From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org X-Spam-Level: X-Spam-Status: No, score=-10.1 required=3.0 tests=BAYES_00,DKIM_SIGNED, DKIM_VALID,DKIM_VALID_AU,FREEMAIL_FORGED_FROMDOMAIN,FREEMAIL_FROM, HEADER_FROM_DIFFERENT_DOMAINS,MAILING_LIST_MULTI,MENTIONS_GIT_HOSTING, SPF_HELO_NONE,SPF_PASS,USER_AGENT_SANE_1 autolearn=ham autolearn_force=no version=3.4.0 Received: from mail.kernel.org (mail.kernel.org [198.145.29.99]) by smtp.lore.kernel.org (Postfix) with ESMTP id 4AE2AC433DF for ; Mon, 24 Aug 2020 14:13:30 +0000 (UTC) Received: from vger.kernel.org (vger.kernel.org [23.128.96.18]) by mail.kernel.org (Postfix) with ESMTP id 218A4206B5 for ; Mon, 24 Aug 2020 14:13:30 +0000 (UTC) Authentication-Results: mail.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="HpGBvByV" Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1726051AbgHXON3 (ORCPT ); Mon, 24 Aug 2020 10:13:29 -0400 Received: from lindbergh.monkeyblade.net ([23.128.96.19]:59512 "EHLO lindbergh.monkeyblade.net" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1725781AbgHXONZ (ORCPT ); Mon, 24 Aug 2020 10:13:25 -0400 Received: from mail-pj1-x1041.google.com (mail-pj1-x1041.google.com [IPv6:2607:f8b0:4864:20::1041]) by lindbergh.monkeyblade.net (Postfix) with ESMTPS id CFBE3C061573 for ; Mon, 24 Aug 2020 07:13:24 -0700 (PDT) Received: by mail-pj1-x1041.google.com with SMTP id mw10so4289467pjb.2 for ; Mon, 24 Aug 2020 07:13:24 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=from:date:to:cc:subject:message-id:references:mime-version :content-disposition:in-reply-to:user-agent; bh=My99gZu9SAiWLI/FM5xZGCr2h7VV0u5aP+ilsJxkPsw=; b=HpGBvByV+x8/zNqxwxPRhqIYxKvrUHK2enGkHJ7sPxNEMPoAlBPoBt8v0++iYxFO6J EPy1/xBRuLt6QI5T9AOKcM9DneOYsQYNgeKQgLfefW+x4wO3LOVtbc18Qtb7b+77fNUt KXHoxeEirHhNwNihCTUDz15pd4z/oYLEDkC4mEuEWJxCDbwg1pZXzRAdOm56BlkRN3++ S35jhyjYBS2lkqmb8DQtgcCR77t14L37/mJwhwQFyD7tGxvEFk5+kAGgxXlOkK95xO2q VzcdlSorKmbJDm7k2290iNCEkKBXpB7mxMMPx3plgr3cfI86wOBWYeMmmhfQ57To7AUT 1tyA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:from:date:to:cc:subject:message-id:references :mime-version:content-disposition:in-reply-to:user-agent; bh=My99gZu9SAiWLI/FM5xZGCr2h7VV0u5aP+ilsJxkPsw=; b=WLxL2++mQPHBTU9vdDCPQ5C3MFkAybmpJSjQt1VLc19nhc3Qen5iHmfwNlZsiNJnhm VedyYGzKlCuPVg4I1uNG2wnwzXgWeGI3mJEE16+7/Da/KggkgOYEc1qzztOxbuNJZyMm ufReWI6swgngAA1PvWbucd7i7pKLPoNIeO6pd1jtdlPseaMMvp2SXg0pduvnPsVP84CP D/4SsCfkx8rsXsYcb7xq6OWO4tQ1Lc6FSsK/QNxtYrp3lBB1/m5RFlrXXHkKhT7ISZ4h j4whniETUt1UHvION89zRMFDIqxc93lYVeuYu1/gX2w7+5ApW8RfQSPe8G7YDqIvvhYV iTaw== X-Gm-Message-State: AOAM531neadPG9rlO7l0s7MyUMLUcZK/mCG1jR+egfEeoazzzE8DJiSt 8ixfiXbGpS7fQkDukXi1yw== X-Google-Smtp-Source: ABdhPJyvkwGd239UD67WcPvS9vUlCtl3t3kvanxIwEy5zRezPm8CDYMJ3WWEQ7bdhzdD80GY/SO0Dg== X-Received: by 2002:a17:90a:8817:: with SMTP id s23mr4901019pjn.158.1598278402245; Mon, 24 Aug 2020 07:13:22 -0700 (PDT) Received: from madhuparna-HP-Notebook ([2402:3a80:cfa:d88f:d15b:321b:cea4:bde0]) by smtp.gmail.com with ESMTPSA id r91sm10094555pja.56.2020.08.24.07.13.19 (version=TLS1_2 cipher=ECDHE-ECDSA-CHACHA20-POLY1305 bits=256/256); Mon, 24 Aug 2020 07:13:21 -0700 (PDT) From: Madhuparna Bhowmik X-Google-Original-From: Madhuparna Bhowmik Date: Mon, 24 Aug 2020 19:43:16 +0530 To: Xie He Cc: Madhuparna Bhowmik , David Miller , Jakub Kicinski , andrianov , netdev Subject: Re: Regarding possible bug in net/wan/x25_asy.c Message-ID: <20200824141315.GA21579@madhuparna-HP-Notebook> References: MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: User-Agent: Mutt/1.9.4 (2018-02-28) Sender: netdev-owner@vger.kernel.org Precedence: bulk List-ID: X-Mailing-List: netdev@vger.kernel.org On Sun, Aug 23, 2020 at 12:12:01PM -0700, Xie He wrote: > On Sun, Aug 23, 2020 at 8:28 AM Madhuparna Bhowmik > wrote: > > > > sl->xhead is modified in both x25_asy_change_mtu() and > > x25_asy_write_wakeup(). However, sl->lock is not held in > > x25_asy_write_wakeup(). So, I am not sure if it is indeed possible to > > have a race between these two functions. If it is possible that these > > two functions can execute in parallel then the lock should be held in > > x25_asy_write_wakeup() as well. Please let me know if this race is > > possible. > > I think you are right. These two functions do race with each other. > There seems to be nothing preventing them from racing. We need to hold > the lock in x25_asy_write_wakeup to prevent it from racing with > x25_asy_change_mtu. > > By the way, I think this driver has bigger problems. We can see that > these function pairs are not symmetric with one another in what they > do: > "x25_asy_alloc" and "x25_asy_free"; > "x25_asy_open" and "x25_asy_close"; > "x25_asy_open_tty" and "x25_asy_close_tty"; > "x25_asy_netdev_ops.ndo_open" and "x25_asy_netdev_ops.ndo_stop". > > This not only makes the code messy, but also makes the actual runtime > behavior buggy. > > I'm planning to fix this with this change: > https://github.com/hyanggi/linux/commit/66387f229168014024117d50ade01092e3c9932c > Please take a look if you are interested. Thanks! > Sure, I had a look at it and since you are already working on fixing this driver, don't think there is a need for a patch to fix the particular race condition bug. This bug was found by the Linux driver verification project and my work was to report it to the maintainers. Thanks and Regards, Madhuparna > Thanks, > Xie He