From: Eddie James <eajames@linux.vnet.ibm.com>
To: openbmc@lists.ozlabs.org
Cc: joel@jms.id.au, andrew@aj.id.au, "Edward A. James" <eajames@us.ibm.com>
Subject: [PATCH linux dev-4.10 v4 29/31] drivers: fsi: occ: Fix client memory management
Date: Thu, 5 Oct 2017 21:05:51 -0500 [thread overview]
Message-ID: <1507255553-13301-30-git-send-email-eajames@linux.vnet.ibm.com> (raw)
In-Reply-To: <1507255553-13301-1-git-send-email-eajames@linux.vnet.ibm.com>
From: "Edward A. James" <eajames@us.ibm.com>
Potential for bad memory access in the worker function. Now fixed by
using reference counters.
Signed-off-by: Edward A. James <eajames@us.ibm.com>
---
drivers/fsi/occ.c | 92 ++++++++++++++++++++++++++-----------------------------
1 file changed, 43 insertions(+), 49 deletions(-)
diff --git a/drivers/fsi/occ.c b/drivers/fsi/occ.c
index ec42fc0..800e8b6 100644
--- a/drivers/fsi/occ.c
+++ b/drivers/fsi/occ.c
@@ -70,15 +70,11 @@ struct occ_response {
* and cleared if the transfer fails or occ_worker_getsram completes.
* XFR_COMPLETE is set when a transfer fails or finishes occ_worker_getsram.
* XFR_CANCELED is set when the transfer's client is released.
- * XFR_WAITING is set from read() if the transfer isn't complete and
- * O_NONBLOCK wasn't specified. Cleared in read() when transfer completes or
- * fails.
*/
enum {
XFR_IN_PROGRESS,
XFR_COMPLETE,
XFR_CANCELED,
- XFR_WAITING,
};
struct occ_xfr {
@@ -104,6 +100,7 @@ enum {
};
struct occ_client {
+ struct kref kref;
struct occ *occ;
struct occ_xfr xfr;
spinlock_t lock; /* lock access to the client state */
@@ -140,6 +137,24 @@ static int occ_enqueue_xfr(struct occ_xfr *xfr)
return 0;
}
+static void occ_get_client(struct occ_client *client)
+{
+ kref_get(&client->kref);
+}
+
+static void occ_client_release(struct kref *kref)
+{
+ struct occ_client *client = container_of(kref, struct occ_client,
+ kref);
+
+ kfree(client);
+}
+
+static void occ_put_client(struct occ_client *client)
+{
+ kref_put(&client->kref, occ_client_release);
+}
+
static struct occ_client *occ_open_common(struct occ *occ, unsigned long flags)
{
struct occ_client *client = kzalloc(sizeof(*client), GFP_KERNEL);
@@ -148,6 +163,7 @@ static struct occ_client *occ_open_common(struct occ *occ, unsigned long flags)
return NULL;
client->occ = occ;
+ kref_init(&client->kref);
spin_lock_init(&client->lock);
init_waitqueue_head(&client->wait);
@@ -192,6 +208,7 @@ static ssize_t occ_read_common(struct occ_client *client, char __user *ubuf,
if (len > OCC_SRAM_BYTES)
return -EINVAL;
+ occ_get_client(client);
xfr = &client->xfr;
occ = client->occ;
@@ -215,8 +232,6 @@ static ssize_t occ_read_common(struct occ_client *client, char __user *ubuf,
goto done;
}
- set_bit(XFR_WAITING, &xfr->flags);
-
spin_unlock_irq(&client->lock);
rc = wait_event_interruptible(client->wait,
@@ -224,15 +239,12 @@ static ssize_t occ_read_common(struct occ_client *client, char __user *ubuf,
spin_lock_irq(&client->lock);
- if (test_bit(XFR_CANCELED, &xfr->flags)) {
- spin_unlock_irq(&client->lock);
- kfree(client);
- return -EBADFD;
- }
-
- clear_bit(XFR_WAITING, &xfr->flags);
if (!test_bit(XFR_COMPLETE, &xfr->flags)) {
- rc = -EINTR;
+ if (occ->cancel || test_bit(XFR_CANCELED, &xfr->flags))
+ rc = -ECANCELED;
+ else
+ rc = -EINTR;
+
goto done;
}
}
@@ -263,6 +275,7 @@ static ssize_t occ_read_common(struct occ_client *client, char __user *ubuf,
done:
spin_unlock_irq(&client->lock);
+ occ_put_client(client);
return rc;
}
@@ -289,6 +302,7 @@ static ssize_t occ_write_common(struct occ_client *client,
if (len > (OCC_CMD_DATA_BYTES + 3) || len < 3)
return -EINVAL;
+ occ_get_client(client);
xfr = &client->xfr;
spin_lock_irq(&client->lock);
@@ -340,6 +354,7 @@ static ssize_t occ_write_common(struct occ_client *client,
done:
spin_unlock_irq(&client->lock);
+ occ_put_client(client);
return rc;
}
@@ -364,38 +379,26 @@ static int occ_release_common(struct occ_client *client)
spin_lock_irq(&client->lock);
- if (!test_bit(CLIENT_XFR_PENDING, &client->flags)) {
- spin_unlock_irq(&client->lock);
- kfree(client);
- return 0;
- }
+ set_bit(XFR_CANCELED, &xfr->flags);
+ if (!test_bit(CLIENT_XFR_PENDING, &client->flags))
+ goto done;
spin_lock_irq(&occ->list_lock);
- set_bit(XFR_CANCELED, &xfr->flags);
if (!test_bit(XFR_IN_PROGRESS, &xfr->flags)) {
/* already deleted from list if complete */
if (!test_bit(XFR_COMPLETE, &xfr->flags))
list_del(&xfr->link);
-
- spin_unlock_irq(&occ->list_lock);
-
- if (test_bit(XFR_WAITING, &xfr->flags)) {
- /* blocking read; let reader clean up */
- wake_up_interruptible(&client->wait);
- spin_unlock_irq(&client->lock);
- return 0;
- }
-
- spin_unlock_irq(&client->lock);
-
- kfree(client);
- return 0;
}
- /* operation is in progress; let worker clean up */
spin_unlock_irq(&occ->list_lock);
+
+ wake_up_all(&client->wait);
+
+done:
spin_unlock_irq(&client->lock);
+
+ occ_put_client(client);
return 0;
}
@@ -601,7 +604,7 @@ static int occ_trigger_attn(struct device *sbefifo)
static void occ_worker(struct work_struct *work)
{
- int rc = 0, empty, waiting, canceled;
+ int rc = 0, empty;
u16 resp_data_length;
unsigned long start;
const unsigned long timeout = msecs_to_jiffies(OCC_TIMEOUT_MS);
@@ -624,6 +627,8 @@ static void occ_worker(struct work_struct *work)
return;
}
+ client = to_client(xfr);
+ occ_get_client(client);
resp = (struct occ_response *)xfr->buf;
set_bit(XFR_IN_PROGRESS, &xfr->flags);
@@ -679,29 +684,18 @@ static void occ_worker(struct work_struct *work)
mutex_unlock(&occ->occ_lock);
xfr->rc = rc;
- client = to_client(xfr);
-
- /* lock client to prevent race with read() */
- spin_lock_irq(&client->lock);
-
set_bit(XFR_COMPLETE, &xfr->flags);
- waiting = test_bit(XFR_WAITING, &xfr->flags);
-
- spin_unlock_irq(&client->lock);
spin_lock_irq(&occ->list_lock);
clear_bit(XFR_IN_PROGRESS, &xfr->flags);
list_del(&xfr->link);
empty = list_empty(&occ->xfrs);
- canceled = test_bit(XFR_CANCELED, &xfr->flags);
spin_unlock_irq(&occ->list_lock);
- if (waiting)
- wake_up_interruptible(&client->wait);
- else if (canceled)
- kfree(client);
+ wake_up_interruptible(&client->wait);
+ occ_put_client(client);
if (!empty)
goto again;
--
1.8.3.1
next prev parent reply other threads:[~2017-10-06 2:07 UTC|newest]
Thread overview: 42+ messages / expand[flat|nested] mbox.gz Atom feed top
2017-10-06 2:05 [PATCH linux dev-4.10 v4 00/31] drivers: fsi: client fixes and refactor Eddie James
2017-10-06 2:05 ` [PATCH linux dev-4.10 v4 01/31] drivers: fsi: sbefifo: Fix includes Eddie James
2017-10-06 2:05 ` [PATCH linux dev-4.10 v4 02/31] drivers: fsi: sbefifo: Use a defined reschedule length Eddie James
2017-10-06 2:05 ` [PATCH linux dev-4.10 v4 03/31] drivers: fsi: sbefifo: Use __be32 for big endian values Eddie James
2017-10-06 2:05 ` [PATCH linux dev-4.10 v4 04/31] drivers: fsi: sbefifo: white space fixes Eddie James
2017-10-06 2:05 ` [PATCH linux dev-4.10 v4 05/31] drivers: fsi: sbefifo: replace awkward wait_event expression Eddie James
2017-10-06 2:05 ` [PATCH linux dev-4.10 v4 06/31] drivers: fsi: sbefifo: remove redundant function Eddie James
2017-10-06 2:09 ` Andrew Jeffery
2017-10-06 2:05 ` [PATCH linux dev-4.10 v4 07/31] drivers: fsi: sbefifo: Use goto to reduce put statements Eddie James
2017-10-06 2:05 ` [PATCH linux dev-4.10 v4 08/31] drivers: fsi: sbefifo: Do an earlier get_client call Eddie James
2017-10-06 2:05 ` [PATCH linux dev-4.10 v4 09/31] drivers: fsi: sbefifo: Remove warning and user data access check Eddie James
2017-10-06 2:05 ` [PATCH linux dev-4.10 v4 10/31] drivers: fsi: sbefifo: destroy the ida list on exit Eddie James
2017-10-06 2:05 ` [PATCH linux dev-4.10 v4 11/31] drivers: fsi: sbefifo: Fix module authors and comments Eddie James
2017-10-06 2:05 ` [PATCH linux dev-4.10 v4 12/31] drivers: fsi: sbefifo: Fix include guards in header file Eddie James
2017-10-06 2:05 ` [PATCH linux dev-4.10 v4 13/31] drivers: fsi: SBEFIFO: Fix probe() and remove() Eddie James
2017-10-06 2:05 ` [PATCH linux dev-4.10 v4 14/31] drivers: fsi: SBEFIFO: check for xfr complete in read wait_event Eddie James
2017-10-06 2:05 ` [PATCH linux dev-4.10 v4 15/31] drivers: fsi: occ: Fix includes Eddie James
2017-10-06 2:05 ` [PATCH linux dev-4.10 v4 16/31] drivers: fsi: occ: Fix errant kfree calls Eddie James
2017-10-06 2:05 ` [PATCH linux dev-4.10 v4 17/31] drivers: fsi: occ: remove unused occ_command structure Eddie James
2017-10-06 2:05 ` [PATCH linux dev-4.10 v4 18/31] drivers: fsi: occ: Use big-endian values Eddie James
2017-10-06 2:05 ` [PATCH linux dev-4.10 v4 19/31] drivers: fsi: occ: Return ENODEV if client is NULL Eddie James
2017-10-06 2:12 ` Andrew Jeffery
2017-10-06 2:05 ` [PATCH linux dev-4.10 v4 20/31] drivers: fsi: occ: Remove early user buffer checking Eddie James
2017-10-06 2:05 ` [PATCH linux dev-4.10 v4 21/31] drivers: fsi: occ: Switch to more logical errnos Eddie James
2017-10-06 2:05 ` [PATCH linux dev-4.10 v4 22/31] drivers: fsi: occ: fix white space and bracket problems Eddie James
2017-10-06 2:14 ` Andrew Jeffery
2017-10-06 2:05 ` [PATCH linux dev-4.10 v4 23/31] drivers: fsi: occ: Destroy the ida list on exit Eddie James
2017-10-06 2:05 ` [PATCH linux dev-4.10 v4 24/31] drivers: fsi: occ: Remove unnecessary platform_set_drvdata call Eddie James
2017-10-06 2:05 ` [PATCH linux dev-4.10 v4 25/31] drivers: fsi: occ: Add comments for clarity Eddie James
2017-10-06 2:05 ` [PATCH linux dev-4.10 v4 26/31] drivers: fsi: occ: Add OCC response definitions to header Eddie James
2017-10-06 2:05 ` [PATCH linux dev-4.10 v4 27/31] drivers: fsi: occ: Poll while receiving "command in progress" Eddie James
2017-10-06 2:05 ` [PATCH linux dev-4.10 v4 28/31] drivers: fsi: occ: Add cancel to remove() and fix probe() Eddie James
2017-10-06 2:16 ` Andrew Jeffery
2017-10-09 1:05 ` Brad Bishop
2017-10-09 1:53 ` Joel Stanley
2017-10-09 14:58 ` Eddie James
2017-10-06 2:05 ` Eddie James [this message]
2017-10-06 2:20 ` [PATCH linux dev-4.10 v4 29/31] drivers: fsi: occ: Fix client memory management Andrew Jeffery
2017-10-09 15:38 ` Eddie James
2017-10-06 2:05 ` [PATCH linux dev-4.10 v4 30/31] drivers/hwmon/occ: Remove repeated ops for OCC command in progress Eddie James
2017-10-06 2:05 ` [PATCH linux dev-4.10 v4 31/31] drivers: hwmon: occ: Cancel occ operations in remove() Eddie James
2017-10-06 2:26 ` Andrew Jeffery
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=1507255553-13301-30-git-send-email-eajames@linux.vnet.ibm.com \
--to=eajames@linux.vnet.ibm.com \
--cc=andrew@aj.id.au \
--cc=eajames@us.ibm.com \
--cc=joel@jms.id.au \
--cc=openbmc@lists.ozlabs.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.