From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from bombadil.infradead.org (bombadil.infradead.org [198.137.202.133]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.lore.kernel.org (Postfix) with ESMTPS id 365A7C433EF for ; Fri, 31 Dec 2021 19:56:48 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=lists.infradead.org; s=bombadil.20210309; h=Sender: Content-Transfer-Encoding:Content-Type:MIME-Version:List-Subscribe:List-Help: List-Post:List-Archive:List-Unsubscribe:List-Id:References:In-Reply-To: Message-Id:Date:Subject:Cc:To:From:Reply-To:Content-ID:Content-Description: Resent-Date:Resent-From:Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID: List-Owner; bh=2gzPWSYJ+hliT5fsUcCHnfh0Ch/x04VUr2vRn1DpTvE=; b=alL8Ttq+FjnCrb JFWFtwN0xVMlHW9z2lpkbH7Dh0FmCfRK/87JIdyKWhrYiWeU4FCWD+6HdjPIX9hAltL1F8CnmMLTo modfHhmy/fsXTxlXPWqpSeOuw1vhBo+DosK1X7sdAosCIA/olIy8BBaYr0a2DoWMrl7L8gQkJkSN3 vD9J8JtnRYP6u3MXCT26E0ASoTqU/bzos+cyflYn19yKtz3ZFWf2qbiAsSvm/rW9MaxxWMTQjGlfQ CglAkTDU2SnHBOe7EuY0X1Qhv6+fK1SEhMuSyi9UEOAmeP2FBL6f8JDY0Mu/MQOJzSimDhdzvDbUD dGi8u8usxmN05A5VgFrg==; Received: from localhost ([::1] helo=bombadil.infradead.org) by bombadil.infradead.org with esmtp (Exim 4.94.2 #2 (Red Hat Linux)) id 1n3NzC-006UQb-19; Fri, 31 Dec 2021 19:54:46 +0000 Received: from mail-wm1-x32e.google.com ([2a00:1450:4864:20::32e]) by bombadil.infradead.org with esmtps (Exim 4.94.2 #2 (Red Hat Linux)) id 1n3Nz6-006UQB-GC; Fri, 31 Dec 2021 19:54:42 +0000 Received: by mail-wm1-x32e.google.com with SMTP id e5so17405685wmq.1; Fri, 31 Dec 2021 11:54:40 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20210112; h=from:to:cc:subject:date:message-id:in-reply-to:references; bh=hbbP5REJxkzE277o6NN+bUvjhJlIyki9X9Dnozc3Rz8=; b=DuUnSYWsG02OZpc9hsYB/UUB+xWsXPlBLfiPiKf3FqVMVZjcsYQ7A0J9xHlOmkkw6A J4A30ryxeIvJlr43OXoIlyKth58mIOrlv+DEarLJ6PwWe5pPj6HxisKWZgNEYC0HRoa4 /hGtR1dqfuZRRPh0T2dLkYQMeTqbJze0zsYrk7RTwOw3WVltd4InSTnzuwp5LUMos6kf i3EKgaoBjl3N0rdq0WfbMj7SoNUn9cPc+j/8JatXcKhcYihzybfadOs3p0xSBdLjRy78 H3FgrSu4sQ+m4IUkcTcbV1dTAd9c/K3jENrTfANo5sh5763W8anDBWm5W7dcG1qTljlj 2fdw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20210112; h=x-gm-message-state:from:to:cc:subject:date:message-id:in-reply-to :references; bh=hbbP5REJxkzE277o6NN+bUvjhJlIyki9X9Dnozc3Rz8=; b=FI7uhhusal1Ndogx54eupjT3D02TEICRjK6+op/rT/EZIgI851g6gqvJf5/czIdLyf BRQIQyDuKAJS5a/MdHGcUo3a4OSG7LDET8WCXBuQ/nDXUz6X1xjrGTStwFLyDb24j70M jniuFx+8U+zZtBvC5f49pjpwE0fv6bXSOhUSviFNUcZ+KkWIJkI/uOo3RCboqUkDXXRo vdX8QqD34ebYR22insssi2jNXn09JogygDRxKd2NMG/CpGL8fwrwRlALD0d23S1XVy8w 1POpygsNxKLx3i1kG4moSpUmxUFekvkzta2Fn19Oc5954rtzph0wVdv0G2rO5sgO6vr/ n7yA== X-Gm-Message-State: AOAM530NmHMEnH+3haBGL8/YtdLkEP9rz3fIUW/7/oFW1sJUgaVPb58d aboJHbDptwp5O3AfdH3zOLHq8/Fgw9fLs92/ X-Google-Smtp-Source: ABdhPJwMHckgo1feARnLZwukFr92TNoIKNgay3r5XkVgfFok+B5fqFHrWmdVqdsLweXRfX8tyXnWsA== X-Received: by 2002:a7b:cd0e:: with SMTP id f14mr30848930wmj.3.1640980478902; Fri, 31 Dec 2021 11:54:38 -0800 (PST) Received: from pswork.fritz.box (i5E86B4D2.versanet.de. [94.134.180.210]) by smtp.gmail.com with ESMTPSA id o64sm26730164wme.28.2021.12.31.11.54.37 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Fri, 31 Dec 2021 11:54:38 -0800 (PST) From: Padmanabha Srinivasaiah To: linux-rpi-kernel@lists.infradead.org, linux-arm-kernel@lists.infradead.org, linux-staging@lists.linux.dev, linux-kernel@vger.kernel.org, stefan.wahren@i2se.com Cc: gregkh@linuxfoundation.org, nsaenz@kernel.org, treasure4paddy@gmail.com, Gaston Gonzalez , Ojaswin Mujoo , Arnd Bergmann , Phil Elwell , bcm-kernel-feedback-list@broadcom.com Subject: [PATCH v3] staging: vc04_services: Fix RCU dereference check Date: Fri, 31 Dec 2021 20:54:03 +0100 Message-Id: <20211231195406.5479-1-treasure4paddy@gmail.com> X-Mailer: git-send-email 2.17.1 In-Reply-To: <20211231185611.GA4463@pswork> References: <20211231185611.GA4463@pswork> X-CRM114-Version: 20100106-BlameMichelson ( TRE 0.8.0 (BSD) ) MR-646709E3 X-CRM114-CacheID: sfid-20211231_115440_586925_A5211652 X-CRM114-Status: GOOD ( 11.93 ) X-BeenThere: linux-arm-kernel@lists.infradead.org X-Mailman-Version: 2.1.34 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , MIME-Version: 1.0 Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: 7bit Sender: "linux-arm-kernel" Errors-To: linux-arm-kernel-bounces+linux-arm-kernel=archiver.kernel.org@lists.infradead.org In service_callback path RCU dereferenced pointer struct vchiq_service need to be accessed inside rcu read-critical section. Also userdata/user_service part of vchiq_service is accessed around different synchronization mechanism, getting an extra reference to a pointer keeps sematics simpler and avoids prolonged graceperiod. Accessing vchiq_service with rcu_read_[lock/unlock] fixes below issue. [ 32.201659] ============================= [ 32.201664] WARNING: suspicious RCU usage [ 32.201670] 5.15.11-rt24-v8+ #3 Not tainted [ 32.201680] ----------------------------- [ 32.201685] drivers/staging/vc04_services/interface/vchiq_arm/vchiq_core.h:529 suspicious rcu_dereference_check() usage! [ 32.201695] [ 32.201695] other info that might help us debug this: [ 32.201695] [ 32.201700] [ 32.201700] rcu_scheduler_active = 2, debug_locks = 1 [ 32.201708] no locks held by vchiq-slot/0/98. [ 32.201715] [ 32.201715] stack backtrace: [ 32.201723] CPU: 1 PID: 98 Comm: vchiq-slot/0 Not tainted 5.15.11-rt24-v8+ #3 [ 32.201733] Hardware name: Raspberry Pi 4 Model B Rev 1.4 (DT) [ 32.201739] Call trace: [ 32.201742] dump_backtrace+0x0/0x1b8 [ 32.201772] show_stack+0x20/0x30 [ 32.201784] dump_stack_lvl+0x8c/0xb8 [ 32.201799] dump_stack+0x18/0x34 [ 32.201808] lockdep_rcu_suspicious+0xe4/0xf8 [ 32.201817] service_callback+0x124/0x400 [ 32.201830] slot_handler_func+0xf60/0x1e20 [ 32.201839] kthread+0x19c/0x1a8 [ 32.201849] ret_from_fork+0x10/0x20 Signed-off-by: Padmanabha Srinivasaiah --- Change in v3: Taking an extra reference for service pointer to keep semantics simpler to accesses in different synchronization mechanism. Changes in v2: RCU dereferenced pointer need to be accessed inside rcu read-side critical section. .../interface/vchiq_arm/vchiq_arm.c | 20 +++++++++++++++++-- 1 file changed, 18 insertions(+), 2 deletions(-) diff --git a/drivers/staging/vc04_services/interface/vchiq_arm/vchiq_arm.c b/drivers/staging/vc04_services/interface/vchiq_arm/vchiq_arm.c index 6759a6261500..3a2e4582db8e 100644 --- a/drivers/staging/vc04_services/interface/vchiq_arm/vchiq_arm.c +++ b/drivers/staging/vc04_services/interface/vchiq_arm/vchiq_arm.c @@ -1058,15 +1058,27 @@ service_callback(enum vchiq_reason reason, struct vchiq_header *header, DEBUG_TRACE(SERVICE_CALLBACK_LINE); + rcu_read_lock(); service = handle_to_service(handle); - if (WARN_ON(!service)) + if (WARN_ON(!service)) { + rcu_read_unlock(); return VCHIQ_SUCCESS; + } user_service = (struct user_service *)service->base.userdata; instance = user_service->instance; - if (!instance || instance->closing) + if (!instance || instance->closing) { + rcu_read_unlock(); return VCHIQ_SUCCESS; + } + + /* + * As hopping around different synchronization mechanism, + * taking an extra reference results in simpler implementation. + */ + vchiq_service_get(service); + rcu_read_unlock(); vchiq_log_trace(vchiq_arm_log_level, "%s - service %lx(%d,%p), reason %d, header %lx, instance %lx, bulk_userdata %lx", @@ -1097,6 +1109,7 @@ service_callback(enum vchiq_reason reason, struct vchiq_header *header, bulk_userdata); if (status != VCHIQ_SUCCESS) { DEBUG_TRACE(SERVICE_CALLBACK_LINE); + vchiq_service_put(service); return status; } } @@ -1105,10 +1118,12 @@ service_callback(enum vchiq_reason reason, struct vchiq_header *header, if (wait_for_completion_interruptible(&user_service->remove_event)) { vchiq_log_info(vchiq_arm_log_level, "%s interrupted", __func__); DEBUG_TRACE(SERVICE_CALLBACK_LINE); + vchiq_service_put(service); return VCHIQ_RETRY; } else if (instance->closing) { vchiq_log_info(vchiq_arm_log_level, "%s closing", __func__); DEBUG_TRACE(SERVICE_CALLBACK_LINE); + vchiq_service_put(service); return VCHIQ_ERROR; } DEBUG_TRACE(SERVICE_CALLBACK_LINE); @@ -1137,6 +1152,7 @@ service_callback(enum vchiq_reason reason, struct vchiq_header *header, header = NULL; } DEBUG_TRACE(SERVICE_CALLBACK_LINE); + vchiq_service_put(service); if (skip_completion) return VCHIQ_SUCCESS; -- 2.17.1 _______________________________________________ linux-arm-kernel mailing list linux-arm-kernel@lists.infradead.org http://lists.infradead.org/mailman/listinfo/linux-arm-kernel