* [PATCH RESEND v2 1/2] ucount: Fix atomic_long_inc_below() argument type
@ 2025-07-21 17:45 Uros Bizjak
2025-07-21 17:45 ` [PATCH RESEND v2 2/2] ucount: Use atomic_long_try_cmpxchg() in atomic_long_inc_below() Uros Bizjak
2025-07-21 22:43 ` [PATCH RESEND v2 1/2] ucount: Fix atomic_long_inc_below() argument type Andrew Morton
0 siblings, 2 replies; 5+ messages in thread
From: Uros Bizjak @ 2025-07-21 17:45 UTC (permalink / raw)
To: linux-kernel
Cc: Uros Bizjak, Eric W. Biederman, Andrew Morton,
Sebastian Andrzej Siewior, Paul E. McKenney, Alexey Gladkov,
Roman Gushchin, MengEn Sun, Thomas Weißschuh
The type of u argument of atomic_long_inc_below() should be long
to avoid unwanted truncation to int.
Fixes: f9c82a4ea89c ("Increase size of ucounts to atomic_long_t")
Signed-off-by: Uros Bizjak <ubizjak@gmail.com>
Reviewed-by: "Eric W. Biederman" <ebiederm@xmission.com>
Cc: Andrew Morton <akpm@linux-foundation.org>
Cc: Sebastian Andrzej Siewior <bigeasy@linutronix.de>
Cc: "Paul E. McKenney" <paulmck@kernel.org>
Cc: Alexey Gladkov <legion@kernel.org>
Cc: Roman Gushchin <roman.gushchin@linux.dev>
Cc: MengEn Sun <mengensun@tencent.com>
Cc: "Thomas Weißschuh" <linux@weissschuh.net>
---
kernel/ucount.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/kernel/ucount.c b/kernel/ucount.c
index 8686e329b8f2..f629db485a07 100644
--- a/kernel/ucount.c
+++ b/kernel/ucount.c
@@ -199,7 +199,7 @@ void put_ucounts(struct ucounts *ucounts)
}
}
-static inline bool atomic_long_inc_below(atomic_long_t *v, int u)
+static inline bool atomic_long_inc_below(atomic_long_t *v, long u)
{
long c, old;
c = atomic_long_read(v);
--
2.50.1
^ permalink raw reply related [flat|nested] 5+ messages in thread
* [PATCH RESEND v2 2/2] ucount: Use atomic_long_try_cmpxchg() in atomic_long_inc_below()
2025-07-21 17:45 [PATCH RESEND v2 1/2] ucount: Fix atomic_long_inc_below() argument type Uros Bizjak
@ 2025-07-21 17:45 ` Uros Bizjak
2025-07-21 22:43 ` [PATCH RESEND v2 1/2] ucount: Fix atomic_long_inc_below() argument type Andrew Morton
1 sibling, 0 replies; 5+ messages in thread
From: Uros Bizjak @ 2025-07-21 17:45 UTC (permalink / raw)
To: linux-kernel
Cc: Uros Bizjak, Alexey Gladkov, Andrew Morton,
Sebastian Andrzej Siewior, Paul E. McKenney, Roman Gushchin,
MengEn Sun, Thomas Weißschuh
Use atomic_long_try_cmpxchg() instead of
atomic_long_cmpxchg (*ptr, old, new) == old in atomic_long_inc_below().
x86 CMPXCHG instruction returns success in ZF flag, so this change saves
a compare after cmpxchg (and related move instruction in front of cmpxchg).
Also, atomic_long_try_cmpxchg implicitly assigns old *ptr value to "old"
when cmpxchg fails, enabling further code simplifications.
No functional change intended.
Signed-off-by: Uros Bizjak <ubizjak@gmail.com>
Reviewed-by: Alexey Gladkov <legion@kernel.org>
Cc: Andrew Morton <akpm@linux-foundation.org>
Cc: Sebastian Andrzej Siewior <bigeasy@linutronix.de>
Cc: "Paul E. McKenney" <paulmck@kernel.org>
Cc: Alexey Gladkov <legion@kernel.org>
Cc: Roman Gushchin <roman.gushchin@linux.dev>
Cc: MengEn Sun <mengensun@tencent.com>
Cc: "Thomas Weißschuh" <linux@weissschuh.net>
---
kernel/ucount.c | 14 ++++++--------
1 file changed, 6 insertions(+), 8 deletions(-)
diff --git a/kernel/ucount.c b/kernel/ucount.c
index f629db485a07..586af49fc03e 100644
--- a/kernel/ucount.c
+++ b/kernel/ucount.c
@@ -201,16 +201,14 @@ void put_ucounts(struct ucounts *ucounts)
static inline bool atomic_long_inc_below(atomic_long_t *v, long u)
{
- long c, old;
- c = atomic_long_read(v);
- for (;;) {
+ long c = atomic_long_read(v);
+
+ do {
if (unlikely(c >= u))
return false;
- old = atomic_long_cmpxchg(v, c, c+1);
- if (likely(old == c))
- return true;
- c = old;
- }
+ } while (!atomic_long_try_cmpxchg(v, &c, c+1));
+
+ return true;
}
struct ucounts *inc_ucount(struct user_namespace *ns, kuid_t uid,
--
2.50.1
^ permalink raw reply related [flat|nested] 5+ messages in thread
* Re: [PATCH RESEND v2 1/2] ucount: Fix atomic_long_inc_below() argument type
2025-07-21 17:45 [PATCH RESEND v2 1/2] ucount: Fix atomic_long_inc_below() argument type Uros Bizjak
2025-07-21 17:45 ` [PATCH RESEND v2 2/2] ucount: Use atomic_long_try_cmpxchg() in atomic_long_inc_below() Uros Bizjak
@ 2025-07-21 22:43 ` Andrew Morton
2025-07-22 6:44 ` Uros Bizjak
1 sibling, 1 reply; 5+ messages in thread
From: Andrew Morton @ 2025-07-21 22:43 UTC (permalink / raw)
To: Uros Bizjak
Cc: linux-kernel, Eric W. Biederman, Sebastian Andrzej Siewior,
Paul E. McKenney, Alexey Gladkov, Roman Gushchin, MengEn Sun,
Thomas Weißschuh
On Mon, 21 Jul 2025 19:45:57 +0200 Uros Bizjak <ubizjak@gmail.com> wrote:
> The type of u argument of atomic_long_inc_below() should be long
> to avoid unwanted truncation to int.
>
> Fixes: f9c82a4ea89c ("Increase size of ucounts to atomic_long_t")
Please (always!) provide a description of the userspace-visible effects
of the bug. That way I (and others) can decide whether the fix should
be backported. And people will be able to determine whether this patch
may fix problems which they are observing. Thanks.
^ permalink raw reply [flat|nested] 5+ messages in thread
* Re: [PATCH RESEND v2 1/2] ucount: Fix atomic_long_inc_below() argument type
2025-07-21 22:43 ` [PATCH RESEND v2 1/2] ucount: Fix atomic_long_inc_below() argument type Andrew Morton
@ 2025-07-22 6:44 ` Uros Bizjak
2025-07-22 9:48 ` Mark Rutland
0 siblings, 1 reply; 5+ messages in thread
From: Uros Bizjak @ 2025-07-22 6:44 UTC (permalink / raw)
To: Andrew Morton
Cc: linux-kernel, Eric W. Biederman, Sebastian Andrzej Siewior,
Paul E. McKenney, Alexey Gladkov, Roman Gushchin, MengEn Sun,
Thomas Weißschuh
On Tue, Jul 22, 2025 at 12:43 AM Andrew Morton
<akpm@linux-foundation.org> wrote:
>
> On Mon, 21 Jul 2025 19:45:57 +0200 Uros Bizjak <ubizjak@gmail.com> wrote:
>
> > The type of u argument of atomic_long_inc_below() should be long
> > to avoid unwanted truncation to int.
> >
> > Fixes: f9c82a4ea89c ("Increase size of ucounts to atomic_long_t")
>
> Please (always!) provide a description of the userspace-visible effects
> of the bug. That way I (and others) can decide whether the fix should
> be backported. And people will be able to determine whether this patch
> may fix problems which they are observing. Thanks.
The patch fixes the wrong argument type of an internal function to
prevent unwanted argument truncation. It fixes an internal locking
primitive; it should not have any direct effect on userspace.
Uros.
^ permalink raw reply [flat|nested] 5+ messages in thread
* Re: [PATCH RESEND v2 1/2] ucount: Fix atomic_long_inc_below() argument type
2025-07-22 6:44 ` Uros Bizjak
@ 2025-07-22 9:48 ` Mark Rutland
0 siblings, 0 replies; 5+ messages in thread
From: Mark Rutland @ 2025-07-22 9:48 UTC (permalink / raw)
To: Uros Bizjak
Cc: Andrew Morton, linux-kernel, Eric W. Biederman,
Sebastian Andrzej Siewior, Paul E. McKenney, Alexey Gladkov,
Roman Gushchin, MengEn Sun, Thomas Weißschuh
On Tue, Jul 22, 2025 at 08:44:29AM +0200, Uros Bizjak wrote:
> On Tue, Jul 22, 2025 at 12:43 AM Andrew Morton
> <akpm@linux-foundation.org> wrote:
> >
> > On Mon, 21 Jul 2025 19:45:57 +0200 Uros Bizjak <ubizjak@gmail.com> wrote:
> >
> > > The type of u argument of atomic_long_inc_below() should be long
> > > to avoid unwanted truncation to int.
> > >
> > > Fixes: f9c82a4ea89c ("Increase size of ucounts to atomic_long_t")
> >
> > Please (always!) provide a description of the userspace-visible effects
> > of the bug. That way I (and others) can decide whether the fix should
> > be backported. And people will be able to determine whether this patch
> > may fix problems which they are observing. Thanks.
>
> The patch fixes the wrong argument type of an internal function to
> prevent unwanted argument truncation. It fixes an internal locking
> primitive; it should not have any direct effect on userspace.
AFAICT there's no problem in practice because atomic_long_inc_below() is
only used by inc_ucount(), and it looks like the value is constrained
between 0 and INT_MAX.
In inc_ucount() the limit value is taken from
user_namespace::ucount_max[], and AFAICT that's only written by sysctls,
to the table setup by setup_userns_sysctls(), where UCOUNT_ENTRY()
limits the value between 0 and INT_MAX.
This is certainly a cleanup, but there might be no functional issue in
practice as above.
Mark.
^ permalink raw reply [flat|nested] 5+ messages in thread
end of thread, other threads:[~2025-07-22 9:48 UTC | newest]
Thread overview: 5+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2025-07-21 17:45 [PATCH RESEND v2 1/2] ucount: Fix atomic_long_inc_below() argument type Uros Bizjak
2025-07-21 17:45 ` [PATCH RESEND v2 2/2] ucount: Use atomic_long_try_cmpxchg() in atomic_long_inc_below() Uros Bizjak
2025-07-21 22:43 ` [PATCH RESEND v2 1/2] ucount: Fix atomic_long_inc_below() argument type Andrew Morton
2025-07-22 6:44 ` Uros Bizjak
2025-07-22 9:48 ` Mark Rutland
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.