Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1653596

[patch 01/26] alarmtimer: Prevent overflow of relative timers

From Thomas Gleixner <tglx@linutronix.de>
Newsgroups linux.kernel
Subject [patch 01/26] alarmtimer: Prevent overflow of relative timers
Date 2017-05-30 23:50 +0200
Message-ID <tMXbB-4e6-55@gated-at.bofh.it> (permalink)
References <tMXbz-4e6-5@gated-at.bofh.it>
Organization linux.* mail to news gateway

Show all headers | View raw


Andrey reported a alartimer related RCU stall while fuzzing the kernel with
syzkaller.

The reason for this is an overflow in ktime_add() which brings the
resulting time into negative space and causes immediate expiry of the
timer. The following rearm with a small interval does not bring the timer
back into positive space due to the same issue.

This results in a permanent firing alarmtimer which hogs the CPU.

Use ktime_add_safe() instead which detects the overflow and clamps the
result to KTIME_SEC_MAX.

Reported-by: Andrey Konovalov <andreyknvl@google.com>
Signed-off-by: Thomas Gleixner <tglx@linutronix.de>
Cc: Dmitry Vyukov <dvyukov@google.com>
Cc: Kostya Serebryany <kcc@google.com>
Cc: syzkaller <syzkaller@googlegroups.com>
---
 kernel/time/alarmtimer.c |    6 +++---
 1 file changed, 3 insertions(+), 3 deletions(-)

--- a/kernel/time/alarmtimer.c
+++ b/kernel/time/alarmtimer.c
@@ -357,7 +357,7 @@ void alarm_start_relative(struct alarm *
 {
 	struct alarm_base *base = &alarm_bases[alarm->type];
 
-	start = ktime_add(start, base->gettime());
+	start = ktime_add_safe(start, base->gettime());
 	alarm_start(alarm, start);
 }
 EXPORT_SYMBOL_GPL(alarm_start_relative);
@@ -445,7 +445,7 @@ u64 alarm_forward(struct alarm *alarm, k
 		overrun++;
 	}
 
-	alarm->node.expires = ktime_add(alarm->node.expires, interval);
+	alarm->node.expires = ktime_add_safe(alarm->node.expires, interval);
 	return overrun;
 }
 EXPORT_SYMBOL_GPL(alarm_forward);
@@ -668,7 +668,7 @@ static int alarm_timer_set(struct k_itim
 		ktime_t now;
 
 		now = alarm_bases[timr->it.alarm.alarmtimer.type].gettime();
-		exp = ktime_add(now, exp);
+		exp = ktime_add_safe(now, exp);
 	}
 
 	alarm_start(&timr->it.alarm.alarmtimer, exp);

Back to linux.kernel | Previous | NextPrevious in thread | Next in thread | Find similar | Unroll thread


Thread

[patch 00/26] alarmtimers/posixtimers: Bug fixes and spec conformity  changes Thomas Gleixner <tglx@linutronix.de> - 2017-05-30 23:50 +0200
  [patch 09/26] posix-timers: Unify overrun/requeue_pending handling Thomas Gleixner <tglx@linutronix.de> - 2017-05-30 23:50 +0200
    [tip:timers/core] posix-timers: Unify overrun/requeue_pending  handling tip-bot for Thomas Gleixner <tipbot@zytor.com> - 2017-06-05 10:30 +0200
  [patch 19/26] posix-timers: Add cancel/arm callbacks Thomas Gleixner <tglx@linutronix.de> - 2017-05-30 23:50 +0200
    [tip:timers/core] posix-timers: Add cancel/arm callbacks tip-bot for Thomas Gleixner <tipbot@zytor.com> - 2017-06-05 10:30 +0200
  [patch 11/26] posix-timers: Store k_clock pointer in k_itimer Thomas Gleixner <tglx@linutronix.de> - 2017-05-30 23:50 +0200
    [tip:timers/core] posix-timers: Store k_clock pointer in k_itimer tip-bot for Thomas Gleixner <tipbot@zytor.com> - 2017-06-05 10:30 +0200
  [patch 24/26] alarmtimer: Implement try_to_cancel callback Thomas Gleixner <tglx@linutronix.de> - 2017-05-30 23:50 +0200
    [tip:timers/core] alarmtimer: Implement try_to_cancel callback tip-bot for Thomas Gleixner <tipbot@zytor.com> - 2017-06-05 10:30 +0200
  [patch 08/26] posix-timers: Move posix-timer internals to core Thomas Gleixner <tglx@linutronix.de> - 2017-05-30 23:50 +0200
    Re: [patch 08/26] posix-timers: Move posix-timer internals to core Christoph Hellwig <hch@infradead.org> - 2017-05-31 17:40 +0200
    [tip:timers/core] posix-timers: Move posix-timer internals to core tip-bot for Thomas Gleixner <tipbot@zytor.com> - 2017-06-05 10:20 +0200
  [patch 17/26] posix-timers: Make use of forward/remaining callbacks Thomas Gleixner <tglx@linutronix.de> - 2017-05-30 23:50 +0200
    [tip:timers/core] posix-timers: Make use of forward/remaining  callbacks tip-bot for Thomas Gleixner <tipbot@zytor.com> - 2017-06-05 10:30 +0200
  [patch 07/26] posix-timers: Cleanup struct k_itimer Thomas Gleixner <tglx@linutronix.de> - 2017-05-30 23:50 +0200
    [tip:timers/core] posix-timers: Cleanup struct k_itimer tip-bot for Thomas Gleixner <tipbot@zytor.com> - 2017-06-05 10:20 +0200
  [patch 02/26] alarmtimer: Rate limit periodic intervals Thomas Gleixner <tglx@linutronix.de> - 2017-05-30 23:50 +0200
    [tip:timers/urgent] alarmtimer: Rate limit periodic intervals tip-bot for Thomas Gleixner <tipbot@zytor.com> - 2017-06-04 15:30 +0200
    [tip:timers/urgent] alarmtimer: Rate limit periodic intervals tip-bot for Thomas Gleixner <tipbot@zytor.com> - 2017-06-04 15:40 +0200
  [patch 14/26] posix-timers: Use timer_rearm() callback in  posixtimer_rearm() Thomas Gleixner <tglx@linutronix.de> - 2017-05-30 23:50 +0200
    [tip:timers/core] posix-timers: Use timer_rearm() callback in  posixtimer_rearm() tip-bot for Thomas Gleixner <tipbot@zytor.com> - 2017-06-05 10:30 +0200
  [patch 04/26] posix-timers: Remove unused export of  posix_timer_event() Thomas Gleixner <tglx@linutronix.de> - 2017-05-30 23:50 +0200
    [tip:timers/core] posix-timers: Remove unused export of  posix_timer_event() tip-bot for Thomas Gleixner <tipbot@zytor.com> - 2017-06-05 10:20 +0200
  [patch 23/26] alarmtimer: Implement remaining callback Thomas Gleixner <tglx@linutronix.de> - 2017-05-30 23:50 +0200
    [tip:timers/core] alarmtimer: Implement remaining callback tip-bot for Thomas Gleixner <tipbot@zytor.com> - 2017-06-05 10:30 +0200
  [patch 13/26] posix-timers: Rename do_schedule_next_timer Thomas Gleixner <tglx@linutronix.de> - 2017-05-30 23:50 +0200
    Re: [patch 13/26] posix-timers: Rename do_schedule_next_timer Christoph Hellwig <hch@infradead.org> - 2017-05-31 17:40 +0200
      Re: [patch 13/26] posix-timers: Rename do_schedule_next_timer Thomas Gleixner <tglx@linutronix.de> - 2017-06-01 23:00 +0200
        Re: [patch 13/26] posix-timers: Rename do_schedule_next_timer Christoph Hellwig <hch@infradead.org> - 2017-06-02 09:10 +0200
    [tip:timers/core] posix-timers: Rename do_schedule_next_timer tip-bot for Thomas Gleixner <tipbot@zytor.com> - 2017-06-05 10:30 +0200
  [patch 22/26] alarmtimer: Implement forward callback Thomas Gleixner <tglx@linutronix.de> - 2017-05-30 23:50 +0200
    [tip:timers/core] alarmtimer: Implement forward callback tip-bot for Thomas Gleixner <tipbot@zytor.com> - 2017-06-05 10:30 +0200
  [patch 03/26] alarmtimer: Remove pointless config conditional Thomas Gleixner <tglx@linutronix.de> - 2017-05-30 23:50 +0200
    [tip:timers/core] alarmtimer: Remove pointless config conditional tip-bot for Thomas Gleixner <tipbot@zytor.com> - 2017-06-05 10:20 +0200
  [patch 26/26] alarmtimer: Switch over to generic set/get/rearm routine Thomas Gleixner <tglx@linutronix.de> - 2017-05-30 23:50 +0200
    [tip:timers/core] alarmtimer: Switch over to generic set/get/rearm  routine tip-bot for Thomas Gleixner <tipbot@zytor.com> - 2017-06-05 10:30 +0200
  [patch 06/26] posix-timers: Avoid gazillions of forward declarations Thomas Gleixner <tglx@linutronix.de> - 2017-05-30 23:50 +0200
    [tip:timers/core] posix-timers: Avoid gazillions of forward  declarations tip-bot for Thomas Gleixner <tipbot@zytor.com> - 2017-06-05 10:20 +0200
  [patch 12/26] posix-timers: Add timer_rearm() callback Thomas Gleixner <tglx@linutronix.de> - 2017-05-30 23:50 +0200
    [tip:timers/core] posix-timers: Add timer_rearm() callback tip-bot for Thomas Gleixner <tipbot@zytor.com> - 2017-06-05 10:30 +0200
  [patch 01/26] alarmtimer: Prevent overflow of relative timers Thomas Gleixner <tglx@linutronix.de> - 2017-05-30 23:50 +0200
    [tip:timers/urgent] alarmtimer: Prevent overflow of relative timers tip-bot for Thomas Gleixner <tipbot@zytor.com> - 2017-06-04 15:30 +0200
    [tip:timers/urgent] alarmtimer: Prevent overflow of relative timers tip-bot for Thomas Gleixner <tipbot@zytor.com> - 2017-06-04 15:40 +0200
  [patch 15/26] posix-timers: Add active flag to k_itimer Thomas Gleixner <tglx@linutronix.de> - 2017-05-30 23:50 +0200
    [tip:timers/core] posix-timers: Add active flag to k_itimer tip-bot for Thomas Gleixner <tipbot@zytor.com> - 2017-06-05 10:30 +0200
  [patch 16/26] posix-timers: Add forward/remaining callbacks Thomas Gleixner <tglx@linutronix.de> - 2017-05-30 23:50 +0200
    [tip:timers/core] posix-timers: Add forward/remaining callbacks tip-bot for Thomas Gleixner <tipbot@zytor.com> - 2017-06-05 10:30 +0200
  [patch 25/26] alarmtimer: Implement arm callback Thomas Gleixner <tglx@linutronix.de> - 2017-05-30 23:50 +0200
    [tip:timers/core] alarmtimer: Implement arm callback tip-bot for Thomas Gleixner <tipbot@zytor.com> - 2017-06-05 10:30 +0200
  [patch 21/26] alarmtimer: Implement timer_rearm() callback Thomas Gleixner <tglx@linutronix.de> - 2017-05-30 23:50 +0200
    [tip:timers/core] alarmtimer: Implement timer_rearm() callback tip-bot for Thomas Gleixner <tipbot@zytor.com> - 2017-06-05 10:30 +0200
  [patch 10/26] posix-timers: Move interval out of the union Thomas Gleixner <tglx@linutronix.de> - 2017-05-30 23:50 +0200
    [tip:timers/core] posix-timers: Move interval out of the union tip-bot for Thomas Gleixner <tipbot@zytor.com> - 2017-06-05 10:30 +0200
  [patch 20/26] posix-timers: Make use of cancel/arm callbacks Thomas Gleixner <tglx@linutronix.de> - 2017-05-30 23:50 +0200
    [tip:timers/core] posix-timers: Make use of cancel/arm callbacks tip-bot for Thomas Gleixner <tipbot@zytor.com> - 2017-06-05 10:30 +0200
  [patch 18/26] posix-timers: Zero settings value in common code Thomas Gleixner <tglx@linutronix.de> - 2017-05-30 23:50 +0200
    [tip:timers/core] posix-timers: Zero settings value in common code tip-bot for Thomas Gleixner <tipbot@zytor.com> - 2017-06-05 10:30 +0200

csiph-web