From: Steven Rostedt <rostedt@goodmis.org>
To: linux-kernel@vger.kernel.org,
linux-rt-users <linux-rt-users@vger.kernel.org>
Cc: Thomas Gleixner <tglx@linutronix.de>,
Carsten Emde <C.Emde@osadl.org>,
Sebastian Andrzej Siewior <bigeasy@linutronix.de>,
John Kacur <jkacur@redhat.com>,
Paul Gortmaker <paul.gortmaker@windriver.com>,
<stable-rt@vger.kernel.org>
Subject: [PATCH RT 20/25] arm/futex: disable preemption during futex_atomic_cmpxchg_inatomic()
Date: Fri, 13 Mar 2015 11:18:45 -0400 [thread overview]
Message-ID: <20150313151837.941137095@goodmis.org> (raw)
In-Reply-To: 20150313151825.583263173@goodmis.org
[-- Attachment #1: 0020-arm-futex-disable-preemption-during-futex_atomic_cmp.patch --]
[-- Type: text/plain, Size: 1795 bytes --]
3.2.68-rt99-rc1 stable review patch.
If anyone has any objections, please let me know.
------------------
From: Sebastian Andrzej Siewior <bigeasy@linutronix.de>
The ARM UP implementation of futex_atomic_cmpxchg_inatomic() assumes that
pagefault_disable() inherits a preempt disabled section. This assumtion
is true for mainline but -RT reverts this and allows preemption in
pagefault disabled regions.
The code sequence of futex_atomic_cmpxchg_inatomic():
| x = *futex;
| if (x == oldval)
| *futex = newval;
The problem occurs if the code is preempted after reading the futex value or
after comparing it with x. While preempted, the futex owner has to be
scheduled which then releases the lock (in userland because it has no waiter
yet). Once the code is back on the CPU, it overwrites the futex value
with with the old PID and the waiter bit set.
The workaround is to explicit disable code preemption to avoid the
described race window.
Debugged-by: Thomas Gleixner <tglx@linutronix.de>
Cc: stable-rt@vger.kernel.org
Signed-off-by: Sebastian Andrzej Siewior <bigeasy@linutronix.de>
Signed-off-by: Steven Rostedt <rostedt@goodmis.org>
---
arch/arm/include/asm/futex.h | 4 ++++
1 file changed, 4 insertions(+)
diff --git a/arch/arm/include/asm/futex.h b/arch/arm/include/asm/futex.h
index aefd4594c9bf..48fc90c7db20 100644
--- a/arch/arm/include/asm/futex.h
+++ b/arch/arm/include/asm/futex.h
@@ -86,6 +86,8 @@ futex_atomic_cmpxchg_inatomic(u32 *uval, u32 __user *uaddr,
int ret = 0;
u32 val;
+ preempt_disable_rt();
+
if (!access_ok(VERIFY_WRITE, uaddr, sizeof(u32)))
return -EFAULT;
@@ -100,6 +102,8 @@ futex_atomic_cmpxchg_inatomic(u32 *uval, u32 __user *uaddr,
: "cc", "memory");
*uval = val;
+
+ preempt_enable_rt();
return ret;
}
--
2.1.4
next prev parent reply other threads:[~2015-03-13 15:18 UTC|newest]
Thread overview: 25+ messages / expand[flat|nested] mbox.gz Atom feed top
2015-03-13 15:18 [PATCH RT 00/25] Linux 3.2.68-rt99-rc1 Steven Rostedt
2015-03-13 15:18 ` [PATCH RT 01/25] gpio: omap: use raw locks for locking Steven Rostedt
2015-03-13 15:18 ` [PATCH RT 02/25] create-rt-enqueue Steven Rostedt
2015-03-13 15:18 ` [PATCH RT 03/25] rtmutex: Simplify rtmutex_slowtrylock() Steven Rostedt
2015-03-13 15:18 ` [PATCH RT 04/25] rtmutex: Simplify and document try_to_take_rtmutex() Steven Rostedt
2015-03-13 15:18 ` [PATCH RT 05/25] rtmutex: No need to keep task ref for lock owner check Steven Rostedt
2015-03-13 15:18 ` [PATCH RT 06/25] rtmutex: Clarify the boost/deboost part Steven Rostedt
2015-03-13 15:18 ` [PATCH RT 07/25] rtmutex: Document pi chain walk Steven Rostedt
2015-03-13 15:18 ` [PATCH RT 08/25] rtmutex: Simplify remove_waiter() Steven Rostedt
2015-03-13 15:18 ` [PATCH RT 09/25] rtmutex: Confine deadlock logic to futex Steven Rostedt
2015-03-13 15:18 ` [PATCH RT 10/25] rtmutex: Cleanup deadlock detector debug logic Steven Rostedt
2015-03-13 15:18 ` [PATCH RT 11/25] rtmutex: Avoid pointless requeueing in the deadlock detection chain walk Steven Rostedt
2015-03-13 15:18 ` [PATCH RT 12/25] futex: Make unlock_pi more robust Steven Rostedt
2015-03-13 15:18 ` [PATCH RT 13/25] futex: Use futex_top_waiter() in lookup_pi_state() Steven Rostedt
2015-03-13 15:18 ` [PATCH RT 14/25] futex: Split out the waiter check from lookup_pi_state() Steven Rostedt
2015-03-13 15:18 ` [PATCH RT 15/25] futex: Split out the first waiter attachment " Steven Rostedt
2015-03-13 15:18 ` [PATCH RT 16/25] futex: Simplify futex_lock_pi_atomic() and make it more robust Steven Rostedt
2015-03-13 15:18 ` [PATCH RT 17/25] rt-mutex: avoid a NULL pointer dereference on deadlock Steven Rostedt
2015-03-13 15:18 ` [PATCH RT 18/25] x86: UV: raw_spinlock conversion Steven Rostedt
2015-03-13 15:18 ` Steven Rostedt [this message]
2015-03-13 15:18 ` [PATCH RT 21/25] scheduling while atomic in cgroup code Steven Rostedt
2015-03-13 15:18 ` [PATCH RT 22/25] work-simple: Simple work queue implemenation Steven Rostedt
2015-03-13 15:18 ` [PATCH RT 23/25] sunrpc: make svc_xprt_do_enqueue() use get_cpu_light() Steven Rostedt
2015-03-13 15:18 ` [PATCH RT 24/25] lockdep: selftest: fix warnings due to missing PREEMPT_RT conditionals Steven Rostedt
2015-03-13 15:18 ` [PATCH RT 25/25] Linux 3.2.68-rt99-rc1 Steven Rostedt
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20150313151837.941137095@goodmis.org \
--to=rostedt@goodmis.org \
--cc=C.Emde@osadl.org \
--cc=bigeasy@linutronix.de \
--cc=jkacur@redhat.com \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-rt-users@vger.kernel.org \
--cc=paul.gortmaker@windriver.com \
--cc=stable-rt@vger.kernel.org \
--cc=tglx@linutronix.de \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).