Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1297975

[PATCH 3.2 75/77] af_unix: fix a fatal race with bit fields

From Ben Hutchings <ben@decadent.org.uk>
Newsgroups linux.kernel
Subject [PATCH 3.2 75/77] af_unix: fix a fatal race with bit fields
Date 2015-12-24 17:10 +0100
Message-ID <qJgCL-u9-29@gated-at.bofh.it> (permalink)
References <qJgjn-6R-3@gated-at.bofh.it>
Organization linux.* mail to news gateway

Show all headers | View raw


3.2.75-rc1 review patch.  If anyone has any objections, please let me know.

------------------

From: Eric Dumazet <eric.dumazet@gmail.com>

commit 60bc851ae59bfe99be6ee89d6bc50008c85ec75d upstream.

Using bit fields is dangerous on ppc64/sparc64, as the compiler [1]
uses 64bit instructions to manipulate them.
If the 64bit word includes any atomic_t or spinlock_t, we can lose
critical concurrent changes.

This is happening in af_unix, where unix_sk(sk)->gc_candidate/
gc_maybe_cycle/lock share the same 64bit word.

This leads to fatal deadlock, as one/several cpus spin forever
on a spinlock that will never be available again.

A safer way would be to use a long to store flags.
This way we are sure compiler/arch wont do bad things.

As we own unix_gc_lock spinlock when clearing or setting bits,
we can use the non atomic __set_bit()/__clear_bit().

recursion_level can share the same 64bit location with the spinlock,
as it is set only with this spinlock held.

[1] bug fixed in gcc-4.8.0 :
http://gcc.gnu.org/bugzilla/show_bug.cgi?id=52080

Reported-by: Ambrose Feinstein <ambrose@google.com>
Signed-off-by: Eric Dumazet <edumazet@google.com>
Cc: Benjamin Herrenschmidt <benh@kernel.crashing.org>
Cc: Paul Mackerras <paulus@samba.org>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
---
 include/net/af_unix.h |  5 +++--
 net/unix/garbage.c    | 12 ++++++------
 2 files changed, 9 insertions(+), 8 deletions(-)

--- a/include/net/af_unix.h
+++ b/include/net/af_unix.h
@@ -54,9 +54,10 @@ struct unix_sock {
 	struct list_head	link;
 	atomic_long_t		inflight;
 	spinlock_t		lock;
-	unsigned int		gc_candidate : 1;
-	unsigned int		gc_maybe_cycle : 1;
 	unsigned char		recursion_level;
+	unsigned long		gc_flags;
+#define UNIX_GC_CANDIDATE	0
+#define UNIX_GC_MAYBE_CYCLE	1
 	struct socket_wq	peer_wq;
 	wait_queue_t		peer_wake;
 };
--- a/net/unix/garbage.c
+++ b/net/unix/garbage.c
@@ -185,7 +185,7 @@ static void scan_inflight(struct sock *x
 					 * have been added to the queues after
 					 * starting the garbage collection
 					 */
-					if (u->gc_candidate) {
+					if (test_bit(UNIX_GC_CANDIDATE, &u->gc_flags)) {
 						hit = true;
 						func(u);
 					}
@@ -254,7 +254,7 @@ static void inc_inflight_move_tail(struc
 	 * of the list, so that it's checked even if it was already
 	 * passed over
 	 */
-	if (u->gc_maybe_cycle)
+	if (test_bit(UNIX_GC_MAYBE_CYCLE, &u->gc_flags))
 		list_move_tail(&u->link, &gc_candidates);
 }
 
@@ -315,8 +315,8 @@ void unix_gc(void)
 		BUG_ON(total_refs < inflight_refs);
 		if (total_refs == inflight_refs) {
 			list_move_tail(&u->link, &gc_candidates);
-			u->gc_candidate = 1;
-			u->gc_maybe_cycle = 1;
+			__set_bit(UNIX_GC_CANDIDATE, &u->gc_flags);
+			__set_bit(UNIX_GC_MAYBE_CYCLE, &u->gc_flags);
 		}
 	}
 
@@ -344,7 +344,7 @@ void unix_gc(void)
 
 		if (atomic_long_read(&u->inflight) > 0) {
 			list_move_tail(&u->link, &not_cycle_list);
-			u->gc_maybe_cycle = 0;
+			__clear_bit(UNIX_GC_MAYBE_CYCLE, &u->gc_flags);
 			scan_children(&u->sk, inc_inflight_move_tail, NULL);
 		}
 	}
@@ -356,7 +356,7 @@ void unix_gc(void)
 	 */
 	while (!list_empty(&not_cycle_list)) {
 		u = list_entry(not_cycle_list.next, struct unix_sock, link);
-		u->gc_candidate = 0;
+		__clear_bit(UNIX_GC_CANDIDATE, &u->gc_flags);
 		list_move_tail(&u->link, &gc_inflight_list);
 	}
 

--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

Back to linux.kernel | Previous | NextPrevious in thread | Next in thread | Find similar | Unroll thread


Thread

[PATCH 3.2 00/77] 3.2.75-rc1 review Ben Hutchings <ben@decadent.org.uk> - 2015-12-24 16:50 +0100
  [PATCH 3.2 43/77] dm btree: fix leak of bufio-backed block in  btree_split_sibling error path Ben Hutchings <ben@decadent.org.uk> - 2015-12-24 17:00 +0100
  [PATCH 3.2 73/77] bluetooth: Validate socket address length in   sco_sock_bind(). Ben Hutchings <ben@decadent.org.uk> - 2015-12-24 17:00 +0100
  [PATCH 3.2 31/77] broadcom: fix PHY_ID_BCM5481 entry in the id table Ben Hutchings <ben@decadent.org.uk> - 2015-12-24 17:00 +0100
  [PATCH 3.2 08/77] USB: ti_usb_3410_502: Fix ID table size Ben Hutchings <ben@decadent.org.uk> - 2015-12-24 17:00 +0100
  [PATCH 3.2 04/77] ALSA: usb-audio: prevent CH345 multiport output  SysEx corruption Ben Hutchings <ben@decadent.org.uk> - 2015-12-24 17:00 +0100
  [PATCH 3.2 76/77] isdn_ppp: Add checks for allocation failure in  isdn_ppp_open() Ben Hutchings <ben@decadent.org.uk> - 2015-12-24 17:00 +0100
  [PATCH 3.2 18/77] USB: option: add XS Stick W100-2 from 4G Systems Ben Hutchings <ben@decadent.org.uk> - 2015-12-24 17:00 +0100
  [PATCH 3.2 28/77] fix sysvfs symlinks Ben Hutchings <ben@decadent.org.uk> - 2015-12-24 17:00 +0100
  [PATCH 3.2 56/77] mm, vmstat: allow WQ concurrency to discover  memory reclaim doesn't make any progress Ben Hutchings <ben@decadent.org.uk> - 2015-12-24 17:00 +0100
  [PATCH 3.2 22/77] net: ip6mr: fix static mfc/dev leaks on table  destruction Ben Hutchings <ben@decadent.org.uk> - 2015-12-24 17:00 +0100
  [PATCH 3.2 37/77] drm/ttm: Fixed a read/write lock imbalance Ben Hutchings <ben@decadent.org.uk> - 2015-12-24 17:00 +0100
  [PATCH 3.2 52/77] ipmi: move timer init to before irq is setup Ben Hutchings <ben@decadent.org.uk> - 2015-12-24 17:00 +0100
  [PATCH 3.2 50/77] ALSA: rme96: Fix unexpected volume reset after  rate changes Ben Hutchings <ben@decadent.org.uk> - 2015-12-24 17:00 +0100
  [PATCH 3.2 64/77] dccp: remove unnecessary codes in ipv6.c Ben Hutchings <ben@decadent.org.uk> - 2015-12-24 17:00 +0100
  [PATCH 3.2 68/77] sctp: update the netstamp_needed counter when  copying  sockets Ben Hutchings <ben@decadent.org.uk> - 2015-12-24 17:00 +0100
  [PATCH 3.2 16/77] xhci: Add XHCI_INTEL_HOST quirk Ben Hutchings <ben@decadent.org.uk> - 2015-12-24 17:00 +0100
  [PATCH 3.2 15/77] macvlan: fix leak in macvlan_handle_frame Ben Hutchings <ben@decadent.org.uk> - 2015-12-24 17:00 +0100
  [PATCH 3.2 65/77] ipv6: add complete rcu protection around np->opt Ben Hutchings <ben@decadent.org.uk> - 2015-12-24 17:00 +0100
  [PATCH 3.2 09/77] USB: ti_usb_3410_5052: Add Honeywell HGI80 ID Ben Hutchings <ben@decadent.org.uk> - 2015-12-24 17:00 +0100
  [PATCH 3.2 17/77] xhci: Workaround to get Intel xHCI reset  working more reliably Ben Hutchings <ben@decadent.org.uk> - 2015-12-24 17:00 +0100
  [PATCH 3.2 05/77] ALSA: usb-audio: work around CH345 input SysEx  corruption Ben Hutchings <ben@decadent.org.uk> - 2015-12-24 17:00 +0100
  [PATCH 3.2 67/77] atl1c: Improve driver not to do order 4  GFP_ATOMIC  allocation Ben Hutchings <ben@decadent.org.uk> - 2015-12-24 17:00 +0100
  [PATCH 3.2 19/77] usblp: do not set TASK_INTERRUPTIBLE before lock Ben Hutchings <ben@decadent.org.uk> - 2015-12-24 17:00 +0100
  [PATCH 3.2 55/77] parisc iommu: fix panic due to trying to  allocate too large region Ben Hutchings <ben@decadent.org.uk> - 2015-12-24 17:00 +0100
  [PATCH 3.2 62/77] net: ipmr: fix static mfc/dev leaks on table   destruction Ben Hutchings <ben@decadent.org.uk> - 2015-12-24 17:00 +0100
  [PATCH 3.2 30/77] vfs: Avoid softlockups with sendfile(2) Ben Hutchings <ben@decadent.org.uk> - 2015-12-24 17:00 +0100
  [PATCH 3.2 10/77] usb: musb: core: fix order of arguments to ulpi  write callback Ben Hutchings <ben@decadent.org.uk> - 2015-12-24 17:00 +0100
  [PATCH 3.2 59/77] snmp: Remove duplicate OUTMCAST stat increment Ben Hutchings <ben@decadent.org.uk> - 2015-12-24 17:00 +0100
  [PATCH 3.2 24/77] USB: cp210x: Remove CP2110 ID from  compatibility list Ben Hutchings <ben@decadent.org.uk> - 2015-12-24 17:00 +0100
  [PATCH 3.2 46/77] drm: Fix an unwanted master inheritance v2 Ben Hutchings <ben@decadent.org.uk> - 2015-12-24 17:00 +0100
    Re: [PATCH 3.2 46/77] drm: Fix an unwanted master inheritance v2 Thomas Hellstrom <thellstrom@vmware.com> - 2015-12-25 15:20 +0100
      Re: [PATCH 3.2 46/77] drm: Fix an unwanted master inheritance v2 Ben Hutchings <ben@decadent.org.uk> - 2015-12-26 05:40 +0100
  [PATCH 3.2 66/77] ipv6: sctp: implement sctp_v6_destroy_sock() Ben Hutchings <ben@decadent.org.uk> - 2015-12-24 17:00 +0100
  [PATCH 3.2 06/77] USB: serial: option: add support for Novatel  MiFi USB620L Ben Hutchings <ben@decadent.org.uk> - 2015-12-24 17:00 +0100
  [PATCH 3.2 71/77] sh_eth: fix kernel oops in skb_put() Ben Hutchings <ben@decadent.org.uk> - 2015-12-24 17:00 +0100
  [PATCH 3.2 14/77] mac80211: mesh: fix call_rcu() usage Ben Hutchings <ben@decadent.org.uk> - 2015-12-24 17:00 +0100
  [PATCH 3.2 49/77] usb: xhci: fix config fail of FS hub behind a  HS hub with MTT Ben Hutchings <ben@decadent.org.uk> - 2015-12-24 17:10 +0100
  [PATCH 3.2 54/77] vgaarb: fix signal handling in vga_get() Ben Hutchings <ben@decadent.org.uk> - 2015-12-24 17:10 +0100
  [PATCH 3.2 58/77] sh64: fix __NR_fgetxattr Ben Hutchings <ben@decadent.org.uk> - 2015-12-24 17:10 +0100
  [PATCH 3.2 70/77] net: add validation for the socket syscall  protocol  argument Ben Hutchings <ben@decadent.org.uk> - 2015-12-24 17:10 +0100
  [PATCH 3.2 40/77] wan/x25: Fix use-after-free in x25_asy_open_tty() Ben Hutchings <ben@decadent.org.uk> - 2015-12-24 17:10 +0100
  [PATCH 3.2 44/77] ipv4: igmp: Allow removing groups from a  removed interface Ben Hutchings <ben@decadent.org.uk> - 2015-12-24 17:10 +0100
  [PATCH 3.2 03/77] ALSA: usb-audio: add packet size quirk for the  Medeli DD305 Ben Hutchings <ben@decadent.org.uk> - 2015-12-24 17:10 +0100
  [PATCH 3.2 53/77] dm btree: fix bufio buffer leaks in  dm_btree_del() error path Ben Hutchings <ben@decadent.org.uk> - 2015-12-24 17:10 +0100
  [PATCH 3.2 74/77] af_unix: Revert 'lock_interruptible' in stream  receive  code Ben Hutchings <ben@decadent.org.uk> - 2015-12-24 17:10 +0100
  [PATCH 3.2 47/77] sched/core: Remove false-positive warning from  wake_up_process() Ben Hutchings <ben@decadent.org.uk> - 2015-12-24 17:10 +0100
  [PATCH 3.2 75/77] af_unix: fix a fatal race with bit fields Ben Hutchings <ben@decadent.org.uk> - 2015-12-24 17:10 +0100
  [PATCH 3.2 45/77] locking: Add WARN_ON_ONCE lock assertion Ben Hutchings <ben@decadent.org.uk> - 2015-12-24 17:10 +0100
  [PATCH 3.2 35/77] RDS: fix race condition when sending a message  on unbound socket Ben Hutchings <ben@decadent.org.uk> - 2015-12-24 17:10 +0100
  [PATCH 3.2 77/77] ppp, slip: Validate VJ compression slot  parameters completely Ben Hutchings <ben@decadent.org.uk> - 2015-12-24 17:10 +0100
  [PATCH 3.2 41/77] USB: whci-hcd: add check for dma mapping error Ben Hutchings <ben@decadent.org.uk> - 2015-12-24 17:10 +0100
  [PATCH 3.2 51/77] 9p: ->evict_inode() should kick out ->i_data,  not ->i_mapping Ben Hutchings <ben@decadent.org.uk> - 2015-12-24 17:10 +0100
  [PATCH 3.2 38/77] AHCI: Fix softreset failed issue of Port Multiplier Ben Hutchings <ben@decadent.org.uk> - 2015-12-24 17:10 +0100
  [PATCH 3.2 39/77] sata_sil: disable trim Ben Hutchings <ben@decadent.org.uk> - 2015-12-24 17:10 +0100
  [PATCH 3.2 36/77] nfs: if we have no valid attrs, then don't  declare the attribute cache valid Ben Hutchings <ben@decadent.org.uk> - 2015-12-24 17:10 +0100
  Re: [PATCH 3.2 00/77] 3.2.75-rc1 review Guenter Roeck <linux@roeck-us.net> - 2015-12-24 23:30 +0100
    Re: [PATCH 3.2 00/77] 3.2.75-rc1 review Ben Hutchings <ben@decadent.org.uk> - 2015-12-24 23:40 +0100

csiph-web