From: Douglas Gilbert <dgilbert@interlog.com>
To: linux-scsi@vger.kernel.org
Cc: martin.petersen@oracle.com, jejb@linux.vnet.ibm.com, hare@suse.de
Subject: [PATCH v17 34/45] sg: protect multiple receivers
Date: Wed, 7 Apr 2021 21:45:20 -0400 [thread overview]
Message-ID: <20210408014531.248890-35-dgilbert@interlog.com> (raw)
In-Reply-To: <20210408014531.248890-1-dgilbert@interlog.com>
If two threads call ioctl(SG_IORECEIVE) [or read()] on the same
file descriptor there is a potential race on the same request
response. Use atomic bit operations to make sure only one thread
gets each request response. [The other thread will either get
another request response or nothing.]
Also make sfp cleanup a bit more robust and report if the
number of submitted requests (which are decremented when
completed) is other than the expected value of zero.
Reviewed-by: Hannes Reinecke <hare@suse.de>
Signed-off-by: Douglas Gilbert <dgilbert@interlog.com>
---
drivers/scsi/sg.c | 48 ++++++++++++++++++++++++++++++++++-------------
1 file changed, 35 insertions(+), 13 deletions(-)
diff --git a/drivers/scsi/sg.c b/drivers/scsi/sg.c
index 88235dc0be4a..e751e1dc832a 100644
--- a/drivers/scsi/sg.c
+++ b/drivers/scsi/sg.c
@@ -109,6 +109,7 @@ enum sg_rq_state { /* N.B. sg_rq_state_arr assumes SG_RS_AWAIT_RCV==2 */
#define SG_FRQ_SYNC_INVOC 2 /* synchronous (blocking) invocation */
#define SG_FRQ_NO_US_XFER 3 /* no user space transfer of data */
#define SG_FRQ_DEACT_ORPHAN 6 /* not keeping orphan so de-activate */
+#define SG_FRQ_RECEIVING 7 /* guard against multiple receivers */
/* Bit positions (flags) for sg_fd::ffd_bm bitmask follow */
#define SG_FFD_FORCE_PACKID 0 /* receive only given pack_id/tag */
@@ -1275,6 +1276,7 @@ sg_ctl_ioreceive(struct file *filp, struct sg_fd *sfp, void __user *p)
SG_LOG(3, sfp, "%s: non_block(+IMMED)=%d\n", __func__, non_block);
/* read in part of v3 or v4 header for pack_id or tag based find */
id = pack_id;
+try_again:
srp = sg_find_srp_by_id(sfp, id);
if (!srp) { /* nothing available so wait on packet or */
if (unlikely(SG_IS_DETACHING(sdp)))
@@ -1289,6 +1291,10 @@ sg_ctl_ioreceive(struct file *filp, struct sg_fd *sfp, void __user *p)
if (res)
return res; /* signal --> -ERESTARTSYS */
} /* now srp should be valid */
+ if (test_and_set_bit(SG_FRQ_RECEIVING, srp->frq_bm)) {
+ cpu_relax();
+ goto try_again;
+ }
return sg_receive_v4(sfp, srp, p, h4p);
}
@@ -1325,7 +1331,7 @@ sg_ctl_ioreceive_v3(struct file *filp, struct sg_fd *sfp, void __user *p)
if (test_bit(SG_FFD_FORCE_PACKID, sfp->ffd_bm))
pack_id = h3p->pack_id;
-
+try_again:
srp = sg_find_srp_by_id(sfp, pack_id);
if (!srp) { /* nothing available so wait on packet or */
if (unlikely(SG_IS_DETACHING(sdp)))
@@ -1340,6 +1346,10 @@ sg_ctl_ioreceive_v3(struct file *filp, struct sg_fd *sfp, void __user *p)
if (unlikely(res))
return res; /* signal --> -ERESTARTSYS */
} /* now srp should be valid */
+ if (test_and_set_bit(SG_FRQ_RECEIVING, srp->frq_bm)) {
+ cpu_relax();
+ goto try_again;
+ }
return sg_receive_v3(sfp, srp, SZ_SG_IO_HDR, p);
}
@@ -1492,6 +1502,7 @@ sg_read(struct file *filp, char __user *p, size_t count, loff_t *ppos)
want_id = h2p->pack_id;
}
}
+try_again:
srp = sg_find_srp_by_id(sfp, want_id);
if (!srp) { /* nothing available so wait on packet to arrive or */
if (unlikely(SG_IS_DETACHING(sdp)))
@@ -1507,6 +1518,10 @@ sg_read(struct file *filp, char __user *p, size_t count, loff_t *ppos)
return ret;
/* otherwise srp should be valid */
}
+ if (test_and_set_bit(SG_FRQ_RECEIVING, srp->frq_bm)) {
+ cpu_relax();
+ goto try_again;
+ }
if (srp->s_hdr3.interface_id == '\0')
ret = sg_read_v1v2(p, (int)count, sfp, srp);
else
@@ -3024,28 +3039,29 @@ sg_finish_scsi_blk_rq(struct sg_request *srp)
atomic_dec(&sfp->submitted);
atomic_dec(&sfp->waiting);
}
+
+ /* Expect blk_put_request(rq) already called in sg_rq_end_io() */
+ if (rq) { /* blk_get_request() may have failed */
+ srp->rq = NULL;
+ if (scsi_req(rq))
+ scsi_req_free_cmd(scsi_req(rq));
+ blk_put_request(rq);
+ }
if (srp->bio) {
bool us_xfer = !test_bit(SG_FRQ_NO_US_XFER, srp->frq_bm);
+ struct bio *bio = srp->bio;
- if (us_xfer) {
- ret = blk_rq_unmap_user(srp->bio);
+ srp->bio = NULL;
+ if (us_xfer && bio) {
+ ret = blk_rq_unmap_user(bio);
if (ret) { /* -EINTR (-4) can be ignored */
SG_LOG(6, sfp,
"%s: blk_rq_unmap_user() --> %d\n",
__func__, ret);
}
}
- srp->bio = NULL;
- }
- /* In worst case READ data returned to user space by this point */
-
- /* Expect blk_put_request(rq) already called in sg_rq_end_io() */
- if (rq) { /* blk_get_request() may have failed */
- if (scsi_req(rq))
- scsi_req_free_cmd(scsi_req(rq));
- srp->rq = NULL;
- blk_put_request(rq);
}
+ /* In worst case, READ data returned to user space by this point */
}
static int
@@ -3475,6 +3491,7 @@ sg_deact_request(struct sg_fd *sfp, struct sg_request *srp)
return;
sbp = srp->sense_bp;
srp->sense_bp = NULL;
+ srp->frq_bm[0] = 0;
sg_rq_state_chg(srp, 0, SG_RS_INACTIVE, true /* force */, __func__);
/* maybe orphaned req, thus never read */
if (sbp)
@@ -3607,6 +3624,7 @@ static void
sg_remove_sfp_usercontext(struct work_struct *work)
{
__maybe_unused int o_count;
+ int subm;
unsigned long idx, iflags;
struct sg_device *sdp;
struct sg_fd *sfp = container_of(work, struct sg_fd, ew_fd.work);
@@ -3644,6 +3662,10 @@ sg_remove_sfp_usercontext(struct work_struct *work)
SG_LOG(6, sfp, "%s: kfree: srp=%pK --\n", __func__, srp);
kfree(srp);
}
+ subm = atomic_read(&sfp->submitted);
+ if (subm != 0)
+ SG_LOG(1, sfp, "%s: expected submitted=0 got %d\n",
+ __func__, subm);
xa_destroy(xafp);
xa_lock_irqsave(xadp, iflags);
e_sfp = __xa_erase(xadp, sfp->idx);
--
2.25.1
next prev parent reply other threads:[~2021-04-08 1:46 UTC|newest]
Thread overview: 53+ messages / expand[flat|nested] mbox.gz Atom feed top
2021-04-08 1:44 [PATCH v17 00/45] sg: add v4 interface Douglas Gilbert
2021-04-08 1:44 ` [PATCH v17 01/45] sg: move functions around Douglas Gilbert
2021-04-08 1:44 ` [PATCH v17 02/45] sg: remove typedefs, type+formatting cleanup Douglas Gilbert
2021-04-08 1:44 ` [PATCH v17 03/45] sg: sg_log and is_enabled Douglas Gilbert
2021-04-08 1:44 ` [PATCH v17 04/45] sg: rework sg_poll(), minor changes Douglas Gilbert
2021-04-08 1:44 ` [PATCH v17 05/45] sg: bitops in sg_device Douglas Gilbert
2021-04-08 1:44 ` [PATCH v17 06/45] sg: make open count an atomic Douglas Gilbert
2021-04-08 1:44 ` [PATCH v17 07/45] sg: move header to uapi section Douglas Gilbert
2021-04-08 1:44 ` [PATCH v17 08/45] sg: speed sg_poll and sg_get_num_waiting Douglas Gilbert
2021-04-08 1:44 ` [PATCH v17 09/45] sg: sg_allow_if_err_recovery and renames Douglas Gilbert
2021-04-08 1:44 ` [PATCH v17 10/45] sg: improve naming Douglas Gilbert
2021-04-08 1:44 ` [PATCH v17 11/45] sg: change rwlock to spinlock Douglas Gilbert
2021-04-08 1:44 ` [PATCH v17 12/45] sg: ioctl handling Douglas Gilbert
2021-04-08 1:44 ` [PATCH v17 13/45] sg: split sg_read Douglas Gilbert
2021-04-08 1:45 ` [PATCH v17 14/45] sg: sg_common_write add structure for arguments Douglas Gilbert
2021-04-08 1:45 ` [PATCH v17 15/45] sg: rework sg_vma_fault Douglas Gilbert
2021-04-08 1:45 ` [PATCH v17 16/45] sg: rework sg_mmap Douglas Gilbert
2021-04-08 1:45 ` [PATCH v17 17/45] sg: replace sg_allow_access Douglas Gilbert
2021-04-08 1:45 ` [PATCH v17 18/45] sg: rework scatter gather handling Douglas Gilbert
2021-04-08 1:45 ` [PATCH v17 19/45] sg: introduce request state machine Douglas Gilbert
2021-04-08 1:45 ` [PATCH v17 20/45] sg: sg_find_srp_by_id Douglas Gilbert
2021-04-08 1:45 ` [PATCH v17 21/45] sg: sg_fill_request_element Douglas Gilbert
2021-04-08 1:45 ` [PATCH v17 22/45] sg: printk change %p to %pK Douglas Gilbert
2021-04-08 1:45 ` [PATCH v17 23/45] sg: xarray for fds in device Douglas Gilbert
2021-04-08 1:45 ` [PATCH v17 24/45] sg: xarray for reqs in fd Douglas Gilbert
2021-04-08 8:05 ` Hannes Reinecke
2021-04-08 1:45 ` [PATCH v17 25/45] sg: replace rq array with xarray Douglas Gilbert
2021-04-08 1:45 ` [PATCH v17 26/45] sg: sense buffer rework Douglas Gilbert
2021-04-08 1:45 ` [PATCH v17 27/45] sg: add sg v4 interface support Douglas Gilbert
2021-04-08 1:45 ` [PATCH v17 28/45] sg: rework debug info Douglas Gilbert
2021-04-08 8:06 ` Hannes Reinecke
2021-04-08 1:45 ` [PATCH v17 29/45] sg: add 8 byte SCSI LUN to sg_scsi_id Douglas Gilbert
2021-04-08 1:45 ` [PATCH v17 30/45] sg: expand sg_comm_wr_t Douglas Gilbert
2021-04-08 1:45 ` [PATCH v17 31/45] sg: add sg_iosubmit_v3 and sg_ioreceive_v3 ioctls Douglas Gilbert
2021-04-08 1:45 ` [PATCH v17 32/45] sg: add some __must_hold macros Douglas Gilbert
2021-04-08 1:45 ` [PATCH v17 33/45] sg: move procfs objects to avoid forward decls Douglas Gilbert
2021-04-08 1:45 ` Douglas Gilbert [this message]
2021-04-08 1:45 ` [PATCH v17 35/45] sg: first debugfs support Douglas Gilbert
2021-04-08 1:45 ` [PATCH v17 36/45] sg: rework mmap support Douglas Gilbert
2021-04-08 1:45 ` [PATCH v17 37/45] sg: defang allow_dio Douglas Gilbert
2021-04-08 1:45 ` [PATCH v17 38/45] sg: warn v3 write system call users Douglas Gilbert
2021-04-08 1:45 ` [PATCH v17 39/45] sg: add mmap_sz tracking Douglas Gilbert
2021-04-08 8:07 ` Hannes Reinecke
2021-04-08 1:45 ` [PATCH v17 40/45] sg: remove rcv_done request state Douglas Gilbert
2021-04-08 1:45 ` [PATCH v17 41/45] sg: track lowest inactive and await indexes Douglas Gilbert
2021-04-08 1:45 ` [PATCH v17 42/45] sg: remove unit attention check for device changed Douglas Gilbert
2021-04-08 1:45 ` [PATCH v17 43/45] sg: no_dxfer: move to/from kernel buffers Douglas Gilbert
2021-04-08 8:07 ` Hannes Reinecke
2021-04-08 1:45 ` [PATCH v17 44/45] sg: add blk_poll support Douglas Gilbert
2021-04-08 8:14 ` Hannes Reinecke
2021-04-08 16:28 ` Douglas Gilbert
2021-04-09 6:00 ` Douglas Gilbert
2021-04-08 1:45 ` [PATCH v17 45/45] sg: bump version to 4.0.12 Douglas Gilbert
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20210408014531.248890-35-dgilbert@interlog.com \
--to=dgilbert@interlog.com \
--cc=hare@suse.de \
--cc=jejb@linux.vnet.ibm.com \
--cc=linux-scsi@vger.kernel.org \
--cc=martin.petersen@oracle.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox