Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1172047

[PATCH 3.16.y-ckt 69/71] tracing: Have filter check for balanced ops

From Luis Henriques <luis.henriques@canonical.com>
Newsgroups linux.kernel
Subject [PATCH 3.16.y-ckt 69/71] tracing: Have filter check for balanced ops
Date 2015-06-25 12:10 +0200
Message-ID <pFcgz-5Bx-71@gated-at.bofh.it> (permalink)
References <pFcgx-5Bx-7@gated-at.bofh.it>
Organization linux.* mail to news gateway

Show all headers | View raw


3.16.7-ckt14 -stable review patch.  If anyone has any objections, please let me know.

------------------

From: Steven Rostedt <rostedt@goodmis.org>

commit 2cf30dc180cea808077f003c5116388183e54f9e upstream.

When the following filter is used it causes a warning to trigger:

 # cd /sys/kernel/debug/tracing
 # echo "((dev==1)blocks==2)" > events/ext4/ext4_truncate_exit/filter
-bash: echo: write error: Invalid argument
 # cat events/ext4/ext4_truncate_exit/filter
((dev==1)blocks==2)
^
parse_error: No error

 ------------[ cut here ]------------
 WARNING: CPU: 2 PID: 1223 at kernel/trace/trace_events_filter.c:1640 replace_preds+0x3c5/0x990()
 Modules linked in: bnep lockd grace bluetooth  ...
 CPU: 3 PID: 1223 Comm: bash Tainted: G        W       4.1.0-rc3-test+ #450
 Hardware name: Hewlett-Packard HP Compaq Pro 6300 SFF/339A, BIOS K01 v02.05 05/07/2012
  0000000000000668 ffff8800c106bc98 ffffffff816ed4f9 ffff88011ead0cf0
  0000000000000000 ffff8800c106bcd8 ffffffff8107fb07 ffffffff8136b46c
  ffff8800c7d81d48 ffff8800d4c2bc00 ffff8800d4d4f920 00000000ffffffea
 Call Trace:
  [<ffffffff816ed4f9>] dump_stack+0x4c/0x6e
  [<ffffffff8107fb07>] warn_slowpath_common+0x97/0xe0
  [<ffffffff8136b46c>] ? _kstrtoull+0x2c/0x80
  [<ffffffff8107fb6a>] warn_slowpath_null+0x1a/0x20
  [<ffffffff81159065>] replace_preds+0x3c5/0x990
  [<ffffffff811596b2>] create_filter+0x82/0xb0
  [<ffffffff81159944>] apply_event_filter+0xd4/0x180
  [<ffffffff81152bbf>] event_filter_write+0x8f/0x120
  [<ffffffff811db2a8>] __vfs_write+0x28/0xe0
  [<ffffffff811dda43>] ? __sb_start_write+0x53/0xf0
  [<ffffffff812e51e0>] ? security_file_permission+0x30/0xc0
  [<ffffffff811dc408>] vfs_write+0xb8/0x1b0
  [<ffffffff811dc72f>] SyS_write+0x4f/0xb0
  [<ffffffff816f5217>] system_call_fastpath+0x12/0x6a
 ---[ end trace e11028bd95818dcd ]---

Worse yet, reading the error message (the filter again) it says that
there was no error, when there clearly was. The issue is that the
code that checks the input does not check for balanced ops. That is,
having an op between a closed parenthesis and the next token.

This would only cause a warning, and fail out before doing any real
harm, but it should still not caues a warning, and the error reported
should work:

 # cd /sys/kernel/debug/tracing
 # echo "((dev==1)blocks==2)" > events/ext4/ext4_truncate_exit/filter
-bash: echo: write error: Invalid argument
 # cat events/ext4/ext4_truncate_exit/filter
((dev==1)blocks==2)
^
parse_error: Meaningless filter expression

And give no kernel warning.

Link: http://lkml.kernel.org/r/20150615175025.7e809215@gandalf.local.home

Cc: Peter Zijlstra <a.p.zijlstra@chello.nl>
Cc: Ingo Molnar <mingo@redhat.com>
Cc: Arnaldo Carvalho de Melo <acme@kernel.org>
Reported-by: Vince Weaver <vincent.weaver@maine.edu>
Tested-by: Vince Weaver <vincent.weaver@maine.edu>
Signed-off-by: Steven Rostedt <rostedt@goodmis.org>
[ luis: backported to 3.16:
  - unconditionally decrement cnt as the OP_NOT logic was introduced only
    by e12c09cf3087 ("tracing: Add NOT to filtering logic") ]
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
 kernel/trace/trace_events_filter.c | 9 +++++++--
 1 file changed, 7 insertions(+), 2 deletions(-)

diff --git a/kernel/trace/trace_events_filter.c b/kernel/trace/trace_events_filter.c
index 8a8631926a07..cb347e85f75e 100644
--- a/kernel/trace/trace_events_filter.c
+++ b/kernel/trace/trace_events_filter.c
@@ -1399,19 +1399,24 @@ static int check_preds(struct filter_parse_state *ps)
 {
 	int n_normal_preds = 0, n_logical_preds = 0;
 	struct postfix_elt *elt;
+	int cnt = 0;
 
 	list_for_each_entry(elt, &ps->postfix, list) {
-		if (elt->op == OP_NONE)
+		if (elt->op == OP_NONE) {
+			cnt++;
 			continue;
+		}
 
+		cnt--;
 		if (elt->op == OP_AND || elt->op == OP_OR) {
 			n_logical_preds++;
 			continue;
 		}
 		n_normal_preds++;
+		WARN_ON_ONCE(cnt < 0);
 	}
 
-	if (!n_normal_preds || n_logical_preds >= n_normal_preds) {
+	if (cnt != 1 || !n_normal_preds || n_logical_preds >= n_normal_preds) {
 		parse_error(ps, FILT_ERR_INVALID_FILTER, 0);
 		return -EINVAL;
 	}
--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

Back to linux.kernel | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread


Thread

[3.16.y-ckt stable] Linux 3.16.7-ckt14 stable review Luis Henriques <luis.henriques@canonical.com> - 2015-06-25 12:10 +0200
  [PATCH 3.16.y-ckt 47/71] btrfs: cleanup orphans while looking up default subvolume Luis Henriques <luis.henriques@canonical.com> - 2015-06-25 12:10 +0200
  [PATCH 3.16.y-ckt 62/71] iser-target: Fix variable-length response error completion Luis Henriques <luis.henriques@canonical.com> - 2015-06-25 12:10 +0200
  [PATCH 3.16.y-ckt 13/71] ozwpan: Use unsigned ints to prevent heap overflow Luis Henriques <luis.henriques@canonical.com> - 2015-06-25 12:10 +0200
  [PATCH 3.16.y-ckt 01/71] iio: adis16400: Report pressure channel scale Luis Henriques <luis.henriques@canonical.com> - 2015-06-25 12:10 +0200
  [PATCH 3.16.y-ckt 15/71] ozwpan: unchecked signed subtraction leads to DoS Luis Henriques <luis.henriques@canonical.com> - 2015-06-25 12:10 +0200
  [PATCH 3.16.y-ckt 70/71] drm/radeon: fix freeze for laptop with Turks/Thames GPU. Luis Henriques <luis.henriques@canonical.com> - 2015-06-25 12:10 +0200
  [PATCH 3.16.y-ckt 61/71] block: fix ext_dev_lock lockdep report Luis Henriques <luis.henriques@canonical.com> - 2015-06-25 12:10 +0200
  [PATCH 3.16.y-ckt 14/71] ozwpan: divide-by-zero leading to panic Luis Henriques <luis.henriques@canonical.com> - 2015-06-25 12:10 +0200
  [PATCH 3.16.y-ckt 50/71] iommu/vt-d: Allow RMRR on graphics devices too Luis Henriques <luis.henriques@canonical.com> - 2015-06-25 12:10 +0200
  [PATCH 3.16.y-ckt 56/71] Input: synaptics - add min/max quirk for Lenovo S540 Luis Henriques <luis.henriques@canonical.com> - 2015-06-25 12:10 +0200
  [PATCH 3.16.y-ckt 10/71] usb: dwc3: gadget: Fix incorrect DEPCMD and DGCMD status macros Luis Henriques <luis.henriques@canonical.com> - 2015-06-25 12:10 +0200
  [PATCH 3.16.y-ckt 46/71] btrfs: incorrect handling for fiemap_fill_next_extent return Luis Henriques <luis.henriques@canonical.com> - 2015-06-25 12:10 +0200
  [PATCH 3.16.y-ckt 55/71] pata_octeon_cf: fix broken build Luis Henriques <luis.henriques@canonical.com> - 2015-06-25 12:10 +0200
  [PATCH 3.16.y-ckt 65/71] drm/mgag200: Reject non-character-cell-aligned mode widths Luis Henriques <luis.henriques@canonical.com> - 2015-06-25 12:10 +0200
  [PATCH 3.16.y-ckt 67/71] crypto: caam - improve initalization for context state saves Luis Henriques <luis.henriques@canonical.com> - 2015-06-25 12:10 +0200
  [PATCH 3.16.y-ckt 57/71] drm/i915: Fix DDC probe for passive adapters Luis Henriques <luis.henriques@canonical.com> - 2015-06-25 12:10 +0200
  [PATCH 3.16.y-ckt 51/71] iommu/vt-d: Fix passthrough mode with translation-disabled devices Luis Henriques <luis.henriques@canonical.com> - 2015-06-25 12:10 +0200
  [PATCH 3.16.y-ckt 68/71] crypto: caam - fix RNG buffer cache alignment Luis Henriques <luis.henriques@canonical.com> - 2015-06-25 12:10 +0200
  [PATCH 3.16.y-ckt 12/71] ozwpan: Use proper check to prevent heap overflow Luis Henriques <luis.henriques@canonical.com> - 2015-06-25 12:10 +0200
  [PATCH 3.16.y-ckt 63/71] iser-target: release stale iser connections Luis Henriques <luis.henriques@canonical.com> - 2015-06-25 12:10 +0200
  [PATCH 3.16.y-ckt 54/71] irqchip: sunxi-nmi: Fix off-by-one error in irq iterator Luis Henriques <luis.henriques@canonical.com> - 2015-06-25 12:10 +0200
  [PATCH 3.16.y-ckt 71/71] Revert "tools/vm: fix page-flags build" Luis Henriques <luis.henriques@canonical.com> - 2015-06-25 12:10 +0200
  [PATCH 3.16.y-ckt 11/71] ALSA: usb-audio: Add mic volume fix quirk for Logitech Quickcam Fusion Luis Henriques <luis.henriques@canonical.com> - 2015-06-25 12:10 +0200
  [PATCH 3.16.y-ckt 69/71] tracing: Have filter check for balanced ops Luis Henriques <luis.henriques@canonical.com> - 2015-06-25 12:10 +0200
  [PATCH 3.16.y-ckt 59/71] mm/memory_hotplug.c: set zone->wait_table to null after freeing it Luis Henriques <luis.henriques@canonical.com> - 2015-06-25 12:10 +0200
  [PATCH 3.16.y-ckt 66/71] crypto: caam - fix uninitialized state->buf_dma field Luis Henriques <luis.henriques@canonical.com> - 2015-06-25 12:10 +0200
  [PATCH 3.16.y-ckt 52/71] ata: ahci_mvebu: Fix wrongly set base address for the MBus window setting Luis Henriques <luis.henriques@canonical.com> - 2015-06-25 12:10 +0200
  [PATCH 3.16.y-ckt 60/71] ring-buffer-benchmark: Fix the wrong sched_priority of producer Luis Henriques <luis.henriques@canonical.com> - 2015-06-25 12:10 +0200
  [PATCH 3.16.y-ckt 64/71] ALSA: hda - adding a DAC/pin preference map for a HP Envy TS machine Luis Henriques <luis.henriques@canonical.com> - 2015-06-25 12:10 +0200
  [PATCH 3.16.y-ckt 35/71] net: dp83640: fix broken calibration routine. Luis Henriques <luis.henriques@canonical.com> - 2015-06-25 12:20 +0200
  [PATCH 3.16.y-ckt 36/71] net: dp83640: reinforce locking rules. Luis Henriques <luis.henriques@canonical.com> - 2015-06-25 12:20 +0200
  [PATCH 3.16.y-ckt 29/71] scripts/sortextable: suppress warning: `relocs_size' may be used uninitialized Luis Henriques <luis.henriques@canonical.com> - 2015-06-25 12:20 +0200
  [PATCH 3.16.y-ckt 30/71] thermal: step_wise: Revert optimization Luis Henriques <luis.henriques@canonical.com> - 2015-06-25 12:20 +0200
  [PATCH 3.16.y-ckt 20/71] Input: elantech - fix detection of touchpads where the revision matches a known rate Luis Henriques <luis.henriques@canonical.com> - 2015-06-25 12:20 +0200
  [PATCH 3.16.y-ckt 37/71] unix/caif: sk_socket can disappear when state is unlocked Luis Henriques <luis.henriques@canonical.com> - 2015-06-25 12:20 +0200
  [PATCH 3.16.y-ckt 24/71] USB: cp210x: add ID for HubZ dual ZigBee and Z-Wave dongle Luis Henriques <luis.henriques@canonical.com> - 2015-06-25 12:20 +0200
  [PATCH 3.16.y-ckt 21/71] ALSA: hda/realtek - Add a fixup for another Acer Aspire 9420 Luis Henriques <luis.henriques@canonical.com> - 2015-06-25 12:20 +0200
  [PATCH 3.16.y-ckt 28/71] kconfig: Fix warning "‘jump’ may be used uninitialized" Luis Henriques <luis.henriques@canonical.com> - 2015-06-25 12:20 +0200
  [PATCH 3.16.y-ckt 23/71] ALSA: usb-audio: fix missing input volume controls in MAYA44 USB(+) Luis Henriques <luis.henriques@canonical.com> - 2015-06-25 12:20 +0200
  [PATCH 3.16.y-ckt 31/71] MIPS: KVM: Do not sign extend on unsigned MMIO load Luis Henriques <luis.henriques@canonical.com> - 2015-06-25 12:20 +0200
  [PATCH 3.16.y-ckt 38/71] xen/netback: Properly initialize credit_bytes Luis Henriques <luis.henriques@canonical.com> - 2015-06-25 12:20 +0200
  [PATCH 3.16.y-ckt 27/71] xfrm: fix a race in xfrm_state_lookup_byspi Luis Henriques <luis.henriques@canonical.com> - 2015-06-25 12:20 +0200
  [PATCH 3.16.y-ckt 42/71] bridge: disable softirqs around br_fdb_update to avoid lockup Luis Henriques <luis.henriques@canonical.com> - 2015-06-25 12:20 +0200
  [PATCH 3.16.y-ckt 39/71] udp: fix behavior of wrong checksums Luis Henriques <luis.henriques@canonical.com> - 2015-06-25 12:20 +0200
  [PATCH 3.16.y-ckt 22/71] ALSA: usb-audio: add MAYA44 USB+ mixer control names Luis Henriques <luis.henriques@canonical.com> - 2015-06-25 12:20 +0200
  [PATCH 3.16.y-ckt 41/71] ipv4/udp: Verify multicast group is ours in upd_v4_early_demux() Luis Henriques <luis.henriques@canonical.com> - 2015-06-25 12:20 +0200
  [PATCH 3.16.y-ckt 40/71] xen: netback: read hotplug script once at start of day. Luis Henriques <luis.henriques@canonical.com> - 2015-06-25 12:20 +0200
  [PATCH 3.16.y-ckt 43/71] drm/i915: Assume dual channel LVDS if pixel clock necessitates it Luis Henriques <luis.henriques@canonical.com> - 2015-06-25 12:20 +0200
  [PATCH 3.16.y-ckt 44/71] Btrfs: send, add missing check for dead clone root Luis Henriques <luis.henriques@canonical.com> - 2015-06-25 12:20 +0200
  [PATCH 3.16.y-ckt 33/71] net: core: Correct an over-stringent device loop detection. Luis Henriques <luis.henriques@canonical.com> - 2015-06-25 12:20 +0200
  [PATCH 3.16.y-ckt 34/71] net: phy: Allow EEE for all RGMII variants Luis Henriques <luis.henriques@canonical.com> - 2015-06-25 12:20 +0200
  [PATCH 3.16.y-ckt 32/71] arch/x86/kvm/mmu.c: work around gcc-4.4.4 bug Luis Henriques <luis.henriques@canonical.com> - 2015-06-25 12:20 +0200
  [PATCH 3.16.y-ckt 18/71] x86/asm/irq: Stop relying on magic JMP behavior for early_idt_handlers Luis Henriques <luis.henriques@canonical.com> - 2015-06-25 12:20 +0200
  [PATCH 3.16.y-ckt 48/71] Drivers: hv: vmbus: Add support for VMBus panic notifier handler Luis Henriques <luis.henriques@canonical.com> - 2015-06-25 12:20 +0200
  [PATCH 3.16.y-ckt 25/71] Input: elantech - add new icbody type Luis Henriques <luis.henriques@canonical.com> - 2015-06-25 12:20 +0200
  [PATCH 3.16.y-ckt 26/71] MIPS: Fix enabling of DEBUG_STACKOVERFLOW Luis Henriques <luis.henriques@canonical.com> - 2015-06-25 12:20 +0200
  [PATCH 3.16.y-ckt 45/71] Btrfs: send, don't leave without decrementing clone root's send_progress Luis Henriques <luis.henriques@canonical.com> - 2015-06-25 12:20 +0200

csiph-web