Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1281213

Re: [PATCH] xen-pciback: fix up cleanup path when alloc fails

Path csiph.com!eternal-september.org!feeder.eternal-september.org!aioe.org!bofh.it!news.nic.it!robomod
From Doug Goldstein <cardoe@cardoe.com>
Newsgroups linux.kernel
Subject Re: [PATCH] xen-pciback: fix up cleanup path when alloc fails
Date Tue, 01 Dec 2015 22:00:02 +0100
Message-ID <qB0bM-6as-17@gated-at.bofh.it> (permalink)
References <qzbuG-1By-23@gated-at.bofh.it> <qAYMF-5kA-5@gated-at.bofh.it> <qB0bM-6as-19@gated-at.bofh.it>
X-Original-To Konrad Rzeszutek Wilk <konrad.wilk@oracle.com>
Dkim-Signature v=1; a=rsa-sha256; c=relaxed/relaxed; d=cardoe-com.20150623.gappssmtp.com; s=20150623; h=subject:to:references:cc:from:message-id:date:user-agent :mime-version:in-reply-to:content-type; bh=aQYrOEvaHO5lvyh5uqZ0kjvx3rsrJivCoHsjQe4xN+A=; b=h+uSlsS/uP9v1P6udvcln8HQywM9fptaKpjFxWyLZPsgyfIX+M6YKp6rmeIieUIEZb UvWsje+mnzZ55oB37wfck3X0+yYc5rsFIQX3gsnu+Va46O29T1hfFAfuuAI6jhm+qdLe tq5MtpJlyGEbmBmgEWrxTmtIJRzC18AHvx8BaOp1Q2/6XFfYuxtUIfr0nh8/FNAeYle0 HN6yGLLqM76xe2W+2pK5GHO6ZqLm5Di/vNp9N06Z6WNU3fd9RbxdFAvNedB98fzhr+CG xUEjcFzTgPeSBvOBjPmsKOi42YTm3QnO8F8ImkS4UwXNx2ZmEeWyJWEWmZm914QTm3mX MIUA==
X-Google-Dkim-Signature v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20130820; h=x-gm-message-state:subject:to:references:cc:from:message-id:date :user-agent:mime-version:in-reply-to:content-type; bh=aQYrOEvaHO5lvyh5uqZ0kjvx3rsrJivCoHsjQe4xN+A=; b=dPHQjb1aBR6Mn4nIA7rVTXLOD3QWEnlznrkRkok0EMmNWpJozIM+6pjkxCx2B7fka6 baFZmjj9tu+GRJ06QOa0hL5O0EM9agk3hwq5spg+5mn9qGqLLKROkyJIgIkyMm00YjUO eXKtHyJIYCnK6uSMNp044FDn5TEl2/HGVys7/qnPtCXZAzpJDTTChvNEvYlmPDZSF0uA uwWcrEC61qk1ty7kydcGaiIfhn5aSqmWiYNyVgvEVKp4FL/GctOp3NIMeXvSyWIxBE2t llIHPtNKES/HUyqlcAY/l0+oJLQ2z3SpfJoM16bL/aBcqNSfFQB6KrPUKycNuoIzU9bP hHCw==
X-Gm-Message-State ALoCoQkZezVJrixrcRi7apaIUUOnKh8Ox/5TNXCAsnPVYfHt2XiAH8wsXbbpoI6bhnIL4XC3mpUt
X-Received by 10.129.76.200 with SMTP id z191mr32630103ywa.247.1449003428141; Tue, 01 Dec 2015 12:57:08 -0800 (PST)
X-Enigmail-Draft-Status N1110
User-Agent Mozilla/5.0 (Macintosh; Intel Mac OS X 10.11; rv:38.0) Gecko/20100101 Thunderbird/38.3.0
MIME-Version 1.0
Content-Type multipart/signed; micalg=pgp-sha512; protocol="application/pgp-signature"; boundary="FJrWDUfBwJuGdXCK968KuCSHXDM2OXEV7"
Sender robomod@news.nic.it
List-ID <linux-kernel.vger.kernel.org>
X-Mailing-List linux-kernel@vger.kernel.org
Approved robomod@news.nic.it
Lines 107
Organization linux.* mail to news gateway
X-Original-Cc xen-devel@lists.xenproject.org, linux-kernel@vger.kernel.org, Bob Liu <bob.liu@oracle.com>, Paul Durrant <paul.durrant@citrix.com>, Wei Liu <wei.liu2@citrix.com>, David Vrabel <david.vrabel@citrix.com>, Boris Ostrovsky <boris.ostrovsky@oracle.com>, Jonathan Creekmore <jonathan.creekmore@gmail.com>
X-Original-Date Tue, 1 Dec 2015 14:54:33 -0600
X-Original-Message-ID <565E0909.2010009@cardoe.com>
X-Original-References <1448569959-7245-1-git-send-email-cardoe@cardoe.com> <20151201164717.GA5032@char.us.oracle.com> <20151201193517.GA32573@char.us.oracle.com>
X-Original-Sender linux-kernel-owner@vger.kernel.org
Xref csiph.com linux.kernel:1281213

Show key headers only | View raw


[Multipart message — attachments visible in raw view] - view raw

On 12/1/15 1:35 PM, Konrad Rzeszutek Wilk wrote:
> On Tue, Dec 01, 2015 at 11:47:17AM -0500, Konrad Rzeszutek Wilk wrote:
>> On Thu, Nov 26, 2015 at 02:32:39PM -0600, Doug Goldstein wrote:
>>> When allocating a pciback device fails, avoid the possibility of a
>>> use after free.
>>
>> Reviewed-by: Konrad Rzeszutek Wilk <konrad.wilk@oracle.com>
>>
>> Ugh, and it looks like xen-blkfront has the same issue.
> 
> <whew> Nope. No problems there.
> 
> The ->probe if it fails (so xenbus_dev_probe returns the error)
> ends up in the 'probe_failed' label in really_probe which takes care by doing:
> 
> dev_set_drvdata(dev, NULL);
> 
> Wheew!
> 
> either way the patch should go in, but the 'possibility' should
> be perhaps removed? Unless there is some other path I missed?

I put 'possibility' in there because it will only happen when the
function returns failure. I was also trying to not make it sound panicky
I guess. I can resubmit the patch with that word dropped if that's
desirable.

> 
>>
>>>
>>> Reported-by: Jonathan Creekmore <jonathan.creekmore@gmail.com>
>>> Signed-off-by: Doug Goldstein <cardoe@cardoe.com>
>>> ---
>>>  drivers/xen/xen-pciback/xenbus.c | 4 +++-
>>>  1 file changed, 3 insertions(+), 1 deletion(-)
>>>
>>> diff --git a/drivers/xen/xen-pciback/xenbus.c b/drivers/xen/xen-pciback/xenbus.c
>>> index 98bc345..4843741 100644
>>> --- a/drivers/xen/xen-pciback/xenbus.c
>>> +++ b/drivers/xen/xen-pciback/xenbus.c
>>> @@ -44,7 +44,6 @@ static struct xen_pcibk_device *alloc_pdev(struct xenbus_device *xdev)
>>>  	dev_dbg(&xdev->dev, "allocated pdev @ 0x%p\n", pdev);
>>>  
>>>  	pdev->xdev = xdev;
>>> -	dev_set_drvdata(&xdev->dev, pdev);
>>>  
>>>  	mutex_init(&pdev->dev_lock);
>>>  
>>> @@ -58,6 +57,9 @@ static struct xen_pcibk_device *alloc_pdev(struct xenbus_device *xdev)
>>>  		kfree(pdev);
>>>  		pdev = NULL;
>>>  	}
>>> +
>>> +	dev_set_drvdata(&xdev->dev, pdev);
>>> +
>>>  out:
>>>  	return pdev;
>>>  }
>>> -- 
>>> 2.4.10
>>>


-- 
Doug Goldstein

Back to linux.kernel | Previous | Next | Find similar | Unroll thread


Thread

Re: [PATCH] xen-pciback: fix up cleanup path when alloc fails Doug Goldstein <cardoe@cardoe.com> - 2015-12-01 22:00 +0100

csiph-web