.it> (permalink)
References <pUTjA-5Qk-7@gated-at.bofh.it> <pVCTn-4Kz-3@gated-at.bofh.it> <pVXl8-21m-25@gated-at.bofh.it>
X-Original-To "Herton R. Krzesinski" <herton@redhat.com>
X-Google-Dkim-Signature v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20130820; h=x-gm-message-state:subject:to:references:cc:from:message-id:date :user-agent:mime-version:in-reply-to:content-type :content-transfer-encoding; bh=sT5n1kHl9YUuo7gQyqr5Ny6YC6itP9YNJcKgcmX1uQI=; b=DWCuhVkjWYxeg/yqxddxLipbqSeaRSfedOD6t0R6aCADtR2xSuDdECbIulfysXWFho tcRbX//mhHjwHAbFZTG7QVagn1aqNr5OkP7mJsYCJL1tbOHeW/xgmuWBt56nDcxt2I1L vVc7zA1wdw1Wyl8hjDzHRNImwDge9qn713B76dDYp/w5JHST8tPjSmNQotbYMYcOHPzt iJoPyrRbGUYpyC5ivc2PBe7GtfQXMIXjdYl1MMilLtKxrOwSZGF96qYzDueVdcKFYR/K iVp1xomErGaCNBXZnO/+KdOXGlQzb4ayRKepjuM+c7AdPXjHPfYQEapLeQa+duI7G/kj U+RA==
X-Gm-Message-State ALoCoQmLB7GZFeJFk4z/cJllqyM3FUnCZS6YrF13Z6p5pp/Uhc+8A7c5GB9f/xZVqQKDDdXZyAwY
X-Received by 10.180.95.10 with SMTP id dg10mr18455327wib.5.1439233334632; Mon, 10 Aug 2015 12:02:14 -0700 (PDT)
User-Agent Mozilla/5.0 (X11; Linux x86_64; rv:38.0) Gecko/20100101 Thunderbird/38.1.0
MIME-Version 1.0
Content-Type text/plain; charset=windows-1252; format=flowed
Content-Transfer-Encoding 7bit
Sender robomod@news.nic.it
List-ID <linux-kernel.vger.kernel.org>
X-Mailing-List linux-kernel@vger.kernel.org
Approved robomod@news.nic.it
Lines 65
Organization linux.* mail to news gateway
X-Original-Cc linux-kernel@vger.kernel.org, Andrew Morton <akpm@linux-foundation.org>, Davidlohr Bueso <dave@stgolabs.net>, Rafael Aquini <aquini@redhat.com>, Joe Perches <joe@perches.com>, Aristeu Rozanski <aris@redhat.com>, djeffery@redhat.com
X-Original-Date Mon, 10 Aug 2015 21:02:11 +0200
X-Original-Message-ID <55C8F533.1090007@colorfullife.com>
X-Original-References <1438967375-14877-1-git-send-email-herton@redhat.com> <55C79294.2010006@colorfullife.com> <20150810153147.GA3540@dhcppc4.redhat.com>
X-Original-Sender linux-kernel-owner@vger.kernel.org
Xref csiph.com linux.kernel:1204487

Show key headers only | View raw


Hi Herton,

On 08/10/2015 05:31 PM, Herton R. Krzesinski wrote:
> Well without the synchronize_rcu() and with the semid list loop fix I was still
> able to get issues, and I thought the problem is related to racing with IPC_RMID
> on freeary again. This is one scenario I would imagine:
>
>                 A                                                  B
>
> freeary()
>    list_del(&un->list_id)
>    spin_lock(&un->ulp->lock)
>    un->semid = -1
>    list_del_rcu(&un->list_proc)
>      __list_del_entry(&un->list_proc)
>        __list_del(entry->prev, entry->next)      exit_sem()
>          next->prev = prev;                        ...
>          prev->next = next;                        ...
>          ...                                       un = list_entry_rcu(ulp->list_proc.next...)
>      (&un->list_proc)->prev = LIST_POISON2         if (&un->list_proc == &ulp->list_proc) <true, last un removed by thread A>
>    ...                                             kfree(ulp)
>    spin_unlock(&un->ulp->lock) <---- bug
>
> Now that is a very tight window, but I had problems even when I tried this patch
> first:
>
> (...)
> -               if (&un->list_proc == &ulp->list_proc)
> -                       semid = -1;
> -                else
> -                       semid = un->semid;
> +               if (&un->list_proc == &ulp->list_proc) {
> +                       rcu_read_unlock();
What about:
+ spin_unlock_wait(&ulp->lock);
> +                       break;
> +               }
> +               spin_lock(&ulp->lock);
> +               semid = un->semid;
> +               spin_unlock(&ulp->lock);
>
> +               /* exit_sem raced with IPC_RMID, nothing to do */
>                  if (semid == -1) {
>                          rcu_read_unlock();
> -                       break;
> +                       synchronize_rcu();
> +                       continue;
>                  }
> (...)
>
> So even with the bad/uneeded synchronize_rcu() which I had placed there, I could
> still get issues (however the testing on patch above was on an older kernel than
> latest upstream, from RHEL 6, I can test without synchronize_rcu() on latest
> upstream, however the affected code is the same). That's when I thought of
> scenario above. I was able to get this oops:
Adding sleep() usually help, too. But it is ugly, so let's try to 
understand the race and to fix it.

Best regards,
     Manfred
--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

Back to linux.kernel | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread


Thread

[PATCH] ipc,sem: fix use after free on IPC_RMID after a task using same semaphore set exits "Herton R. Krzesinski" <herton@redhat.com> - 2015-08-07 19:10 +0200
  Re: [PATCH] ipc,sem: fix use after free on IPC_RMID after a task  using same semaphore set exits Aristeu Rozanski <aris@redhat.com> - 2015-08-07 21:40 +0200
  Re: [PATCH] ipc,sem: fix use after free on IPC_RMID after a task  using same semaphore set exits Manfred Spraul <manfred@colorfullife.com> - 2015-08-09 19:50 +0200
    Re: [PATCH] ipc,sem: fix use after free on IPC_RMID after a task  using same semaphore set exits "Herton R. Krzesinski" <herton@redhat.com> - 2015-08-10 17:40 +0200
      Re: [PATCH] ipc,sem: fix use after free on IPC_RMID after a task  using same semaphore set exits Manfred Spraul <manfred@colorfullife.com> - 2015-08-10 21:10 +0200
        Re: [PATCH] ipc,sem: fix use after free on IPC_RMID after a task  using same semaphore set exits "Herton R. Krzesinski" <herton@redhat.com> - 2015-08-11 18:50 +0200

csiph-web