Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1509333

[PATCH 4.4 015/112] pstore/ramoops: fixup driver removal

From Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Newsgroups linux.kernel
Subject [PATCH 4.4 015/112] pstore/ramoops: fixup driver removal
Date 2016-10-26 15:10 +0200
Message-ID <sww7U-49u-57@gated-at.bofh.it> (permalink)
References <swvER-3Eq-3@gated-at.bofh.it>
Organization linux.* mail to news gateway

Show all headers | View raw


4.4-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Sebastian Andrzej Siewior <bigeasy@linutronix.de>

commit 4407de74df18ed405cc5998990004c813ccfdbde upstream.

A basic rmmod ramoops segfaults. Let's see why.

Since commit 34f0ec82e0a9 ("pstore: Correct the max_dump_cnt clearing of
ramoops") sets ->max_dump_cnt to zero before looping over ->przs but we
didn't use it before that either.

And since commit ee1d267423a1 ("pstore: add pstore unregister") we free
that memory on rmmod.

But even then, we looped until a NULL pointer or ERR. I don't see where
it is ensured that the last member is NULL. Let's try this instead:
simply error recovery and free. Clean up in error case where resources
were allocated. And then, in the free path, rely on ->max_dump_cnt in
the free path.

Cc: Anton Vorontsov <anton@enomsg.org>
Cc: Colin Cross <ccross@android.com>
Cc: Kees Cook <keescook@chromium.org>
Cc: Tony Luck <tony.luck@intel.com>
Cc: Namhyung Kim <namhyung@kernel.org>
Acked-by: Namhyung Kim <namhyung@kernel.org>
Signed-off-by: Sebastian Andrzej Siewior <bigeasy@linutronix.de>
Signed-off-by: Kees Cook <keescook@chromium.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>

---
 fs/pstore/ram.c |   17 ++++++++++++-----
 1 file changed, 12 insertions(+), 5 deletions(-)

--- a/fs/pstore/ram.c
+++ b/fs/pstore/ram.c
@@ -375,13 +375,14 @@ static void ramoops_free_przs(struct ram
 {
 	int i;
 
-	cxt->max_dump_cnt = 0;
 	if (!cxt->przs)
 		return;
 
-	for (i = 0; !IS_ERR_OR_NULL(cxt->przs[i]); i++)
+	for (i = 0; i < cxt->max_dump_cnt; i++)
 		persistent_ram_free(cxt->przs[i]);
+
 	kfree(cxt->przs);
+	cxt->max_dump_cnt = 0;
 }
 
 static int ramoops_init_przs(struct device *dev, struct ramoops_context *cxt,
@@ -406,7 +407,7 @@ static int ramoops_init_przs(struct devi
 			     GFP_KERNEL);
 	if (!cxt->przs) {
 		dev_err(dev, "failed to initialize a prz array for dumps\n");
-		goto fail_prz;
+		goto fail_mem;
 	}
 
 	for (i = 0; i < cxt->max_dump_cnt; i++) {
@@ -417,6 +418,11 @@ static int ramoops_init_przs(struct devi
 			err = PTR_ERR(cxt->przs[i]);
 			dev_err(dev, "failed to request mem region (0x%zx@0x%llx): %d\n",
 				cxt->record_size, (unsigned long long)*paddr, err);
+
+			while (i > 0) {
+				i--;
+				persistent_ram_free(cxt->przs[i]);
+			}
 			goto fail_prz;
 		}
 		*paddr += cxt->record_size;
@@ -424,7 +430,9 @@ static int ramoops_init_przs(struct devi
 
 	return 0;
 fail_prz:
-	ramoops_free_przs(cxt);
+	kfree(cxt->przs);
+fail_mem:
+	cxt->max_dump_cnt = 0;
 	return err;
 }
 
@@ -583,7 +591,6 @@ static int ramoops_remove(struct platfor
 	struct ramoops_context *cxt = &oops_cxt;
 
 	pstore_unregister(&cxt->pstore);
-	cxt->max_dump_cnt = 0;
 
 	kfree(cxt->pstore.buf);
 	cxt->pstore.bufsize = 0;

Back to linux.kernel | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread


Thread

[PATCH 4.4 000/112] 4.4.28-stable review Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-10-26 14:50 +0200
  [PATCH 4.4 061/112] NFSv4: Dont report revoked delegations as valid in nfs_have_delegation() Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-10-26 15:00 +0200
  [PATCH 4.4 084/112] irqchip/gicv3: Handle loop timeout proper Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-10-26 15:00 +0200
  [PATCH 4.4 028/112] powerpc/powernv: Use CPU-endian hub diag-data type in pnv_eeh_get_and_dump_hub_diag() Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-10-26 15:00 +0200
  [PATCH 4.4 051/112] ALSA: hda - Fix a failure of micmute led when having multi adcs Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-10-26 15:00 +0200
  [PATCH 4.4 074/112] Clarify locking of cifs file and tcon structures and make more granular Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-10-26 15:00 +0200
  [PATCH 4.4 027/112] powerpc/powernv: Pass CPU-endian PE number to opal_pci_eeh_freeze_clear() Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-10-26 15:00 +0200
  [PATCH 4.4 071/112] fs/super.c: fix race between freeze_super() and thaw_super() Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-10-26 15:00 +0200
  [PATCH 4.4 077/112] SMB3: GUIDs should be constructed as random but valid uuids Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-10-26 15:00 +0200
  [PATCH 4.4 019/112] perf intel-pt: Fix snapshot overlap detection decoder errors Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-10-26 15:00 +0200
  [PATCH 4.4 024/112] dm mpath: check if paths request_queue is dying in activate_path() Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-10-26 15:00 +0200
  [PATCH 4.4 072/112] cifs: Limit the overall credit acquired Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-10-26 15:00 +0200
  [PATCH 4.4 070/112] arc: dont leak bits of kernel stack into coredump Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-10-26 15:00 +0200
  [PATCH 4.4 057/112] Input: i8042 - skip selftest on ASUS laptops Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-10-26 15:00 +0200
  [PATCH 4.4 054/112] lib: move strtobool() to kstrtobool() Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-10-26 15:00 +0200
  [PATCH 4.4 037/112] zfcp: restore: Dont use 0 to indicate invalid LUN in rec trace Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-10-26 15:00 +0200
  [PATCH 4.4 058/112] Input: elantech - force needed quirks on Fujitsu H760 Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-10-26 15:00 +0200
  [PATCH 4.4 055/112] lib: update single-char callers of strtobool() Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-10-26 15:00 +0200
  [PATCH 4.4 060/112] sunrpc: fix write space race causing stalls Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-10-26 15:00 +0200
  [PATCH 4.4 053/112] MIPS: ptrace: Fix regs_return_value for kernel context Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-10-26 15:00 +0200
  [PATCH 4.4 056/112] lib: add "on"/"off" support to kstrtobool Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-10-26 15:00 +0200
  [PATCH 4.4 010/112] platform: dont return 0 from platform_get_irq[_byname]() on error Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-10-26 15:10 +0200
  [PATCH 4.4 047/112] [media] mb86a20s: fix the locking logic Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-10-26 15:10 +0200
  [PATCH 4.4 022/112] dm: mark request_queue dead before destroying the DM device Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-10-26 15:10 +0200
  [PATCH 4.4 021/112] perf intel-pt: Fix MTC timestamp calculation for large MTC periods Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-10-26 15:10 +0200
  [PATCH 4.4 043/112] scsi: zfcp: spin_lock_irqsave() is not nestable Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-10-26 15:10 +0200
  [PATCH 4.4 017/112] pstore/ram: Use memcpy_toio instead of memcpy Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-10-26 15:10 +0200
  [PATCH 4.4 041/112] zfcp: fix payload trace length for SAN request&response Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-10-26 15:10 +0200
  [PATCH 4.4 050/112] [media] cx231xx: fix GPIOs for Pixelview SBTVD hybrid Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-10-26 15:10 +0200
  [PATCH 4.4 049/112] [media] cx231xx: dont return error on success Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-10-26 15:10 +0200
  [PATCH 4.4 044/112] fbdev/efifb: Fix 16 color palette entry calculation Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-10-26 15:10 +0200
  [PATCH 4.4 048/112] [media] mb86a20s: fix demod settings Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-10-26 15:10 +0200
  [PATCH 4.4 015/112] pstore/ramoops: fixup driver removal Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-10-26 15:10 +0200
  [PATCH 4.4 032/112] ubi: Deal with interrupted erasures in WL Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-10-26 15:10 +0200
  [PATCH 4.4 046/112] ovl: copy_up_xattr(): use strnlen Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-10-26 15:10 +0200
  [PATCH 4.4 036/112] zfcp: retain trace level for SCSI and HBA FSF response records Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-10-26 15:10 +0200
  [PATCH 4.4 013/112] parisc: Fix kernel memory layout regarding position of __gp Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-10-26 15:10 +0200
  [PATCH 4.4 011/112] cpufreq: intel_pstate: Fix unsafe HWP MSR access Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-10-26 15:10 +0200
  [PATCH 4.4 038/112] zfcp: trace on request for open and close of WKA port Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-10-26 15:10 +0200
  [PATCH 4.4 035/112] zfcp: close window with unblocked rport during rport gone Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-10-26 15:10 +0200
  [PATCH 4.4 034/112] zfcp: fix ELS/GS request&response length for hardware data router Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-10-26 15:10 +0200
  [PATCH 4.4 042/112] zfcp: trace full payload of all SAN records (req,resp,iels) Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-10-26 15:10 +0200
  [PATCH 4.4 040/112] zfcp: fix D_ID field with actual value on tracing SAN responses Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-10-26 15:10 +0200
  [PATCH 4.4 045/112] ovl: Fix info leak in ovl_lookup_temp() Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-10-26 15:10 +0200
  [PATCH 4.4 033/112] zfcp: fix fc_host port_type with NPIV Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-10-26 15:10 +0200
  Re: [PATCH 4.4 000/112] 4.4.28-stable review Shuah Khan <shuah.kh@samsung.com> - 2016-10-26 20:50 +0200
  Re: [PATCH 4.4 000/112] 4.4.28-stable review Guenter Roeck <linux@roeck-us.net> - 2016-10-26 23:50 +0200

csiph-web