public inbox for linux-kernel@vger.kernel.org
 help / color / mirror / Atom feed
* [PATCH] cred - synchronize rcu before releasing cred
@ 2010-06-16 12:24 Jiri Olsa
  2010-06-16 12:45 ` Eric Dumazet
  0 siblings, 1 reply; 25+ messages in thread
From: Jiri Olsa @ 2010-06-16 12:24 UTC (permalink / raw)
  To: dhowells; +Cc: linux-kernel, Jiri Olsa

hi,

BZ 591015 - kernel BUG at kernel/cred.c:168
https://bugzilla.redhat.com/show_bug.cgi?id=591015

Above bugzilla reported bug during the releasing of
old cred structure.

There is reproducer attached to the bugzilla.

The issue is caused by releasing old cred struct while other
kernel path might be still using it. This leads to cred->usage
inconsistency inside the __put_cred and triggering the bug.

Following kernel paths are affected:

The CPU1 path is setting the new groups creds.
The CPU2 path is cat /proc/PID/status


CPU 1                              CPU 2

sys_setgroups                      proc_pid_status      
  set_current_groups                 task_state
    commit_creds                       rcu_read_lock
      put_cred                         ...
        __put_cred                     get_cred
          BUG_ON(usage != 0)           ...
                                       rcu_read_unlock
                                       


If __put_cred got executed during the CPU2 holding the reference
the BUG_ON inside __put_cred is trigered.

I put synchronize_rcu before put_cred call, so we are sure
all the rcu_read_lock blocks are finished, and if needed, using
new creds.

Also I moved rcu_read_unlock below the put_cred for consistency.


wbr,
jirka


Signed-off-by: Jiri Olsa <jolsa@redhat.com>
---
 fs/proc/array.c |    3 ++-
 kernel/cred.c   |    6 ++++++
 2 files changed, 8 insertions(+), 1 deletions(-)

diff --git a/fs/proc/array.c b/fs/proc/array.c
index 9b58d38..c0e60d1 100644
--- a/fs/proc/array.c
+++ b/fs/proc/array.c
@@ -199,7 +199,6 @@ static inline void task_state(struct seq_file *m, struct pid_namespace *ns,
 		"FDSize:\t%d\n"
 		"Groups:\t",
 		fdt ? fdt->max_fds : 0);
-	rcu_read_unlock();
 
 	group_info = cred->group_info;
 	task_unlock(p);
@@ -208,6 +207,8 @@ static inline void task_state(struct seq_file *m, struct pid_namespace *ns,
 		seq_printf(m, "%d ", GROUP_AT(group_info, g));
 	put_cred(cred);
 
+	rcu_read_unlock();
+
 	seq_printf(m, "\n");
 }
 
diff --git a/kernel/cred.c b/kernel/cred.c
index a2d5504..4872f12 100644
--- a/kernel/cred.c
+++ b/kernel/cred.c
@@ -510,6 +510,12 @@ int commit_creds(struct cred *new)
 	    new->fsgid != old->fsgid)
 		proc_id_connector(task, PROC_EVENT_GID);
 
+	/*
+	 * New cred is set already, now let the old one
+	 * chance to disappear on other CPUs.
+	 */
+	synchronize_rcu();
+
 	/* release the old obj and subj refs both */
 	put_cred(old);
 	put_cred(old);

^ permalink raw reply related	[flat|nested] 25+ messages in thread
* [PATCH] cred - synchronize rcu before releasing cred
@ 2010-06-25 13:33 Jiri Olsa
  2010-07-02 12:14 ` Jiri Olsa
  0 siblings, 1 reply; 25+ messages in thread
From: Jiri Olsa @ 2010-06-25 13:33 UTC (permalink / raw)
  To: linux-security-module
  Cc: David Howells, Eric Dumazet, linux-kernel, Paul E. McKenney

BZ 591015 - kernel BUG at kernel/cred.c:168
https://bugzilla.redhat.com/show_bug.cgi?id=591015

Above bugzilla reported bug during the releasing of
old cred structure.

There is reproducer attached to the bugzilla.

The issue is caused by releasing old cred struct while other
kernel path might be still using it. This leads to cred->usage
inconsistency inside the __put_cred and triggering the bug.

Following kernel paths are affected:

The CPU1 path is setting the new groups creds.
The CPU2 path is cat /proc/PID/status


CPU 1                              CPU 2

sys_setgroups                      proc_pid_status      
  set_current_groups                 task_state
    commit_creds                       rcu_read_lock
      put_cred                         ...
        __put_cred                     get_cred
          BUG_ON(usage != 0)           ...
                                       rcu_read_unlock
                                       


If __put_cred got executed during the CPU2 holding the reference
the BUG_ON inside __put_cred is trigered.

I think there's no need to get the cred refference as long as
the 'cred' handling stays inside the rcu_read_lock block.

And the condition of __task_cred 'make sure task doesn't go away',
is done by proc_single_show as this is the proc file.

wbr,
jirka


Signed-off-by: Jiri Olsa <jolsa@redhat.com>
Acked-by: David Howells <dhowells@redhat.com>
---
diff --git a/fs/proc/array.c b/fs/proc/array.c
index 9b58d38..ac3b3a4 100644
--- a/fs/proc/array.c
+++ b/fs/proc/array.c
@@ -176,7 +176,7 @@ static inline void task_state(struct seq_file *m, struct pid_namespace *ns,
 		if (tracer)
 			tpid = task_pid_nr_ns(tracer, ns);
 	}
-	cred = get_cred((struct cred *) __task_cred(p));
+	cred = __task_cred(p);
 	seq_printf(m,
 		"State:\t%s\n"
 		"Tgid:\t%d\n"
@@ -199,15 +199,14 @@ static inline void task_state(struct seq_file *m, struct pid_namespace *ns,
 		"FDSize:\t%d\n"
 		"Groups:\t",
 		fdt ? fdt->max_fds : 0);
-	rcu_read_unlock();
 
 	group_info = cred->group_info;
 	task_unlock(p);
 
 	for (g = 0; g < min(group_info->ngroups, NGROUPS_SMALL); g++)
 		seq_printf(m, "%d ", GROUP_AT(group_info, g));
-	put_cred(cred);
 
+	rcu_read_unlock();
 	seq_printf(m, "\n");
 }
 

^ permalink raw reply related	[flat|nested] 25+ messages in thread
* [PATCH] cred - synchronize rcu before releasing cred
@ 2010-07-27 15:50 Jiri Olsa
  2010-07-27 16:16 ` Linus Torvalds
  0 siblings, 1 reply; 25+ messages in thread
From: Jiri Olsa @ 2010-07-27 15:50 UTC (permalink / raw)
  To: Linus Torvalds
  Cc: Andrew Morton, David Howells, Eric Dumazet, linux-kernel,
	Paul E. McKenney

hi,

got no objections on linux-security-module and acked by David.
Noone pick it, so got advice to send this directly to you.

wbr,
jirka
---

BZ 591015 - kernel BUG at kernel/cred.c:168
https://bugzilla.redhat.com/show_bug.cgi?id=591015

Above bugzilla reported bug during the releasing of
old cred structure.

There is reproducer attached to the bugzilla.

The issue is caused by releasing old cred struct while other
kernel path might be still using it. This leads to cred->usage
inconsistency inside the __put_cred and triggering the bug.

Following kernel paths are affected:

The CPU1 path is setting the new groups creds.
The CPU2 path is cat /proc/PID/status


CPU 1                              CPU 2

sys_setgroups                      proc_pid_status      
  set_current_groups                 task_state
    commit_creds                       rcu_read_lock
      put_cred                         ...
        __put_cred                     get_cred
          BUG_ON(usage != 0)           ...
                                       rcu_read_unlock
                                       


If __put_cred got executed during the CPU2 holding the reference
the BUG_ON inside __put_cred is trigered.

I think there's no need to get the cred refference as long as
the 'cred' handling stays inside the rcu_read_lock block.

And the condition of __task_cred 'make sure task doesn't go away',
is done by proc_single_show as this is the proc file.

wbr,
jirka


Signed-off-by: Jiri Olsa <jolsa@redhat.com>
Acked-by: David Howells <dhowells@redhat.com>
---
diff --git a/fs/proc/array.c b/fs/proc/array.c
index 9b58d38..ac3b3a4 100644
--- a/fs/proc/array.c
+++ b/fs/proc/array.c
@@ -176,7 +176,7 @@ static inline void task_state(struct seq_file *m, struct pid_namespace *ns,
 		if (tracer)
 			tpid = task_pid_nr_ns(tracer, ns);
 	}
-	cred = get_cred((struct cred *) __task_cred(p));
+	cred = __task_cred(p);
 	seq_printf(m,
 		"State:\t%s\n"
 		"Tgid:\t%d\n"
@@ -199,15 +199,14 @@ static inline void task_state(struct seq_file *m, struct pid_namespace *ns,
 		"FDSize:\t%d\n"
 		"Groups:\t",
 		fdt ? fdt->max_fds : 0);
-	rcu_read_unlock();
 
 	group_info = cred->group_info;
 	task_unlock(p);
 
 	for (g = 0; g < min(group_info->ngroups, NGROUPS_SMALL); g++)
 		seq_printf(m, "%d ", GROUP_AT(group_info, g));
-	put_cred(cred);
 
+	rcu_read_unlock();
 	seq_printf(m, "\n");
 }
 

----- End forwarded message -----

^ permalink raw reply related	[flat|nested] 25+ messages in thread

end of thread, other threads:[~2010-07-30 21:33 UTC | newest]

Thread overview: 25+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2010-06-16 12:24 [PATCH] cred - synchronize rcu before releasing cred Jiri Olsa
2010-06-16 12:45 ` Eric Dumazet
2010-06-16 12:57   ` Jiri Olsa
2010-06-16 13:10     ` Eric Dumazet
2010-06-16 16:08       ` Jiri Olsa
2010-06-17 23:50         ` David Howells
2010-06-19 12:01           ` Jiri Olsa
2010-06-25 12:55             ` Jiri Olsa
2010-06-25 13:28               ` David Howells
  -- strict thread matches above, loose matches on Subject: below --
2010-06-25 13:33 Jiri Olsa
2010-07-02 12:14 ` Jiri Olsa
2010-07-27 15:50 Jiri Olsa
2010-07-27 16:16 ` Linus Torvalds
2010-07-27 16:46   ` David Howells
2010-07-27 17:56     ` Linus Torvalds
2010-07-28  8:25       ` Jiri Olsa
2010-07-28 12:07       ` David Howells
2010-07-28 12:47         ` David Howells
2010-07-29  6:00           ` Paul E. McKenney
2010-07-29  8:34             ` David Howells
2010-07-30 21:32               ` Paul E. McKenney
2010-07-28 13:17         ` David Howells
2010-07-28 14:46           ` Jiri Olsa
2010-07-29  9:38             ` Jiri Olsa
2010-07-28 15:51           ` Linus Torvalds

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox