Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1227104 > unrolled thread

[PATCH v5 1/3] tty: fix data race in flush_to_ldisc

Started byDmitry Vyukov <dvyukov@google.com>
First post2015-09-17 17:20 +0200
Last post2015-09-17 19:40 +0200
Articles 2 — 2 participants

Back to article view | Back to linux.kernel

This discussion starts older than the indexed window; earlier articles aren't shown. The article labeled Started by below is the oldest one visible, not the original post.


Contents

  [PATCH v5 1/3] tty: fix data race in flush_to_ldisc Dmitry Vyukov <dvyukov@google.com> - 2015-09-17 17:20 +0200
    Re: [PATCH v5 1/3] tty: fix data race in flush_to_ldisc Peter Hurley <peter@hurleysoftware.com> - 2015-09-17 19:40 +0200

#1227104 — [PATCH v5 1/3] tty: fix data race in flush_to_ldisc

FromDmitry Vyukov <dvyukov@google.com>
Date2015-09-17 17:20 +0200
Subject[PATCH v5 1/3] tty: fix data race in flush_to_ldisc
Message-ID<q9J8C-7rl-17@gated-at.bofh.it>
flush_to_ldisc reads port->itty and checks that it is not NULL,
concurrently release_tty sets port->itty to NULL. It is possible
that flush_to_ldisc loads port->itty once, ensures that it is
not NULL, but then reloads it again and uses. The second load
can already return NULL, which will cause a crash.

Use READ_ONCE to read port->itty.

The data race was found with KernelThreadSanitizer (KTSAN).

Signed-off-by: Dmitry Vyukov <dvyukov@google.com>
---

Changed since first version:
 - remove WRITE_ONCE when updating port->itty
---
 drivers/tty/tty_buffer.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/drivers/tty/tty_buffer.c b/drivers/tty/tty_buffer.c
index 5a3fa89..23de97d 100644
--- a/drivers/tty/tty_buffer.c
+++ b/drivers/tty/tty_buffer.c
@@ -467,7 +467,7 @@ static void flush_to_ldisc(struct work_struct *work)
 	struct tty_struct *tty;
 	struct tty_ldisc *disc;
 
-	tty = port->itty;
+	tty = READ_ONCE(port->itty);
 	if (tty == NULL)
 		return;
 
-- 
2.6.0.rc0.131.gf624c3d

--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

[toc] | [next] | [standalone]


#1227246

FromPeter Hurley <peter@hurleysoftware.com>
Date2015-09-17 19:40 +0200
Message-ID<q9Lk7-286-35@gated-at.bofh.it>
In reply to#1227104
On Thu, Sep 17, 2015 at 11:17 AM, Dmitry Vyukov <dvyukov@google.com> wrote:
> flush_to_ldisc reads port->itty and checks that it is not NULL,
> concurrently release_tty sets port->itty to NULL. It is possible
> that flush_to_ldisc loads port->itty once, ensures that it is
> not NULL, but then reloads it again and uses. The second load
> can already return NULL, which will cause a crash.
>
> Use READ_ONCE to read port->itty.
>
> The data race was found with KernelThreadSanitizer (KTSAN).

Reviewed-by: Peter Hurley <peter@hurleysoftware.com>
--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

[toc] | [prev] | [standalone]


Back to top | Article view | linux.kernel


csiph-web