From: <gregkh@linuxfoundation.org>
To: daniel@iogearbox.net, ast@kernel.org, gregkh@linuxfoundation.org,
malat@debian.org, yhs@fb.com
Cc: <stable@vger.kernel.org>, <stable-commits@vger.kernel.org>
Subject: Patch "bpf: fix memory leak in lpm_trie map_free callback function" has been added to the 4.15-stable tree
Date: Fri, 09 Mar 2018 14:17:07 -0800 [thread overview]
Message-ID: <1520633827149228@kroah.com> (raw)
In-Reply-To: <92a9bac0950f4c6def7378bc548eeaea6518b4da.1520507630.git.daniel@iogearbox.net>
This is a note to let you know that I've just added the patch titled
bpf: fix memory leak in lpm_trie map_free callback function
to the 4.15-stable tree which can be found at:
http://www.kernel.org/git/?p=linux/kernel/git/stable/stable-queue.git;a=summary
The filename of the patch is:
bpf-fix-memory-leak-in-lpm_trie-map_free-callback-function.patch
and it can be found in the queue-4.15 subdirectory.
If you, or anyone else, feels it should not be added to the stable tree,
please let <stable@vger.kernel.org> know about it.
>From foo@baz Fri Mar 9 14:15:30 PST 2018
From: Daniel Borkmann <daniel@iogearbox.net>
Date: Thu, 8 Mar 2018 13:16:43 +0100
Subject: bpf: fix memory leak in lpm_trie map_free callback function
To: gregkh@linuxfoundation.org
Cc: ast@kernel.org, daniel@iogearbox.net, stable@vger.kernel.org, Yonghong Song <yhs@fb.com>
Message-ID: <92a9bac0950f4c6def7378bc548eeaea6518b4da.1520507630.git.daniel@iogearbox.net>
From: Yonghong Song <yhs@fb.com>
[ upstream commit 9a3efb6b661f71d5675369ace9257833f0e78ef3 ]
There is a memory leak happening in lpm_trie map_free callback
function trie_free. The trie structure itself does not get freed.
Also, trie_free function did not do synchronize_rcu before freeing
various data structures. This is incorrect as some rcu_read_lock
region(s) for lookup, update, delete or get_next_key may not complete yet.
The fix is to add synchronize_rcu in the beginning of trie_free.
The useless spin_lock is removed from this function as well.
Fixes: b95a5c4db09b ("bpf: add a longest prefix match trie map implementation")
Reported-by: Mathieu Malaterre <malat@debian.org>
Reported-by: Alexei Starovoitov <ast@kernel.org>
Tested-by: Mathieu Malaterre <malat@debian.org>
Signed-off-by: Yonghong Song <yhs@fb.com>
Signed-off-by: Alexei Starovoitov <ast@kernel.org>
Signed-off-by: Daniel Borkmann <daniel@iogearbox.net>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
kernel/bpf/lpm_trie.c | 11 +++++++----
1 file changed, 7 insertions(+), 4 deletions(-)
--- a/kernel/bpf/lpm_trie.c
+++ b/kernel/bpf/lpm_trie.c
@@ -560,7 +560,10 @@ static void trie_free(struct bpf_map *ma
struct lpm_trie_node __rcu **slot;
struct lpm_trie_node *node;
- raw_spin_lock(&trie->lock);
+ /* Wait for outstanding programs to complete
+ * update/lookup/delete/get_next_key and free the trie.
+ */
+ synchronize_rcu();
/* Always start at the root and walk down to a node that has no
* children. Then free that node, nullify its reference in the parent
@@ -574,7 +577,7 @@ static void trie_free(struct bpf_map *ma
node = rcu_dereference_protected(*slot,
lockdep_is_held(&trie->lock));
if (!node)
- goto unlock;
+ goto out;
if (rcu_access_pointer(node->child[0])) {
slot = &node->child[0];
@@ -592,8 +595,8 @@ static void trie_free(struct bpf_map *ma
}
}
-unlock:
- raw_spin_unlock(&trie->lock);
+out:
+ kfree(trie);
}
static int trie_get_next_key(struct bpf_map *map, void *key, void *next_key)
Patches currently in stable-queue which might be from daniel@iogearbox.net are
queue-4.15/bpf-fix-mlock-precharge-on-arraymaps.patch
queue-4.15/bpf-x64-implement-retpoline-for-tail-call.patch
queue-4.15/bpf-arm64-fix-out-of-bounds-access-in-tail-call.patch
queue-4.15/bpf-fix-memory-leak-in-lpm_trie-map_free-callback-function.patch
queue-4.15/bpf-ppc64-fix-out-of-bounds-access-in-tail-call.patch
queue-4.15/bpf-add-schedule-points-in-percpu-arrays-management.patch
queue-4.15/bpf-allow-xadd-only-on-aligned-memory.patch
queue-4.15/bpf-fix-rcu-lockdep-warning-for-lpm_trie-map_free-callback.patch
next prev parent reply other threads:[~2018-03-09 22:17 UTC|newest]
Thread overview: 18+ messages / expand[flat|nested] mbox.gz Atom feed top
2018-03-08 12:16 [PATCH stable 4.15 0/8] BPF stable patches Daniel Borkmann
2018-03-08 12:16 ` [PATCH stable 4.15 1/8] bpf: fix mlock precharge on arraymaps Daniel Borkmann
2018-03-09 22:17 ` Patch "bpf: fix mlock precharge on arraymaps" has been added to the 4.15-stable tree gregkh
2018-03-08 12:16 ` [PATCH stable 4.15 2/8] bpf: fix memory leak in lpm_trie map_free callback function Daniel Borkmann
2018-03-09 22:17 ` gregkh [this message]
2018-03-08 12:16 ` [PATCH stable 4.15 3/8] bpf: fix rcu lockdep warning for lpm_trie map_free callback Daniel Borkmann
2018-03-09 22:17 ` Patch "bpf: fix rcu lockdep warning for lpm_trie map_free callback" has been added to the 4.15-stable tree gregkh
2018-03-08 12:16 ` [PATCH stable 4.15 4/8] bpf, x64: implement retpoline for tail call Daniel Borkmann
2018-03-09 22:17 ` Patch "bpf, x64: implement retpoline for tail call" has been added to the 4.15-stable tree gregkh
2018-03-08 12:16 ` [PATCH stable 4.15 5/8] bpf, arm64: fix out of bounds access in tail call Daniel Borkmann
2018-03-09 22:17 ` Patch "bpf, arm64: fix out of bounds access in tail call" has been added to the 4.15-stable tree gregkh
2018-03-08 12:16 ` [PATCH stable 4.15 6/8] bpf: add schedule points in percpu arrays management Daniel Borkmann
2018-03-09 22:17 ` Patch "bpf: add schedule points in percpu arrays management" has been added to the 4.15-stable tree gregkh
2018-03-08 12:16 ` [PATCH stable 4.15 7/8] bpf: allow xadd only on aligned memory Daniel Borkmann
2018-03-09 22:17 ` Patch "bpf: allow xadd only on aligned memory" has been added to the 4.15-stable tree gregkh
2018-03-08 12:16 ` [PATCH stable 4.15 8/8] bpf, ppc64: fix out of bounds access in tail call Daniel Borkmann
2018-03-09 22:17 ` Patch "bpf, ppc64: fix out of bounds access in tail call" has been added to the 4.15-stable tree gregkh
2018-03-09 22:17 ` [PATCH stable 4.15 0/8] BPF stable patches Greg KH
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=1520633827149228@kroah.com \
--to=gregkh@linuxfoundation.org \
--cc=ast@kernel.org \
--cc=daniel@iogearbox.net \
--cc=malat@debian.org \
--cc=stable-commits@vger.kernel.org \
--cc=stable@vger.kernel.org \
--cc=yhs@fb.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.