Linux kernel -stable discussions
 help / color / mirror / Atom feed
From: Kamal Mostafa <kamal@canonical.com>
To: linux-kernel@vger.kernel.org, stable@vger.kernel.org,
	kernel-team@lists.ubuntu.com
Cc: Yishai Hadas <yishaih@mellanox.com>,
	Shachar Raindel <raindel@mellanox.com>,
	Doug Ledford <dledford@redhat.com>,
	Kamal Mostafa <kamal@canonical.com>
Subject: [PATCH 3.13.y-ckt 81/85] IB/uverbs: Fix race between ib_uverbs_open and remove_one
Date: Tue, 20 Oct 2015 14:35:37 -0700	[thread overview]
Message-ID: <1445376941-7046-82-git-send-email-kamal@canonical.com> (raw)
In-Reply-To: <1445376941-7046-1-git-send-email-kamal@canonical.com>

3.13.11-ckt28 -stable review patch.  If anyone has any objections, please let me know.

------------------

From: Yishai Hadas <yishaih@mellanox.com>

commit 35d4a0b63dc0c6d1177d4f532a9deae958f0662c upstream.

Fixes: 2a72f212263701b927559f6850446421d5906c41 ("IB/uverbs: Remove dev_table")

Before this commit there was a device look-up table that was protected
by a spin_lock used by ib_uverbs_open and by ib_uverbs_remove_one. When
it was dropped and container_of was used instead, it enabled the race
with remove_one as dev might be freed just after:
dev = container_of(inode->i_cdev, struct ib_uverbs_device, cdev) but
before the kref_get.

In addition, this buggy patch added some dead code as
container_of(x,y,z) can never be NULL and so dev can never be NULL.
As a result the comment above ib_uverbs_open saying "the open method
will either immediately run -ENXIO" is wrong as it can never happen.

The solution follows Jason Gunthorpe suggestion from below URL:
https://www.mail-archive.com/linux-rdma@vger.kernel.org/msg25692.html

cdev will hold a kref on the parent (the containing structure,
ib_uverbs_device) and only when that kref is released it is
guaranteed that open will never be called again.

In addition, fixes the active count scheme to use an atomic
not a kref to prevent WARN_ON as pointed by above comment
from Jason.

Signed-off-by: Yishai Hadas <yishaih@mellanox.com>
Signed-off-by: Shachar Raindel <raindel@mellanox.com>
Reviewed-by: Jason Gunthorpe <jgunthorpe@obsidianresearch.com>
Signed-off-by: Doug Ledford <dledford@redhat.com>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 drivers/infiniband/core/uverbs.h      |  3 ++-
 drivers/infiniband/core/uverbs_main.c | 43 ++++++++++++++++++++++++-----------
 2 files changed, 32 insertions(+), 14 deletions(-)

diff --git a/drivers/infiniband/core/uverbs.h b/drivers/infiniband/core/uverbs.h
index a283274..639557b 100644
--- a/drivers/infiniband/core/uverbs.h
+++ b/drivers/infiniband/core/uverbs.h
@@ -85,7 +85,7 @@
  */
 
 struct ib_uverbs_device {
-	struct kref				ref;
+	atomic_t				refcount;
 	int					num_comp_vectors;
 	struct completion			comp;
 	struct device			       *dev;
@@ -94,6 +94,7 @@ struct ib_uverbs_device {
 	struct cdev			        cdev;
 	struct rb_root				xrcd_tree;
 	struct mutex				xrcd_tree_mutex;
+	struct kobject				kobj;
 };
 
 struct ib_uverbs_event_file {
diff --git a/drivers/infiniband/core/uverbs_main.c b/drivers/infiniband/core/uverbs_main.c
index 08219fb..2e10ff9 100644
--- a/drivers/infiniband/core/uverbs_main.c
+++ b/drivers/infiniband/core/uverbs_main.c
@@ -127,14 +127,18 @@ static int (*uverbs_ex_cmd_table[])(struct ib_uverbs_file *file,
 static void ib_uverbs_add_one(struct ib_device *device);
 static void ib_uverbs_remove_one(struct ib_device *device);
 
-static void ib_uverbs_release_dev(struct kref *ref)
+static void ib_uverbs_release_dev(struct kobject *kobj)
 {
 	struct ib_uverbs_device *dev =
-		container_of(ref, struct ib_uverbs_device, ref);
+		container_of(kobj, struct ib_uverbs_device, kobj);
 
-	complete(&dev->comp);
+	kfree(dev);
 }
 
+static struct kobj_type ib_uverbs_dev_ktype = {
+	.release = ib_uverbs_release_dev,
+};
+
 static void ib_uverbs_release_event_file(struct kref *ref)
 {
 	struct ib_uverbs_event_file *file =
@@ -298,13 +302,19 @@ static int ib_uverbs_cleanup_ucontext(struct ib_uverbs_file *file,
 	return context->device->dealloc_ucontext(context);
 }
 
+static void ib_uverbs_comp_dev(struct ib_uverbs_device *dev)
+{
+	complete(&dev->comp);
+}
+
 static void ib_uverbs_release_file(struct kref *ref)
 {
 	struct ib_uverbs_file *file =
 		container_of(ref, struct ib_uverbs_file, ref);
 
 	module_put(file->device->ib_dev->owner);
-	kref_put(&file->device->ref, ib_uverbs_release_dev);
+	if (atomic_dec_and_test(&file->device->refcount))
+		ib_uverbs_comp_dev(file->device);
 
 	kfree(file);
 }
@@ -733,9 +743,7 @@ static int ib_uverbs_open(struct inode *inode, struct file *filp)
 	int ret;
 
 	dev = container_of(inode->i_cdev, struct ib_uverbs_device, cdev);
-	if (dev)
-		kref_get(&dev->ref);
-	else
+	if (!atomic_inc_not_zero(&dev->refcount))
 		return -ENXIO;
 
 	if (!try_module_get(dev->ib_dev->owner)) {
@@ -756,6 +764,7 @@ static int ib_uverbs_open(struct inode *inode, struct file *filp)
 	mutex_init(&file->mutex);
 
 	filp->private_data = file;
+	kobject_get(&dev->kobj);
 
 	return nonseekable_open(inode, filp);
 
@@ -763,13 +772,16 @@ err_module:
 	module_put(dev->ib_dev->owner);
 
 err:
-	kref_put(&dev->ref, ib_uverbs_release_dev);
+	if (atomic_dec_and_test(&dev->refcount))
+		ib_uverbs_comp_dev(dev);
+
 	return ret;
 }
 
 static int ib_uverbs_close(struct inode *inode, struct file *filp)
 {
 	struct ib_uverbs_file *file = filp->private_data;
+	struct ib_uverbs_device *dev = file->device;
 
 	ib_uverbs_cleanup_ucontext(file, file->ucontext);
 
@@ -777,6 +789,7 @@ static int ib_uverbs_close(struct inode *inode, struct file *filp)
 		kref_put(&file->async_file->ref, ib_uverbs_release_event_file);
 
 	kref_put(&file->ref, ib_uverbs_release_file);
+	kobject_put(&dev->kobj);
 
 	return 0;
 }
@@ -872,10 +885,11 @@ static void ib_uverbs_add_one(struct ib_device *device)
 	if (!uverbs_dev)
 		return;
 
-	kref_init(&uverbs_dev->ref);
+	atomic_set(&uverbs_dev->refcount, 1);
 	init_completion(&uverbs_dev->comp);
 	uverbs_dev->xrcd_tree = RB_ROOT;
 	mutex_init(&uverbs_dev->xrcd_tree_mutex);
+	kobject_init(&uverbs_dev->kobj, &ib_uverbs_dev_ktype);
 
 	spin_lock(&map_lock);
 	devnum = find_first_zero_bit(dev_map, IB_UVERBS_MAX_DEVICES);
@@ -902,6 +916,7 @@ static void ib_uverbs_add_one(struct ib_device *device)
 	cdev_init(&uverbs_dev->cdev, NULL);
 	uverbs_dev->cdev.owner = THIS_MODULE;
 	uverbs_dev->cdev.ops = device->mmap ? &uverbs_mmap_fops : &uverbs_fops;
+	uverbs_dev->cdev.kobj.parent = &uverbs_dev->kobj;
 	kobject_set_name(&uverbs_dev->cdev.kobj, "uverbs%d", uverbs_dev->devnum);
 	if (cdev_add(&uverbs_dev->cdev, base, 1))
 		goto err_cdev;
@@ -932,9 +947,10 @@ err_cdev:
 		clear_bit(devnum, overflow_map);
 
 err:
-	kref_put(&uverbs_dev->ref, ib_uverbs_release_dev);
+	if (atomic_dec_and_test(&uverbs_dev->refcount))
+		ib_uverbs_comp_dev(uverbs_dev);
 	wait_for_completion(&uverbs_dev->comp);
-	kfree(uverbs_dev);
+	kobject_put(&uverbs_dev->kobj);
 	return;
 }
 
@@ -954,9 +970,10 @@ static void ib_uverbs_remove_one(struct ib_device *device)
 	else
 		clear_bit(uverbs_dev->devnum - IB_UVERBS_MAX_DEVICES, overflow_map);
 
-	kref_put(&uverbs_dev->ref, ib_uverbs_release_dev);
+	if (atomic_dec_and_test(&uverbs_dev->refcount))
+		ib_uverbs_comp_dev(uverbs_dev);
 	wait_for_completion(&uverbs_dev->comp);
-	kfree(uverbs_dev);
+	kobject_put(&uverbs_dev->kobj);
 }
 
 static char *uverbs_devnode(struct device *dev, umode_t *mode)
-- 
1.9.1


  parent reply	other threads:[~2015-10-20 21:36 UTC|newest]

Thread overview: 88+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2015-10-20 21:34 [3.13.y-ckt stable] Linux 3.13.11-ckt28 stable review Kamal Mostafa
2015-10-20 21:34 ` [PATCH 3.13.y-ckt 01/85] USB: whiteheat: fix potential null-deref at probe Kamal Mostafa
2015-10-20 21:34 ` [PATCH 3.13.y-ckt 02/85] dcache: Handle escaped paths in prepend_path Kamal Mostafa
2015-10-20 21:34 ` [PATCH 3.13.y-ckt 03/85] vfs: Test for and handle paths that are unreachable from their mnt_root Kamal Mostafa
2015-10-20 21:34 ` [PATCH 3.13.y-ckt 04/85] sctp: fix race on protocol/netns initialization Kamal Mostafa
2015-10-20 21:34 ` [PATCH 3.13.y-ckt 05/85] [media] v4l: omap3isp: Fix sub-device power management code Kamal Mostafa
2015-10-20 21:34 ` [PATCH 3.13.y-ckt 06/85] [media] rc-core: fix remove uevent generation Kamal Mostafa
2015-10-20 21:34 ` [PATCH 3.13.y-ckt 07/85] xtensa: fix threadptr reload on return to userspace Kamal Mostafa
2015-10-20 21:34 ` [PATCH 3.13.y-ckt 08/85] ARM: OMAP2+: DRA7: clockdomain: change l4per2_7xx_clkdm to SW_WKUP Kamal Mostafa
2015-10-20 21:34 ` [PATCH 3.13.y-ckt 09/85] mac80211: enable assoc check for mesh interfaces Kamal Mostafa
2015-10-20 21:34 ` [PATCH 3.13.y-ckt 10/85] PCI: Add dev_flags bit to access VPD through function 0 Kamal Mostafa
2015-10-20 21:34 ` [PATCH 3.13.y-ckt 11/85] PCI: Add VPD function 0 quirk for Intel Ethernet devices Kamal Mostafa
2015-10-20 21:34 ` [PATCH 3.13.y-ckt 12/85] usb: dwc3: ep0: Fix mem corruption on OUT transfers of more than 512 bytes Kamal Mostafa
2015-10-20 21:34 ` [PATCH 3.13.y-ckt 13/85] serial: 8250_pci: Add support for Pericom PI7C9X795[1248] Kamal Mostafa
2015-10-20 21:34 ` [PATCH 3.13.y-ckt 14/85] KVM: MMU: fix validation of mmio page fault Kamal Mostafa
2015-10-20 21:34 ` [PATCH 3.13.y-ckt 15/85] auxdisplay: ks0108: fix refcount Kamal Mostafa
2015-10-20 21:34 ` [PATCH 3.13.y-ckt 16/85] devres: fix devres_get() Kamal Mostafa
2015-10-20 21:34 ` [PATCH 3.13.y-ckt 17/85] iio: adis16400: Fix adis16448 gyroscope scale Kamal Mostafa
2015-10-20 21:34 ` [PATCH 3.13.y-ckt 18/85] iio: Add inverse unit conversion macros Kamal Mostafa
2015-10-20 21:34 ` [PATCH 3.13.y-ckt 19/85] iio: adis16480: Fix scale factors Kamal Mostafa
2015-10-20 21:34 ` [PATCH 3.13.y-ckt 20/85] iio: industrialio-buffer: Fix iio_buffer_poll return value Kamal Mostafa
2015-10-20 21:34 ` [PATCH 3.13.y-ckt 21/85] iio: event: Remove negative error code from iio_event_poll Kamal Mostafa
2015-10-20 21:34 ` [PATCH 3.13.y-ckt 22/85] NFSv4: don't set SETATTR for O_RDONLY|O_EXCL Kamal Mostafa
2015-10-20 21:34 ` [PATCH 3.13.y-ckt 23/85] unshare: Unsharing a thread does not require unsharing a vm Kamal Mostafa
2015-10-20 21:34 ` [PATCH 3.13.y-ckt 24/85] ASoC: adav80x: Remove .read_flag_mask setting from adav80x_regmap_config Kamal Mostafa
2015-10-20 21:34 ` [PATCH 3.13.y-ckt 25/85] drivers: usb :fsl: Implement Workaround for USB Erratum A007792 Kamal Mostafa
2015-10-20 21:34 ` [PATCH 3.13.y-ckt 26/85] drivers: usb: fsl: Workaround for USB erratum-A005275 Kamal Mostafa
2015-10-20 21:34 ` [PATCH 3.13.y-ckt 27/85] serial: 8250: don't bind to SMSC IrCC IR port Kamal Mostafa
2015-10-20 21:34 ` [PATCH 3.13.y-ckt 28/85] staging: comedi: adl_pci7x3x: fix digital output on PCI-7230 Kamal Mostafa
2015-10-20 21:34 ` [PATCH 3.13.y-ckt 29/85] blk-mq: fix buffer overflow when reading sysfs file of 'pending' Kamal Mostafa
2015-10-20 21:34 ` [PATCH 3.13.y-ckt 30/85] xtensa: fix kernel register spilling Kamal Mostafa
2015-10-20 21:34 ` [PATCH 3.13.y-ckt 31/85] NFS: nfs_set_pgio_error sometimes misses errors Kamal Mostafa
2015-10-20 21:34 ` [PATCH 3.13.y-ckt 32/85] NFS: Fix a NULL pointer dereference of migration recovery ops for v4.2 client Kamal Mostafa
2015-10-20 21:34 ` [PATCH 3.13.y-ckt 33/85] usb: host: ehci-sys: delete useless bus_to_hcd conversion Kamal Mostafa
2015-10-20 21:34 ` [PATCH 3.13.y-ckt 34/85] USB: symbolserial: Use usb_get_serial_port_data Kamal Mostafa
2015-10-20 21:34 ` [PATCH 3.13.y-ckt 35/85] USB: ftdi_sio: Added custom PID for CustomWare products Kamal Mostafa
2015-10-20 21:34 ` [PATCH 3.13.y-ckt 36/85] HID: usbhid: Fix the check for HID_RESET_PENDING in hid_io_error Kamal Mostafa
2015-10-20 21:34 ` [PATCH 3.13.y-ckt 37/85] eCryptfs: Invalidate dcache entries when lower i_nlink is zero Kamal Mostafa
2015-10-20 21:34 ` [PATCH 3.13.y-ckt 38/85] libxfs: readahead of dir3 data blocks should use the read verifier Kamal Mostafa
2015-10-20 21:34 ` [PATCH 3.13.y-ckt 39/85] xfs: Fix xfs_attr_leafblock definition Kamal Mostafa
2015-10-20 21:34 ` [PATCH 3.13.y-ckt 40/85] arm64: kconfig: Move LIST_POISON to a safe value Kamal Mostafa
2015-10-20 21:34 ` [PATCH 3.13.y-ckt 41/85] Btrfs: check if previous transaction aborted to avoid fs corruption Kamal Mostafa
2015-10-20 21:34 ` [PATCH 3.13.y-ckt 42/85] DRM - radeon: Don't link train DisplayPort on HPD until we get the dpcd Kamal Mostafa
2015-10-20 21:34 ` [PATCH 3.13.y-ckt 43/85] rtlwifi: rtl8192cu: Add new device ID Kamal Mostafa
2015-10-20 21:35 ` [PATCH 3.13.y-ckt 44/85] " Kamal Mostafa
2015-10-20 21:35 ` [PATCH 3.13.y-ckt 45/85] of/address: Don't loop forever in of_find_matching_node_by_address() Kamal Mostafa
2015-10-20 21:35 ` [PATCH 3.13.y-ckt 46/85] drivercore: Fix unregistration path of platform devices Kamal Mostafa
2015-10-20 21:35 ` [PATCH 3.13.y-ckt 47/85] Input: synaptics - fix handling of disabling gesture mode Kamal Mostafa
2015-10-20 22:44   ` Dmitry Torokhov
2015-10-21 20:26     ` Kamal Mostafa
2015-10-20 21:35 ` [PATCH 3.13.y-ckt 48/85] xfs: return errors from partial I/O failures to files Kamal Mostafa
2015-10-20 21:35 ` [PATCH 3.13.y-ckt 49/85] IB/qib: Change lkey table allocation to support more MRs Kamal Mostafa
2015-10-20 21:35 ` [PATCH 3.13.y-ckt 50/85] tg3: Fix temperature reporting Kamal Mostafa
2015-10-20 21:35 ` [PATCH 3.13.y-ckt 51/85] drm/i915: Always mark the object as dirty when used by the GPU Kamal Mostafa
2015-10-20 21:35 ` [PATCH 3.13.y-ckt 52/85] Add radeon suspend/resume quirk for HP Compaq dc5750 Kamal Mostafa
2015-10-20 21:35 ` [PATCH 3.13.y-ckt 53/85] IB/uverbs: reject invalid or unknown opcodes Kamal Mostafa
2015-10-20 21:35 ` [PATCH 3.13.y-ckt 54/85] hpfs: update ctime and mtime on directory modification Kamal Mostafa
2015-10-20 21:35 ` [PATCH 3.13.y-ckt 55/85] Input: evdev - do not report errors form flush() Kamal Mostafa
2015-10-20 21:35 ` [PATCH 3.13.y-ckt 56/85] crypto: ghash-clmulni: specify context size for ghash async algorithm Kamal Mostafa
2015-10-20 21:35 ` [PATCH 3.13.y-ckt 57/85] fs: create and use seq_show_option for escaping Kamal Mostafa
2015-10-20 21:35 ` [PATCH 3.13.y-ckt 58/85] ALSA: hda - Enable headphone jack detect on old Fujitsu laptops Kamal Mostafa
2015-10-20 21:35 ` [PATCH 3.13.y-ckt 59/85] ALSA: hda - Use ALC880_FIXUP_FUJITSU for FSC Amilo M1437 Kamal Mostafa
2015-10-20 21:35 ` [PATCH 3.13.y-ckt 60/85] scsi: fix scsi_error_handler vs. scsi_host_dev_release race Kamal Mostafa
2015-10-20 21:35 ` [PATCH 3.13.y-ckt 61/85] parisc: Use double word condition in 64bit CAS operation Kamal Mostafa
2015-10-20 21:35 ` [PATCH 3.13.y-ckt 62/85] vmscan: fix increasing nr_isolated incurred by putback unevictable pages Kamal Mostafa
2015-10-20 21:35 ` [PATCH 3.13.y-ckt 63/85] hfs,hfsplus: cache pages correctly between bnode_create and bnode_free Kamal Mostafa
2015-10-20 21:35 ` [PATCH 3.13.y-ckt 64/85] hfs: fix B-tree corruption after insertion at position 0 Kamal Mostafa
2015-10-20 21:35 ` [PATCH 3.13.y-ckt 65/85] drm/qxl: validate monitors config modes Kamal Mostafa
2015-10-20 21:35 ` [PATCH 3.13.y-ckt 66/85] PCI: Fix TI816X class code quirk Kamal Mostafa
2015-10-20 21:35 ` [PATCH 3.13.y-ckt 67/85] x86/mm: Initialize pmd_idx in page_table_range_init_count() Kamal Mostafa
2015-10-20 21:35 ` [PATCH 3.13.y-ckt 68/85] powerpc/rtas: Introduce rtas_get_sensor_fast() for IRQ handlers Kamal Mostafa
2015-10-20 21:35 ` [PATCH 3.13.y-ckt 69/85] jbd2: avoid infinite loop when destroying aborted journal Kamal Mostafa
2015-10-20 21:35 ` [PATCH 3.13.y-ckt 70/85] clk: versatile: off by one in clk_sp810_timerclken_of_get() Kamal Mostafa
2015-10-20 21:35 ` [PATCH 3.13.y-ckt 71/85] usb: gadget: m66592-udc: forever loop in set_feature() Kamal Mostafa
2015-10-20 21:35 ` [PATCH 3.13.y-ckt 72/85] windfarm: decrement client count when unregistering Kamal Mostafa
2015-10-20 21:35 ` [PATCH 3.13.y-ckt 73/85] perf hists: Update the column width for the "srcline" sort key Kamal Mostafa
2015-10-20 21:35 ` [PATCH 3.13.y-ckt 74/85] batman-adv: Make DAT capability changes atomic Kamal Mostafa
2015-10-20 21:35 ` [PATCH 3.13.y-ckt 75/85] batman-adv: Make NC " Kamal Mostafa
2015-10-20 21:35 ` [PATCH 3.13.y-ckt 76/85] powerpc/mm: Fix pte_pagesize_index() crash on 4K w/64K hash Kamal Mostafa
2015-10-20 21:35 ` [PATCH 3.13.y-ckt 77/85] perf stat: Get correct cpu id for print_aggr Kamal Mostafa
2015-10-20 21:35 ` [PATCH 3.13.y-ckt 78/85] IB/mlx4: Fix potential deadlock when sending mad to wire Kamal Mostafa
2015-10-20 21:35 ` [PATCH 3.13.y-ckt 79/85] IB/mlx4: Forbid using sysfs to change RoCE pkeys Kamal Mostafa
2015-10-20 21:35 ` [PATCH 3.13.y-ckt 80/85] IB/mlx4: Use correct SL on AH query under RoCE Kamal Mostafa
2015-10-20 21:35 ` Kamal Mostafa [this message]
2015-10-20 21:35 ` [PATCH 3.13.y-ckt 82/85] mmc: core: fix race condition in mmc_wait_data_done Kamal Mostafa
2015-10-20 21:35 ` [PATCH 3.13.y-ckt 83/85] ipv6: fix exthdrs offload registration in out_rt path Kamal Mostafa
2015-10-20 21:35 ` [PATCH 3.13.y-ckt 84/85] task_work: remove fifo ordering guarantee Kamal Mostafa
2015-10-20 21:35 ` [PATCH 3.13.y-ckt 85/85] scsi_dh: fix randconfig build error Kamal Mostafa

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=1445376941-7046-82-git-send-email-kamal@canonical.com \
    --to=kamal@canonical.com \
    --cc=dledford@redhat.com \
    --cc=kernel-team@lists.ubuntu.com \
    --cc=linux-kernel@vger.kernel.org \
    --cc=raindel@mellanox.com \
    --cc=stable@vger.kernel.org \
    --cc=yishaih@mellanox.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox