Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.kernel > #1226894 > unrolled thread
| Started by | Dmitry Vyukov <dvyukov@google.com> |
|---|---|
| First post | 2015-09-17 12:40 +0200 |
| Last post | 2015-09-17 16:00 +0200 |
| Articles | 6 — 3 participants |
Back to article view | Back to linux.kernel
[PATCH v2] tty: fix data race in flush_to_ldisc Dmitry Vyukov <dvyukov@google.com> - 2015-09-17 12:40 +0200
Re: [PATCH v2] tty: fix data race in flush_to_ldisc Greg KH <gregkh@linuxfoundation.org> - 2015-09-17 15:00 +0200
Re: [PATCH v2] tty: fix data race in flush_to_ldisc Peter Hurley <peter@hurleysoftware.com> - 2015-09-17 15:20 +0200
Re: [PATCH v2] tty: fix data race in flush_to_ldisc Dmitry Vyukov <dvyukov@google.com> - 2015-09-17 15:30 +0200
Re: [PATCH v2] tty: fix data race in flush_to_ldisc Greg KH <gregkh@linuxfoundation.org> - 2015-09-17 16:00 +0200
Re: [PATCH v2] tty: fix data race in flush_to_ldisc Greg KH <gregkh@linuxfoundation.org> - 2015-09-17 16:00 +0200
| From | Dmitry Vyukov <dvyukov@google.com> |
|---|---|
| Date | 2015-09-17 12:40 +0200 |
| Subject | [PATCH v2] tty: fix data race in flush_to_ldisc |
| Message-ID | <q9ELD-TQ-11@gated-at.bofh.it> |
flush_to_ldisc reads port->itty and checks that it is not NULL, concurrently release_tty sets port->itty to NULL. It is possible that flush_to_ldisc loads port->itty once, ensures that it is not NULL, but then reloads it again and uses. The second load can already return NULL, which will cause a crash. Use READ_ONCE to read port->itty. The data race was found with KernelThreadSanitizer (KTSAN). Signed-off-by: Dmitry Vyukov <dvyukov@google.com> --- Changed since first version: - remove WRITE_ONCE when updating port->itty --- drivers/tty/tty_buffer.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/drivers/tty/tty_buffer.c b/drivers/tty/tty_buffer.c index 5a3fa89..23de97d 100644 --- a/drivers/tty/tty_buffer.c +++ b/drivers/tty/tty_buffer.c @@ -467,7 +467,7 @@ static void flush_to_ldisc(struct work_struct *work) struct tty_struct *tty; struct tty_ldisc *disc; - tty = port->itty; + tty = READ_ONCE(port->itty); if (tty == NULL) return; -- 2.6.0.rc0.131.gf624c3d -- To unsubscribe from this list: send the line "unsubscribe linux-kernel" in the body of a message to majordomo@vger.kernel.org More majordomo info at http://vger.kernel.org/majordomo-info.html Please read the FAQ at http://www.tux.org/lkml/
[toc] | [next] | [standalone]
| From | Greg KH <gregkh@linuxfoundation.org> |
|---|---|
| Date | 2015-09-17 15:00 +0200 |
| Message-ID | <q9GXa-40N-37@gated-at.bofh.it> |
| In reply to | #1226894 |
On Thu, Sep 17, 2015 at 12:39:36PM +0200, Dmitry Vyukov wrote: > flush_to_ldisc reads port->itty and checks that it is not NULL, > concurrently release_tty sets port->itty to NULL. It is possible > that flush_to_ldisc loads port->itty once, ensures that it is > not NULL, but then reloads it again and uses. The second load > can already return NULL, which will cause a crash. > > Use READ_ONCE to read port->itty. > > The data race was found with KernelThreadSanitizer (KTSAN). > > Signed-off-by: Dmitry Vyukov <dvyukov@google.com> You sent 3 patches here, but no hint as to what order they need to be applied in. Please resend them as a patch series (i.e. 1/3, 2/3, 3/3) so they can be applied correctly. thanks, greg k-h -- To unsubscribe from this list: send the line "unsubscribe linux-kernel" in the body of a message to majordomo@vger.kernel.org More majordomo info at http://vger.kernel.org/majordomo-info.html Please read the FAQ at http://www.tux.org/lkml/
[toc] | [prev] | [next] | [standalone]
| From | Peter Hurley <peter@hurleysoftware.com> |
|---|---|
| Date | 2015-09-17 15:20 +0200 |
| Message-ID | <q9Hgt-4Dp-13@gated-at.bofh.it> |
| In reply to | #1226992 |
On Thu, Sep 17, 2015 at 8:53 AM, Greg KH <gregkh@linuxfoundation.org> wrote: > On Thu, Sep 17, 2015 at 12:39:36PM +0200, Dmitry Vyukov wrote: >> flush_to_ldisc reads port->itty and checks that it is not NULL, >> concurrently release_tty sets port->itty to NULL. It is possible >> that flush_to_ldisc loads port->itty once, ensures that it is >> not NULL, but then reloads it again and uses. The second load >> can already return NULL, which will cause a crash. >> >> Use READ_ONCE to read port->itty. >> >> The data race was found with KernelThreadSanitizer (KTSAN). >> >> Signed-off-by: Dmitry Vyukov <dvyukov@google.com> > > You sent 3 patches here, but no hint as to what order they need to be > applied in. Please resend them as a patch series (i.e. 1/3, 2/3, 3/3) > so they can be applied correctly. Greg, I don't think these 3 patches are dependent on each other; I think they can be applied in any order. Regards, Peter Hurley -- To unsubscribe from this list: send the line "unsubscribe linux-kernel" in the body of a message to majordomo@vger.kernel.org More majordomo info at http://vger.kernel.org/majordomo-info.html Please read the FAQ at http://www.tux.org/lkml/
[toc] | [prev] | [next] | [standalone]
| From | Dmitry Vyukov <dvyukov@google.com> |
|---|---|
| Date | 2015-09-17 15:30 +0200 |
| Message-ID | <q9Hqb-4OV-23@gated-at.bofh.it> |
| In reply to | #1227021 |
On Thu, Sep 17, 2015 at 3:18 PM, Peter Hurley <peter@hurleysoftware.com> wrote: > On Thu, Sep 17, 2015 at 8:53 AM, Greg KH <gregkh@linuxfoundation.org> wrote: >> On Thu, Sep 17, 2015 at 12:39:36PM +0200, Dmitry Vyukov wrote: >>> flush_to_ldisc reads port->itty and checks that it is not NULL, >>> concurrently release_tty sets port->itty to NULL. It is possible >>> that flush_to_ldisc loads port->itty once, ensures that it is >>> not NULL, but then reloads it again and uses. The second load >>> can already return NULL, which will cause a crash. >>> >>> Use READ_ONCE to read port->itty. >>> >>> The data race was found with KernelThreadSanitizer (KTSAN). >>> >>> Signed-off-by: Dmitry Vyukov <dvyukov@google.com> >> >> You sent 3 patches here, but no hint as to what order they need to be >> applied in. Please resend them as a patch series (i.e. 1/3, 2/3, 3/3) >> so they can be applied correctly. > > Greg, > > I don't think these 3 patches are dependent on each other; I think they > can be applied in any order. Yes, these patches are independent and can be applied in any order, and any subset of them can be applied. I can send them as patch series if necessary, though. -- Dmitry Vyukov, Software Engineer, dvyukov@google.com Google Germany GmbH, Dienerstraße 12, 80331, München Geschäftsführer: Graham Law, Christine Elizabeth Flores Registergericht und -nummer: Hamburg, HRB 86891 Sitz der Gesellschaft: Hamburg Diese E-Mail ist vertraulich. Wenn Sie nicht der richtige Adressat sind, leiten Sie diese bitte nicht weiter, informieren Sie den Absender und löschen Sie die E-Mail und alle Anhänge. Vielen Dank. This e-mail is confidential. If you are not the right addressee please do not forward it, please inform the sender, and please erase this e-mail including any attachments. Thanks. -- To unsubscribe from this list: send the line "unsubscribe linux-kernel" in the body of a message to majordomo@vger.kernel.org More majordomo info at http://vger.kernel.org/majordomo-info.html Please read the FAQ at http://www.tux.org/lkml/
[toc] | [prev] | [next] | [standalone]
| From | Greg KH <gregkh@linuxfoundation.org> |
|---|---|
| Date | 2015-09-17 16:00 +0200 |
| Message-ID | <q9HTc-5nL-3@gated-at.bofh.it> |
| In reply to | #1227030 |
On Thu, Sep 17, 2015 at 03:21:02PM +0200, Dmitry Vyukov wrote: > On Thu, Sep 17, 2015 at 3:18 PM, Peter Hurley <peter@hurleysoftware.com> wrote: > > On Thu, Sep 17, 2015 at 8:53 AM, Greg KH <gregkh@linuxfoundation.org> wrote: > >> On Thu, Sep 17, 2015 at 12:39:36PM +0200, Dmitry Vyukov wrote: > >>> flush_to_ldisc reads port->itty and checks that it is not NULL, > >>> concurrently release_tty sets port->itty to NULL. It is possible > >>> that flush_to_ldisc loads port->itty once, ensures that it is > >>> not NULL, but then reloads it again and uses. The second load > >>> can already return NULL, which will cause a crash. > >>> > >>> Use READ_ONCE to read port->itty. > >>> > >>> The data race was found with KernelThreadSanitizer (KTSAN). > >>> > >>> Signed-off-by: Dmitry Vyukov <dvyukov@google.com> > >> > >> You sent 3 patches here, but no hint as to what order they need to be > >> applied in. Please resend them as a patch series (i.e. 1/3, 2/3, 3/3) > >> so they can be applied correctly. > > > > Greg, > > > > I don't think these 3 patches are dependent on each other; I think they > > can be applied in any order. > > > Yes, these patches are independent and can be applied in any order, > and any subset of them can be applied. > I can send them as patch series if necessary, though. Please do, that makes it easier for me. thanks, greg k-h -- To unsubscribe from this list: send the line "unsubscribe linux-kernel" in the body of a message to majordomo@vger.kernel.org More majordomo info at http://vger.kernel.org/majordomo-info.html Please read the FAQ at http://www.tux.org/lkml/
[toc] | [prev] | [next] | [standalone]
| From | Greg KH <gregkh@linuxfoundation.org> |
|---|---|
| Date | 2015-09-17 16:00 +0200 |
| Message-ID | <q9HTc-5nL-9@gated-at.bofh.it> |
| In reply to | #1227021 |
On Thu, Sep 17, 2015 at 09:18:11AM -0400, Peter Hurley wrote: > On Thu, Sep 17, 2015 at 8:53 AM, Greg KH <gregkh@linuxfoundation.org> wrote: > > On Thu, Sep 17, 2015 at 12:39:36PM +0200, Dmitry Vyukov wrote: > >> flush_to_ldisc reads port->itty and checks that it is not NULL, > >> concurrently release_tty sets port->itty to NULL. It is possible > >> that flush_to_ldisc loads port->itty once, ensures that it is > >> not NULL, but then reloads it again and uses. The second load > >> can already return NULL, which will cause a crash. > >> > >> Use READ_ONCE to read port->itty. > >> > >> The data race was found with KernelThreadSanitizer (KTSAN). > >> > >> Signed-off-by: Dmitry Vyukov <dvyukov@google.com> > > > > You sent 3 patches here, but no hint as to what order they need to be > > applied in. Please resend them as a patch series (i.e. 1/3, 2/3, 3/3) > > so they can be applied correctly. > > Greg, > > I don't think these 3 patches are dependent on each other; I think they > can be applied in any order. How do I know that? :) -- To unsubscribe from this list: send the line "unsubscribe linux-kernel" in the body of a message to majordomo@vger.kernel.org More majordomo info at http://vger.kernel.org/majordomo-info.html Please read the FAQ at http://www.tux.org/lkml/
[toc] | [prev] | [standalone]
Back to top | Article view | linux.kernel
csiph-web