Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1223246

[PATCH 3.10 02/11] ipc/sem.c: update/correct memory barriers

From Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Newsgroups linux.kernel
Subject [PATCH 3.10 02/11] ipc/sem.c: update/correct memory barriers
Date 2015-09-12 01:20 +0200
Message-ID <q7FLR-7Un-37@gated-at.bofh.it> (permalink)
References <q7FiN-75P-3@gated-at.bofh.it>
Organization linux.* mail to news gateway

Show all headers | View raw


3.10-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Manfred Spraul <manfred@colorfullife.com>

commit 3ed1f8a99d70ea1cd1508910eb107d0edcae5009 upstream.

sem_lock() did not properly pair memory barriers:

!spin_is_locked() and spin_unlock_wait() are both only control barriers.
The code needs an acquire barrier, otherwise the cpu might perform read
operations before the lock test.

As no primitive exists inside <include/spinlock.h> and since it seems
noone wants another primitive, the code creates a local primitive within
ipc/sem.c.

With regards to -stable:

The change of sem_wait_array() is a bugfix, the change to sem_lock() is a
nop (just a preprocessor redefinition to improve the readability).  The
bugfix is necessary for all kernels that use sem_wait_array() (i.e.:
starting from 3.10).

Signed-off-by: Manfred Spraul <manfred@colorfullife.com>
Reported-by: Oleg Nesterov <oleg@redhat.com>
Acked-by: Peter Zijlstra (Intel) <peterz@infradead.org>
Cc: "Paul E. McKenney" <paulmck@linux.vnet.ibm.com>
Cc: Kirill Tkhai <ktkhai@parallels.com>
Cc: Ingo Molnar <mingo@redhat.com>
Cc: Josh Poimboeuf <jpoimboe@redhat.com>
Cc: Davidlohr Bueso <dave@stgolabs.net>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>

---
 ipc/sem.c |   20 ++++++++++++++++++--
 1 file changed, 18 insertions(+), 2 deletions(-)

--- a/ipc/sem.c
+++ b/ipc/sem.c
@@ -253,6 +253,16 @@ static void sem_rcu_free(struct rcu_head
 }
 
 /*
+ * spin_unlock_wait() and !spin_is_locked() are not memory barriers, they
+ * are only control barriers.
+ * The code must pair with spin_unlock(&sem->lock) or
+ * spin_unlock(&sem_perm.lock), thus just the control barrier is insufficient.
+ *
+ * smp_rmb() is sufficient, as writes cannot pass the control barrier.
+ */
+#define ipc_smp_acquire__after_spin_is_unlocked()	smp_rmb()
+
+/*
  * Wait until all currently ongoing simple ops have completed.
  * Caller must own sem_perm.lock.
  * New simple ops cannot start, because simple ops first check
@@ -275,6 +285,7 @@ static void sem_wait_array(struct sem_ar
 		sem = sma->sem_base + i;
 		spin_unlock_wait(&sem->lock);
 	}
+	ipc_smp_acquire__after_spin_is_unlocked();
 }
 
 /*
@@ -326,8 +337,13 @@ static inline int sem_lock(struct sem_ar
 
 		/* Then check that the global lock is free */
 		if (!spin_is_locked(&sma->sem_perm.lock)) {
-			/* spin_is_locked() is not a memory barrier */
-			smp_mb();
+			/*
+			 * We need a memory barrier with acquire semantics,
+			 * otherwise we can race with another thread that does:
+			 *	complex_count++;
+			 *	spin_unlock(sem_perm.lock);
+			 */
+			ipc_smp_acquire__after_spin_is_unlocked();
 
 			/* Now repeat the test of complex_count:
 			 * It can't change anymore until we drop sem->lock.


--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

Back to linux.kernel | Previous | NextPrevious in thread | Next in thread | Find similar | Unroll thread


Thread

[PATCH 3.10 00/11] 3.10.88-stable review Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2015-09-12 00:50 +0200
  [PATCH 3.10 10/11] crypto: caam - fix memory corruption in ahash_final_ctx Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2015-09-12 00:50 +0200
  [PATCH 3.10 03/11] mm/hwpoison: fix page refcount of unknown non LRU page Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2015-09-12 01:20 +0200
  [PATCH 3.10 04/11] perf: Fix fasync handling on inherited events Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2015-09-12 01:20 +0200
  [PATCH 3.10 09/11] libfc: Fix fc_fcp_cleanup_each_cmd() Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2015-09-12 01:20 +0200
  [PATCH 3.10 06/11] localmodconfig: Use Kbuild files too Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2015-09-12 01:20 +0200
  [PATCH 3.10 02/11] ipc/sem.c: update/correct memory barriers Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2015-09-12 01:20 +0200
  [PATCH 3.10 08/11] drm/radeon: add new OLAND pci id Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2015-09-12 01:20 +0200
  [PATCH 3.10 05/11] dm thin metadata: delete btrees when releasing metadata snapshot Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2015-09-12 01:20 +0200
  [PATCH 3.10 01/11] ipc,sem: fix use after free on IPC_RMID after a task using same semaphore set exits Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2015-09-12 01:20 +0200
  Re: [PATCH 3.10 00/11] 3.10.88-stable review Shuah Khan <shuahkh@osg.samsung.com> - 2015-09-12 03:10 +0200
  Re: [PATCH 3.10 00/11] 3.10.88-stable review Guenter Roeck <linux@roeck-us.net> - 2015-09-12 06:30 +0200
  Re: [PATCH 3.10 00/11] 3.10.88-stable review Sudip Mukherjee <sudipm.mukherjee@gmail.com> - 2015-09-12 09:30 +0200
    Re: [PATCH 3.10 00/11] 3.10.88-stable review Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2015-09-12 18:00 +0200
      Re: [PATCH 3.10 00/11] 3.10.88-stable review Max Filippov <jcmvbkbc@gmail.com> - 2015-09-12 18:30 +0200
        Re: [PATCH 3.10 00/11] 3.10.88-stable review Sudip Mukherjee <sudipm.mukherjee@gmail.com> - 2015-09-12 19:40 +0200
          Re: [PATCH 3.10 00/11] 3.10.88-stable review Guenter Roeck <linux@roeck-us.net> - 2015-09-12 20:00 +0200
            Re: [PATCH 3.10 00/11] 3.10.88-stable review Sudip Mukherjee <sudipm.mukherjee@gmail.com> - 2015-09-12 20:20 +0200
        Re: [PATCH 3.10 00/11] 3.10.88-stable review Sudip Mukherjee <sudipm.mukherjee@gmail.com> - 2015-09-14 11:10 +0200
          Re: [PATCH 3.10 00/11] 3.10.88-stable review Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2015-09-21 06:40 +0200
      Re: [PATCH 3.10 00/11] 3.10.88-stable review Sudip Mukherjee <sudipm.mukherjee@gmail.com> - 2015-09-12 19:50 +0200
      Re: [PATCH 3.10 00/11] 3.10.88-stable review Guenter Roeck <linux@roeck-us.net> - 2015-09-12 19:50 +0200

csiph-web