Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1446020

[PATCH][v2] timekeeping: Fix memory overwrite of sleep_time_bin array

From Chen Yu <yu.c.chen@intel.com>
Newsgroups linux.kernel
Subject [PATCH][v2] timekeeping: Fix memory overwrite of sleep_time_bin array
Date 2016-07-19 06:50 +0200
Message-ID <rWv8J-7LS-11@gated-at.bofh.it> (permalink)
Organization linux.* mail to news gateway

Show all headers | View raw


It is reported the hibernation fails at 2nd attempt, which
hangs at hibernate() -> syscore_resume() -> i8237A_resume()
-> claim_dma_lock(), because the lock has already been taken.
However there is actually no other process would like to grab
this lock on that problematic platform.

Further investigation shows that, the problem is caused by setting
/sys/power/pm_trace to 1 before the 1st hibernation, since once
pm_trace is enabled, the rtc becomes an unmeaningful value after resumed,
which might bring a significant long sleep time in timekeeping_resume,
thus in tk_debug_account_sleep_time, if the bit31 happened to be set to 1,
the fls might return 32 and then we add 1 to sleep_time_bin[32], which
caused a memory overwritten. As System.map shows:

ffffffff81c9d080 b sleep_time_bin
ffffffff81c9d100 B dma_spin_lock

Thus set the dma_spin_lock.val to 1, which caused this problem.

To fix this problem, we ignore those abnormal sleep time,
since no one would like to sleep that long.

Cc: Stable <stable@vger.kernel.org> # 3.17+
Suggested-by: Rafael J. Wysocki <rafael.j.wysocki@intel.com>
Reported-and-tested-by: Janek Kozicki <cosurgi@gmail.com>
Signed-off-by: Chen Yu <yu.c.chen@intel.com>
---
 kernel/time/timekeeping_debug.c | 4 +++-
 1 file changed, 3 insertions(+), 1 deletion(-)

diff --git a/kernel/time/timekeeping_debug.c b/kernel/time/timekeeping_debug.c
index f6bd652..b164bb9 100644
--- a/kernel/time/timekeeping_debug.c
+++ b/kernel/time/timekeeping_debug.c
@@ -24,6 +24,7 @@
 #include "timekeeping_internal.h"
 
 static unsigned int sleep_time_bin[32] = {0};
+#define MAX_SLEEP_TIME 0x7fffffff
 
 static int tk_debug_show_sleep_time(struct seq_file *s, void *data)
 {
@@ -69,6 +70,7 @@ late_initcall(tk_debug_sleep_time_init);
 
 void tk_debug_account_sleep_time(struct timespec64 *t)
 {
-	sleep_time_bin[fls(t->tv_sec)]++;
+	if ((t->tv_sec >= 0) && (t->tv_sec <= MAX_SLEEP_TIME))
+		sleep_time_bin[fls(t->tv_sec)]++;
 }
 
-- 
2.7.4

Back to linux.kernel | Previous | NextNext in thread | Find similar | Unroll thread


Thread

[PATCH][v2] timekeeping: Fix memory overwrite of sleep_time_bin array Chen Yu <yu.c.chen@intel.com> - 2016-07-19 06:50 +0200
  Re: [PATCH][v2] timekeeping: Fix memory overwrite of sleep_time_bin  array Thomas Gleixner <tglx@linutronix.de> - 2016-07-19 10:40 +0200
    Re: [PATCH][v2] timekeeping: Fix memory overwrite of sleep_time_bin  array Chen Yu <yu.c.chen@intel.com> - 2016-07-19 11:00 +0200
      Re: [PATCH][v2] timekeeping: Fix memory overwrite of sleep_time_bin  array Thomas Gleixner <tglx@linutronix.de> - 2016-07-19 12:50 +0200
        Re: [PATCH][v2] timekeeping: Fix memory overwrite of sleep_time_bin  array Chen Yu <yu.c.chen@intel.com> - 2016-07-20 13:00 +0200
          Re: [PATCH][v2] timekeeping: Fix memory overwrite of sleep_time_bin array "Rafael J. Wysocki" <rjw@rjwysocki.net> - 2016-07-20 15:00 +0200
            RE: [PATCH][v2] timekeeping: Fix memory overwrite of sleep_time_bin  array "Chen, Yu C" <yu.c.chen@intel.com> - 2016-07-20 19:00 +0200

csiph-web