Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.kernel > #1688886
| From | Elena Reshetova <elena.reshetova@intel.com> |
|---|---|
| Newsgroups | linux.kernel |
| Subject | [PATCH 07/15] kernel: convert ring_buffer.refcount from atomic_t to refcount_t |
| Date | 2017-07-17 12:50 +0200 |
| Message-ID | <u4bLb-3Tv-5@gated-at.bofh.it> (permalink) |
| References | <u4bLb-3Tv-1@gated-at.bofh.it> |
| Organization | linux.* mail to news gateway |
refcount_t type and corresponding API should be
used instead of atomic_t when the variable is used as
a reference counter. This allows to avoid accidental
refcounter overflows that might lead to use-after-free
situations.
Suggested-by: Kees Cook <keescook@chromium.org>
Reviewed-by: David Windsor <dwindsor@gmail.com>
Reviewed-by: Hans Liljestrand <ishkamiel@gmail.com>
Signed-off-by: Elena Reshetova <elena.reshetova@intel.com>
---
kernel/events/core.c | 4 ++--
kernel/events/internal.h | 3 ++-
kernel/events/ring_buffer.c | 2 +-
3 files changed, 5 insertions(+), 4 deletions(-)
diff --git a/kernel/events/core.c b/kernel/events/core.c
index faf9925..9147397 100644
--- a/kernel/events/core.c
+++ b/kernel/events/core.c
@@ -5049,7 +5049,7 @@ struct ring_buffer *ring_buffer_get(struct perf_event *event)
rcu_read_lock();
rb = rcu_dereference(event->rb);
if (rb) {
- if (!atomic_inc_not_zero(&rb->refcount))
+ if (!refcount_inc_not_zero(&rb->refcount))
rb = NULL;
}
rcu_read_unlock();
@@ -5059,7 +5059,7 @@ struct ring_buffer *ring_buffer_get(struct perf_event *event)
void ring_buffer_put(struct ring_buffer *rb)
{
- if (!atomic_dec_and_test(&rb->refcount))
+ if (!refcount_dec_and_test(&rb->refcount))
return;
WARN_ON_ONCE(!list_empty(&rb->event_list));
diff --git a/kernel/events/internal.h b/kernel/events/internal.h
index 486fd78..b8e6fdf 100644
--- a/kernel/events/internal.h
+++ b/kernel/events/internal.h
@@ -3,13 +3,14 @@
#include <linux/hardirq.h>
#include <linux/uaccess.h>
+#include <linux/refcount.h>
/* Buffer handling */
#define RING_BUFFER_WRITABLE 0x01
struct ring_buffer {
- atomic_t refcount;
+ refcount_t refcount;
struct rcu_head rcu_head;
#ifdef CONFIG_PERF_USE_VMALLOC
struct work_struct work;
diff --git a/kernel/events/ring_buffer.c b/kernel/events/ring_buffer.c
index ee97196..3353572 100644
--- a/kernel/events/ring_buffer.c
+++ b/kernel/events/ring_buffer.c
@@ -284,7 +284,7 @@ ring_buffer_init(struct ring_buffer *rb, long watermark, int flags)
else
rb->overwrite = 1;
- atomic_set(&rb->refcount, 1);
+ refcount_set(&rb->refcount, 1);
INIT_LIST_HEAD(&rb->event_list);
spin_lock_init(&rb->event_lock);
--
2.7.4
Back to linux.kernel | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread
[PATCH 00/15] v3 kernel core pieces refcount conversions Elena Reshetova <elena.reshetova@intel.com> - 2017-07-17 12:50 +0200
[PATCH 07/15] kernel: convert ring_buffer.refcount from atomic_t to refcount_t Elena Reshetova <elena.reshetova@intel.com> - 2017-07-17 12:50 +0200
[PATCH 02/15] kernel: convert signal_struct.sigcnt from atomic_t to refcount_t Elena Reshetova <elena.reshetova@intel.com> - 2017-07-17 12:50 +0200
[PATCH 04/15] kernel: convert task_struct.usage from atomic_t to refcount_t Elena Reshetova <elena.reshetova@intel.com> - 2017-07-17 12:50 +0200
[PATCH 13/15] sched: convert numa_group.refcount from atomic_t to refcount_t Elena Reshetova <elena.reshetova@intel.com> - 2017-07-17 12:50 +0200
[PATCH 03/15] kernel: convert user_struct.__count from atomic_t to refcount_t Elena Reshetova <elena.reshetova@intel.com> - 2017-07-17 12:50 +0200
[PATCH 09/15] kernel: convert uprobe.ref from atomic_t to refcount_t Elena Reshetova <elena.reshetova@intel.com> - 2017-07-17 12:50 +0200
[PATCH 14/15] kernel: convert futex_pi_state.refcount from atomic_t to refcount_t Elena Reshetova <elena.reshetova@intel.com> - 2017-07-17 12:50 +0200
Re: [PATCH 14/15] kernel: convert futex_pi_state.refcount from atomic_t to refcount_t Thomas Gleixner <tglx@linutronix.de> - 2017-07-17 16:30 +0200
RE: [PATCH 14/15] kernel: convert futex_pi_state.refcount from atomic_t to refcount_t "Reshetova, Elena" <elena.reshetova@intel.com> - 2017-07-17 19:00 +0200
RE: [PATCH 14/15] kernel: convert futex_pi_state.refcount from atomic_t to refcount_t Thomas Gleixner <tglx@linutronix.de> - 2017-07-17 20:00 +0200
RE: [PATCH 14/15] kernel: convert futex_pi_state.refcount from atomic_t to refcount_t "Reshetova, Elena" <elena.reshetova@intel.com> - 2017-07-18 11:40 +0200
[PATCH 15/15] kernel: convert kcov.refcount from atomic_t to refcount_t Elena Reshetova <elena.reshetova@intel.com> - 2017-07-17 12:50 +0200
[PATCH 10/15] kernel: convert nsproxy.count from atomic_t to refcount_t Elena Reshetova <elena.reshetova@intel.com> - 2017-07-17 12:50 +0200
[PATCH 11/15] kernel: convert group_info.usage from atomic_t to refcount_t Elena Reshetova <elena.reshetova@intel.com> - 2017-07-17 12:50 +0200
[PATCH 01/15] kernel: convert sighand_struct.count from atomic_t to refcount_t Elena Reshetova <elena.reshetova@intel.com> - 2017-07-17 12:50 +0200
[PATCH 05/15] kernel: convert task_struct.stack_refcount from atomic_t to refcount_t Elena Reshetova <elena.reshetova@intel.com> - 2017-07-17 12:50 +0200
[PATCH 06/15] kernel: convert perf_event_context.refcount from atomic_t to refcount_t Elena Reshetova <elena.reshetova@intel.com> - 2017-07-17 12:50 +0200
[PATCH 12/15] kernel: convert cred.usage from atomic_t to refcount_t Elena Reshetova <elena.reshetova@intel.com> - 2017-07-17 12:50 +0200
csiph-web