From: Greg KH <gregkh@suse.de>
To: linux-kernel@vger.kernel.org, stable@kernel.org, jejb@kernel.org
Cc: Justin Forbes <jmforbes@linuxtx.org>,
Zwane Mwaikambo <zwane@arm.linux.org.uk>,
"Theodore Ts'o" <tytso@mit.edu>,
Randy Dunlap <rdunlap@xenotime.net>,
Dave Jones <davej@redhat.com>,
Chuck Wolber <chuckw@quantumlinux.com>,
Chris Wedgwood <reviews@ml.cw.f00f.org>,
Michael Krufky <mkrufky@linuxtv.org>,
Chuck Ebbert <cebbert@redhat.com>,
Domenico Andreoli <cavokz@gmail.com>, Willy Tarreau <w@1wt.eu>,
Rodrigo Rubira Branco <rbranco@la.checkpoint.com>,
Jake Edge <jake@lwn.net>, Eugene Teo <eteo@redhat.com>,
torvalds@linux-foundation.org, akpm@linux-foundation.org,
alan@lxorguk.ukuu.org.uk,
Marcin Slusarz <marcin.slusarz@gmail.com>,
Alessandro Zummo <alessandro.zummo@towertech.it>,
David Brownell <dbrownell@users.sourceforge.net>
Subject: [patch 69/71] rtc: fix kernel panic on second use of SIGIO nofitication
Date: Mon, 6 Oct 2008 17:40:26 -0700 [thread overview]
Message-ID: <20081007004026.GR3055@suse.de> (raw)
In-Reply-To: <20081007003634.GA3055@suse.de>
[-- Attachment #1: rtc-fix-kernel-panic-on-second-use-of-sigio-nofitication.patch --]
[-- Type: text/plain, Size: 5211 bytes --]
2.6.26-stable review patch. If anyone has any objections, please let us
know.
------------------
From: Marcin Slusarz <marcin.slusarz@gmail.com>
commit 2e4a75cdcb89ff53bb182dda3a6dcdc14befe007 upstream
When userspace uses SIGIO notification and forgets to disable it before
closing file descriptor, rtc->async_queue contains stale pointer to struct
file. When user space enables again SIGIO notification in different
process, kernel dereferences this (poisoned) pointer and crashes.
So disable SIGIO notification on close.
Kernel panic:
(second run of qemu (requires echo 1024 > /sys/class/rtc/rtc0/max_user_freq))
general protection fault: 0000 [1] PREEMPT
CPU 0
Modules linked in: af_packet snd_pcm_oss snd_mixer_oss snd_seq_oss snd_seq_midi_event snd_seq usbhid tuner tea5767 tda8290 tuner_xc2028 xc5000 tda9887 tuner_simple tuner_types mt20xx tea5761 tda9875 uhci_hcd ehci_hcd usbcore bttv snd_via82xx snd_ac97_codec ac97_bus snd_pcm snd_timer ir_common compat_ioctl32 snd_page_alloc videodev v4l1_compat snd_mpu401_uart snd_rawmidi v4l2_common videobuf_dma_sg videobuf_core snd_seq_device snd btcx_risc soundcore tveeprom i2c_viapro
Pid: 5781, comm: qemu-system-x86 Not tainted 2.6.27-rc6 #363
RIP: 0010:[<ffffffff8024f891>] [<ffffffff8024f891>] __lock_acquire+0x3db/0x73f
RSP: 0000:ffffffff80674cb8 EFLAGS: 00010002
RAX: ffff8800224c62f0 RBX: 0000000000000046 RCX: 0000000000000002
RDX: 0000000000000000 RSI: 0000000000000000 RDI: ffff8800224c62f0
RBP: ffffffff80674d08 R08: 0000000000000002 R09: 0000000000000001
R10: ffffffff80238941 R11: 0000000000000001 R12: 0000000000000000
R13: 6b6b6b6b6b6b6b6b R14: ffff88003a450080 R15: 0000000000000000
FS: 00007f98b69516f0(0000) GS:ffffffff80623200(0000) knlGS:00000000f7cc86d0
CS: 0010 DS: 0000 ES: 0000 CR0: 000000008005003b
CR2: 0000000000a87000 CR3: 0000000022598000 CR4: 00000000000006e0
DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
DR3: 0000000000000000 DR6: 00000000ffff0ff0 DR7: 0000000000000400
Process qemu-system-x86 (pid: 5781, threadinfo ffff880028812000, task ffff88003a450080)
Stack: ffffffff80674cf8 0000000180238440 0000000200000002 0000000000000000
ffff8800224c62f0 0000000000000046 0000000000000000 0000000000000002
0000000000000002 0000000000000000 ffffffff80674d68 ffffffff8024fc7a
Call Trace:
<IRQ> [<ffffffff8024fc7a>] lock_acquire+0x85/0xa9
[<ffffffff8029cb62>] ? send_sigio+0x2a/0x184
[<ffffffff80491d1f>] _read_lock+0x3e/0x4a
[<ffffffff8029cb62>] ? send_sigio+0x2a/0x184
[<ffffffff8029cb62>] send_sigio+0x2a/0x184
[<ffffffff8024fb97>] ? __lock_acquire+0x6e1/0x73f
[<ffffffff8029cd4d>] ? kill_fasync+0x2c/0x4e
[<ffffffff8029cd10>] __kill_fasync+0x54/0x65
[<ffffffff8029cd5b>] kill_fasync+0x3a/0x4e
[<ffffffff80402896>] rtc_update_irq+0x9c/0xa5
[<ffffffff80404640>] cmos_interrupt+0xae/0xc0
[<ffffffff8025d1c1>] handle_IRQ_event+0x25/0x5a
[<ffffffff8025e5e4>] handle_edge_irq+0xdd/0x123
[<ffffffff8020da34>] do_IRQ+0xe4/0x144
[<ffffffff8020bad6>] ret_from_intr+0x0/0xf
<EOI> [<ffffffff8026fdc2>] ? __alloc_pages_internal+0xe7/0x3ad
[<ffffffff8033fe67>] ? clear_page_c+0x7/0x10
[<ffffffff8026fc10>] ? get_page_from_freelist+0x385/0x450
[<ffffffff8026fdc2>] ? __alloc_pages_internal+0xe7/0x3ad
[<ffffffff80280aac>] ? anon_vma_prepare+0x2e/0xf6
[<ffffffff80279400>] ? handle_mm_fault+0x227/0x6a5
[<ffffffff80494716>] ? do_page_fault+0x494/0x83f
[<ffffffff8049251d>] ? error_exit+0x0/0xa9
Code: cc 41 39 45 28 74 24 e8 5e 1d 0f 00 85 c0 0f 84 6a 03 00 00 83 3d 8f a9 aa 00 00 be 47 03 00 00 0f 84 6a 02 00 00 e9 53 03 00 00 <41> ff 85 38 01 00 00 45 8b be 90 06 00 00 41 83 ff 2f 76 24 e8
RIP [<ffffffff8024f891>] __lock_acquire+0x3db/0x73f
RSP <ffffffff80674cb8>
---[ end trace 431877d860448760 ]---
Kernel panic - not syncing: Aiee, killing interrupt handler!
Signed-off-by: Marcin Slusarz <marcin.slusarz@gmail.com>
Acked-by: Alessandro Zummo <alessandro.zummo@towertech.it>
Acked-by: David Brownell <dbrownell@users.sourceforge.net>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@suse.de>
---
drivers/rtc/rtc-dev.c | 15 +++++++++------
1 file changed, 9 insertions(+), 6 deletions(-)
--- a/drivers/rtc/rtc-dev.c
+++ b/drivers/rtc/rtc-dev.c
@@ -401,6 +401,12 @@ static int rtc_dev_ioctl(struct inode *i
return err;
}
+static int rtc_dev_fasync(int fd, struct file *file, int on)
+{
+ struct rtc_device *rtc = file->private_data;
+ return fasync_helper(fd, file, on, &rtc->async_queue);
+}
+
static int rtc_dev_release(struct inode *inode, struct file *file)
{
struct rtc_device *rtc = file->private_data;
@@ -411,16 +417,13 @@ static int rtc_dev_release(struct inode
if (rtc->ops->release)
rtc->ops->release(rtc->dev.parent);
+ if (file->f_flags & FASYNC)
+ rtc_dev_fasync(-1, file, 0);
+
clear_bit_unlock(RTC_DEV_BUSY, &rtc->flags);
return 0;
}
-static int rtc_dev_fasync(int fd, struct file *file, int on)
-{
- struct rtc_device *rtc = file->private_data;
- return fasync_helper(fd, file, on, &rtc->async_queue);
-}
-
static const struct file_operations rtc_dev_fops = {
.owner = THIS_MODULE,
.llseek = no_llseek,
--
next prev parent reply other threads:[~2008-10-07 1:05 UTC|newest]
Thread overview: 78+ messages / expand[flat|nested] mbox.gz Atom feed top
[not found] <20081007002606.723632097@mini.kroah.org>
2008-10-07 0:36 ` [patch 00/71] 2.6.26-stable review Greg KH
2008-10-07 0:37 ` [patch 01/71] x86-32: AMD c1e force timer broadcast late Greg KH
2008-10-07 0:37 ` [patch 02/71] ACPI: Fix thermal shutdowns Greg KH
2008-10-07 0:37 ` [patch 03/71] i2c-dev: Return correct error code on class_create() failure Greg KH
2008-10-07 0:37 ` [patch 04/71] ixgbe: initialize interrupt throttle rate Greg KH
2008-10-07 0:37 ` [patch 05/71] drivers/mmc/card/block.c: fix refcount leak in mmc_block_open() Greg KH
2008-10-07 0:37 ` [patch 06/71] async_tx: fix the bug in async_tx_run_dependencies Greg KH
2008-10-07 0:37 ` [patch 07/71] mm: mark the correct zone as full when scanning zonelists Greg KH
2008-10-07 0:37 ` [patch 08/71] pxa2xx_spi: dma bugfixes Greg KH
2008-10-07 0:37 ` [patch 09/71] pxa2xx_spi: chipselect bugfixes Greg KH
2008-10-07 0:37 ` [patch 10/71] smb.h: do not include linux/time.h in userspace Greg KH
2008-10-07 0:37 ` [patch 11/71] USB: fix hcd interrupt disabling Greg KH
2008-10-07 0:37 ` [patch 12/71] SCSI: qla2xxx: Defer enablement of RISC interrupts until ISP initialization completes Greg KH
2008-10-07 0:38 ` [patch 13/71] ALSA: hda - Fix model for Dell Inspiron 1525 Greg KH
2008-10-07 0:38 ` [patch 14/71] ALSA: oxygen: fix distorted output on AK4396-based cards Greg KH
2008-10-07 0:38 ` [patch 15/71] ALSA: fix locking in snd_pcm_open*() and snd_rawmidi_open*() Greg KH
2008-10-07 0:38 ` [patch 16/71] ALSA: remove unneeded power_mutex lock in snd_pcm_drop Greg KH
2008-10-07 0:38 ` [patch 17/71] KVM: SVM: fix random segfaults with NPT enabled Greg KH
2008-10-07 0:38 ` [patch 18/71] KVM: SVM: fix guest global tlb flushes with NPT Greg KH
2008-10-07 0:38 ` [patch 19/71] x86-64: Clean up save/restore_i387() usage Greg KH
2008-10-07 0:38 ` [patch 20/71] x64, fpu: fix possible FPU leakage in error conditions Greg KH
2008-10-07 0:38 ` [patch 21/71] x86: Fix broken LDT access in VMI Greg KH
2008-10-07 0:38 ` [patch 22/71] block: submit_bh() inadvertently discards barrier flag on a sync write Greg KH
2008-10-07 0:38 ` [patch 23/71] sched: fix process time monotonicity Greg KH
2008-10-07 0:38 ` [patch 24/71] APIC routing fix Greg KH
2008-10-07 0:38 ` [patch 25/71] ocfs2: Increment the reference count of an already-active stack Greg KH
2008-10-07 0:38 ` [patch 26/71] sg: disable interrupts inside sg_copy_buffer Greg KH
2008-10-07 0:38 ` [patch 27/71] x86: Fix 27-rc crash on vsmp due to paravirt during module load Greg KH
2008-10-07 0:38 ` [patch 28/71] rt2x00: Use ieee80211_hw->workqueue again Greg KH
2008-10-07 0:38 ` [patch 29/71] x86: fdiv bug detection fix Greg KH
2008-10-07 0:38 ` [patch 30/71] x86: fix oprofile + hibernation badness Greg KH
2008-10-07 0:38 ` [patch 31/71] x86: PAT proper tracking of set_memory_uc and friends Greg KH
2008-10-07 0:38 ` [patch 32/71] x86-64: fix overlap of modules and fixmap areas Greg KH
2008-10-07 0:38 ` [patch 33/71] mm: dirty page tracking race fix Greg KH
2008-10-07 0:38 ` [patch 34/71] rtc: fix deadlock Greg KH
2008-10-07 0:38 ` [patch 35/71] x86: fix SMP alternatives: use mutex instead of spinlock, text_poke is sleepable Greg KH
2008-10-07 0:38 ` [patch 36/71] ACPI: Avoid bogus EC timeout when EC is in Polling mode Greg KH
2008-10-07 0:39 ` [patch 37/71] x86: add io delay quirk for Presario F700 Greg KH
2008-10-07 0:39 ` [patch 38/71] x86: fix memmap=exactmap boot argument Greg KH
2008-10-07 0:39 ` [patch 39/71] clockevents: prevent clockevent event_handler ending up handler_noop Greg KH
2008-10-07 0:39 ` [patch 40/71] clockevents: prevent endless loop in periodic broadcast handler Greg KH
2008-10-07 0:39 ` [patch 41/71] clockevents: enforce reprogram in oneshot setup Greg KH
2008-10-07 0:39 ` [patch 42/71] clockevents: prevent multiple init/shutdown Greg KH
2008-10-07 0:39 ` [patch 43/71] clockevents: prevent endless loop lockup Greg KH
2008-10-07 0:39 ` [patch 44/71] HPET: make minimum reprogramming delta useful Greg KH
2008-10-07 0:39 ` [patch 45/71] clockevents: broadcast fixup possible waiters Greg KH
2008-10-07 0:39 ` [patch 46/71] x86: HPET fix moronic 32/64bit thinko Greg KH
2008-10-07 0:39 ` [patch 47/71] x86: HPET: read back compare register before reading counter Greg KH
2008-10-07 0:39 ` [patch 48/71] ntp: fix calculation of the next jiffie to trigger RTC sync Greg KH
2008-10-07 0:39 ` [patch 49/71] clockevents: remove WARN_ON which was used to gather information Greg KH
2008-10-07 0:39 ` [patch 50/71] pcmcia: Fix broken abuse of dev->driver_data Greg KH
2008-10-07 0:39 ` [patch 51/71] af_key: Free dumping state on socket close Greg KH
2008-10-07 0:39 ` [patch 52/71] XFRM,IPv6: initialize ip6_dst_blackhole_ops.kmem_cachep Greg KH
2008-10-07 0:39 ` [patch 53/71] ipv6: Fix OOPS in ip6_dst_lookup_tail() Greg KH
2008-10-07 0:39 ` [patch 54/71] niu: panic on reset Greg KH
2008-10-07 0:39 ` [patch 55/71] netlink: fix overrun in attribute iteration Greg KH
2008-10-07 0:39 ` [patch 56/71] ipsec: Fix pskb_expand_head corruption in xfrm_state_check_space Greg KH
2008-10-07 0:40 ` [patch 57/71] sctp: do not enable peer features if we cant do them Greg KH
2008-10-07 0:40 ` [patch 58/71] sctp: Fix oops when INIT-ACK indicates that peer doesnt support AUTH Greg KH
2008-10-07 0:40 ` [patch 59/71] udp: Fix rcv socket locking Greg KH
2008-10-07 0:40 ` [patch 60/71] sparc64: Fix PCI error interrupt registry on PSYCHO Greg KH
2008-12-29 17:14 ` [patch 60/71] sparc64: Fix PCI error interrupt registry on Geert Uytterhoeven
2008-12-29 17:14 ` [patch 60/71] sparc64: Fix PCI error interrupt registry on PSYCHO Geert Uytterhoeven
2008-12-30 2:36 ` [patch 60/71] sparc64: Fix PCI error interrupt registry on David Miller
2008-12-30 2:36 ` [patch 60/71] sparc64: Fix PCI error interrupt registry on PSYCHO David Miller
2008-10-07 0:40 ` [patch 61/71] sparc64: Fix interrupt register calculations on Psycho and Sabre Greg KH
2008-10-07 0:40 ` [patch 62/71] sparc64: Fix OOPS in psycho_pcierr_intr_other() Greg KH
2008-10-07 0:40 ` [patch 63/71] sparc64: Fix disappearing PCI devices on e3500 Greg KH
2008-10-07 0:40 ` [patch 64/71] sparc64: Fix missing devices due to PCI bridge test in of_create_pci_dev() Greg KH
2008-10-07 0:40 ` [patch 65/71] braille_console: only register notifiers when the braille console is used Greg KH
2008-10-07 0:40 ` [patch 66/71] ALSA: snd-powermac: mixers for PowerMac G4 AGP Greg KH
2008-10-07 0:40 ` [patch 67/71] ALSA: snd-powermac: HP detection for 1st iMac G3 SL Greg KH
2008-10-07 0:40 ` [patch 68/71] fbcon: fix monochrome color value calculation Greg KH
2008-10-07 0:40 ` Greg KH [this message]
2008-10-07 0:40 ` [patch 70/71] mm owner: fix race between swapoff and exit Greg KH
2008-10-07 0:40 ` [patch 71/71] S390: CVE-2008-1514: prevent ptrace padding area read/write in 31-bit mode Greg KH
2008-10-07 4:42 ` [patch 00/71] 2.6.26-stable review Grant Coady
2008-10-07 4:59 ` Greg KH
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20081007004026.GR3055@suse.de \
--to=gregkh@suse.de \
--cc=akpm@linux-foundation.org \
--cc=alan@lxorguk.ukuu.org.uk \
--cc=alessandro.zummo@towertech.it \
--cc=cavokz@gmail.com \
--cc=cebbert@redhat.com \
--cc=chuckw@quantumlinux.com \
--cc=davej@redhat.com \
--cc=dbrownell@users.sourceforge.net \
--cc=eteo@redhat.com \
--cc=jake@lwn.net \
--cc=jejb@kernel.org \
--cc=jmforbes@linuxtx.org \
--cc=linux-kernel@vger.kernel.org \
--cc=marcin.slusarz@gmail.com \
--cc=mkrufky@linuxtv.org \
--cc=rbranco@la.checkpoint.com \
--cc=rdunlap@xenotime.net \
--cc=reviews@ml.cw.f00f.org \
--cc=stable@kernel.org \
--cc=torvalds@linux-foundation.org \
--cc=tytso@mit.edu \
--cc=w@1wt.eu \
--cc=zwane@arm.linux.org.uk \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.