Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1495200 > unrolled thread

[PATCH 2/2 v3] pci-hyperv: lock pci bus on device eject

Started byLong Li <longli@exchange.microsoft.com>
First post2016-10-04 07:00 +0200
Last post2016-10-04 22:50 +0200
Articles 2 — 2 participants

Back to article view | Back to linux.kernel


Contents

  [PATCH 2/2 v3] pci-hyperv: lock pci bus on device eject Long Li <longli@exchange.microsoft.com> - 2016-10-04 07:00 +0200
    RE: [PATCH 2/2 v3] pci-hyperv: lock pci bus on device eject KY Srinivasan <kys@microsoft.com> - 2016-10-04 22:50 +0200

#1495200 — [PATCH 2/2 v3] pci-hyperv: lock pci bus on device eject

FromLong Li <longli@exchange.microsoft.com>
Date2016-10-04 07:00 +0200
Subject[PATCH 2/2 v3] pci-hyperv: lock pci bus on device eject
Message-ID<sopZI-67m-3@gated-at.bofh.it>
From: Long Li <longli@microsoft.com>

A PCI_EJECT message can arrive at the same time we are calling pci_scan_child_bus in the workqueue for the previous PCI_BUS_RELATIONS message or in create_root_hv_pci_bus(), in this case we could potentailly modify the bus from multiple places. Properly lock the bus access.

Thanks Dexuan Cui <decui@microsoft.com> for pointing out the race condition in create_root_hv_pci_bus().

Signed-off-by: Long Li <longli@microsoft.com>
Tested-by: Cathy Avery <cavery@redhat.com>
Reported-by: Xiaofeng Wang <xiaofwan@redhat.com>
---
 drivers/pci/host/pci-hyperv.c | 4 ++++
 1 file changed, 4 insertions(+)

diff --git a/drivers/pci/host/pci-hyperv.c b/drivers/pci/host/pci-hyperv.c
index 4a37598..33c75c9 100644
--- a/drivers/pci/host/pci-hyperv.c
+++ b/drivers/pci/host/pci-hyperv.c
@@ -1198,9 +1198,11 @@ static int create_root_hv_pci_bus(struct hv_pcibus_device *hbus)
 	hbus->pci_bus->msi = &hbus->msi_chip;
 	hbus->pci_bus->msi->dev = &hbus->hdev->device;
 
+	pci_lock_rescan_remove();
 	pci_scan_child_bus(hbus->pci_bus);
 	pci_bus_assign_resources(hbus->pci_bus);
 	pci_bus_add_devices(hbus->pci_bus);
+	pci_unlock_rescan_remove();
 	hbus->state = hv_pcibus_installed;
 	return 0;
 }
@@ -1590,8 +1592,10 @@ static void hv_eject_device_work(struct work_struct *work)
 	pdev = pci_get_domain_bus_and_slot(hpdev->hbus->sysdata.domain, 0,
 					   wslot);
 	if (pdev) {
+		pci_lock_rescan_remove();
 		pci_stop_and_remove_bus_device(pdev);
 		pci_dev_put(pdev);
+		pci_unlock_rescan_remove();
 	}
 
 	memset(&ctxt, 0, sizeof(ctxt));
-- 
1.8.5.6

[toc] | [next] | [standalone]


#1495593

FromKY Srinivasan <kys@microsoft.com>
Date2016-10-04 22:50 +0200
Message-ID<soEOZ-7Fw-3@gated-at.bofh.it>
In reply to#1495200

> -----Original Message-----
> From: Long Li
> Sent: Monday, October 3, 2016 11:43 PM
> To: KY Srinivasan <kys@microsoft.com>; Haiyang Zhang
> <haiyangz@microsoft.com>; Bjorn Helgaas <bhelgaas@google.com>
> Cc: devel@linuxdriverproject.org; linux-pci@vger.kernel.org; linux-
> kernel@vger.kernel.org; Long Li <longli@microsoft.com>
> Subject: [PATCH 2/2 v3] pci-hyperv: lock pci bus on device eject
> 
> This sender failed our fraud detection checks and may not be who they
> appear to be. Learn about spoofing at http://aka.ms/LearnAboutSpoofing
> 
> From: Long Li <longli@microsoft.com>
> 
> A PCI_EJECT message can arrive at the same time we are calling
> pci_scan_child_bus in the workqueue for the previous PCI_BUS_RELATIONS
> message or in create_root_hv_pci_bus(), in this case we could potentailly
> modify the bus from multiple places. Properly lock the bus access.
> 
> Thanks Dexuan Cui <decui@microsoft.com> for pointing out the race
> condition in create_root_hv_pci_bus().
> 
> Signed-off-by: Long Li <longli@microsoft.com>
> Tested-by: Cathy Avery <cavery@redhat.com>
> Reported-by: Xiaofeng Wang <xiaofwan@redhat.com>

Acked-by: KY Srinivasan <kys@microsoft.com>

> ---
>  drivers/pci/host/pci-hyperv.c | 4 ++++
>  1 file changed, 4 insertions(+)
> 
> diff --git a/drivers/pci/host/pci-hyperv.c b/drivers/pci/host/pci-hyperv.c
> index 4a37598..33c75c9 100644
> --- a/drivers/pci/host/pci-hyperv.c
> +++ b/drivers/pci/host/pci-hyperv.c
> @@ -1198,9 +1198,11 @@ static int create_root_hv_pci_bus(struct
> hv_pcibus_device *hbus)
>         hbus->pci_bus->msi = &hbus->msi_chip;
>         hbus->pci_bus->msi->dev = &hbus->hdev->device;
> 
> +       pci_lock_rescan_remove();
>         pci_scan_child_bus(hbus->pci_bus);
>         pci_bus_assign_resources(hbus->pci_bus);
>         pci_bus_add_devices(hbus->pci_bus);
> +       pci_unlock_rescan_remove();
>         hbus->state = hv_pcibus_installed;
>         return 0;
>  }
> @@ -1590,8 +1592,10 @@ static void hv_eject_device_work(struct
> work_struct *work)
>         pdev = pci_get_domain_bus_and_slot(hpdev->hbus->sysdata.domain,
> 0,
>                                            wslot);
>         if (pdev) {
> +               pci_lock_rescan_remove();
>                 pci_stop_and_remove_bus_device(pdev);
>                 pci_dev_put(pdev);
> +               pci_unlock_rescan_remove();
>         }
> 
>         memset(&ctxt, 0, sizeof(ctxt));
> --
> 1.8.5.6

[toc] | [prev] | [standalone]


Back to top | Article view | linux.kernel


csiph-web