From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from mail.linuxfoundation.org ([140.211.169.12]:47830 "EHLO mail.linuxfoundation.org" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S932646AbcAZAry (ORCPT ); Mon, 25 Jan 2016 19:47:54 -0500 Subject: Patch "ALSA: timer: Fix race among timer ioctls" has been added to the 4.3-stable tree To: tiwai@suse.de, dvyukov@google.com, gregkh@linuxfoundation.org Cc: , From: Date: Mon, 25 Jan 2016 16:47:53 -0800 Message-ID: <145376927352179@kroah.com> MIME-Version: 1.0 Content-Type: text/plain; charset=ANSI_X3.4-1968 Content-Transfer-Encoding: 8bit Sender: stable-owner@vger.kernel.org List-ID: This is a note to let you know that I've just added the patch titled ALSA: timer: Fix race among timer ioctls to the 4.3-stable tree which can be found at: http://www.kernel.org/git/?p=linux/kernel/git/stable/stable-queue.git;a=summary The filename of the patch is: alsa-timer-fix-race-among-timer-ioctls.patch and it can be found in the queue-4.3 subdirectory. If you, or anyone else, feels it should not be added to the stable tree, please let know about it. >>From af368027a49a751d6ff4ee9e3f9961f35bb4fede Mon Sep 17 00:00:00 2001 From: Takashi Iwai Date: Wed, 13 Jan 2016 17:48:01 +0100 Subject: ALSA: timer: Fix race among timer ioctls From: Takashi Iwai commit af368027a49a751d6ff4ee9e3f9961f35bb4fede upstream. ALSA timer ioctls have an open race and this may lead to a use-after-free of timer instance object. A simplistic fix is to make each ioctl exclusive. We have already tread_sem for controlling the tread, and extend this as a global mutex to be applied to each ioctl. The downside is, of course, the worse concurrency. But these ioctls aren't to be parallel accessible, in anyway, so it should be fine to serialize there. Reported-by: Dmitry Vyukov Tested-by: Dmitry Vyukov Signed-off-by: Takashi Iwai Signed-off-by: Greg Kroah-Hartman --- sound/core/timer.c | 32 +++++++++++++++++++------------- 1 file changed, 19 insertions(+), 13 deletions(-) --- a/sound/core/timer.c +++ b/sound/core/timer.c @@ -73,7 +73,7 @@ struct snd_timer_user { struct timespec tstamp; /* trigger tstamp */ wait_queue_head_t qchange_sleep; struct fasync_struct *fasync; - struct mutex tread_sem; + struct mutex ioctl_lock; }; /* list of timers */ @@ -1263,7 +1263,7 @@ static int snd_timer_user_open(struct in return -ENOMEM; spin_lock_init(&tu->qlock); init_waitqueue_head(&tu->qchange_sleep); - mutex_init(&tu->tread_sem); + mutex_init(&tu->ioctl_lock); tu->ticks = 1; tu->queue_size = 128; tu->queue = kmalloc(tu->queue_size * sizeof(struct snd_timer_read), @@ -1283,8 +1283,10 @@ static int snd_timer_user_release(struct if (file->private_data) { tu = file->private_data; file->private_data = NULL; + mutex_lock(&tu->ioctl_lock); if (tu->timeri) snd_timer_close(tu->timeri); + mutex_unlock(&tu->ioctl_lock); kfree(tu->queue); kfree(tu->tqueue); kfree(tu); @@ -1522,7 +1524,6 @@ static int snd_timer_user_tselect(struct int err = 0; tu = file->private_data; - mutex_lock(&tu->tread_sem); if (tu->timeri) { snd_timer_close(tu->timeri); tu->timeri = NULL; @@ -1566,7 +1567,6 @@ static int snd_timer_user_tselect(struct } __err: - mutex_unlock(&tu->tread_sem); return err; } @@ -1779,7 +1779,7 @@ enum { SNDRV_TIMER_IOCTL_PAUSE_OLD = _IO('T', 0x23), }; -static long snd_timer_user_ioctl(struct file *file, unsigned int cmd, +static long __snd_timer_user_ioctl(struct file *file, unsigned int cmd, unsigned long arg) { struct snd_timer_user *tu; @@ -1796,17 +1796,11 @@ static long snd_timer_user_ioctl(struct { int xarg; - mutex_lock(&tu->tread_sem); - if (tu->timeri) { /* too late */ - mutex_unlock(&tu->tread_sem); + if (tu->timeri) /* too late */ return -EBUSY; - } - if (get_user(xarg, p)) { - mutex_unlock(&tu->tread_sem); + if (get_user(xarg, p)) return -EFAULT; - } tu->tread = xarg ? 1 : 0; - mutex_unlock(&tu->tread_sem); return 0; } case SNDRV_TIMER_IOCTL_GINFO: @@ -1839,6 +1833,18 @@ static long snd_timer_user_ioctl(struct return -ENOTTY; } +static long snd_timer_user_ioctl(struct file *file, unsigned int cmd, + unsigned long arg) +{ + struct snd_timer_user *tu = file->private_data; + long ret; + + mutex_lock(&tu->ioctl_lock); + ret = __snd_timer_user_ioctl(file, cmd, arg); + mutex_unlock(&tu->ioctl_lock); + return ret; +} + static int snd_timer_user_fasync(int fd, struct file * file, int on) { struct snd_timer_user *tu; Patches currently in stable-queue which might be from tiwai@suse.de are queue-4.3/alsa-hrtimer-fix-stall-by-hrtimer_cancel.patch queue-4.3/alsa-hda-fix-white-noise-on-dell-latitude-e5550.patch queue-4.3/alsa-hda-fix-the-headset-mic-detection-problem-for-a-dell-laptop.patch queue-4.3/alsa-timer-harden-slave-timer-list-handling.patch queue-4.3/alsa-hda-fix-headphone-mic-input-on-a-few-dell-alc293-machines.patch queue-4.3/alsa-timer-fix-double-unlink-of-active_list.patch queue-4.3/alsa-hda-add-fixup-for-acer-aspire-one-cloudbook-14.patch queue-4.3/alsa-control-avoid-kernel-warnings-from-tlv-ioctl-with-numid-0.patch queue-4.3/alsa-hda-flush-the-pending-probe-work-at-remove.patch queue-4.3/alsa-hda-fixup-inverted-internal-mic-for-lenovo-e50-80.patch queue-4.3/alsa-usb-audio-add-sample-rate-inquiry-quirk-for-audioquest-dragonfly.patch queue-4.3/alsa-hda-realtek-dell-xps-one-alc3260-speaker-no-sound-after-resume-back.patch queue-4.3/alsa-hda-apply-hp-headphone-fixups-more-generically.patch queue-4.3/alsa-hda-set-codec-to-d3-at-reboot-shutdown-on-thinkpads.patch queue-4.3/alsa-hda-realtek-fix-silent-headphone-output-on-macpro-4-1-v2.patch queue-4.3/alsa-rme96-fix-unexpected-volume-reset-after-rate-changes.patch queue-4.3/alsa-fireworks-bebob-oxfw-dice-enable-to-make-as-built-in.patch queue-4.3/alsa-hda-set-skl-hda-controller-power-at-freeze-and-thaw.patch queue-4.3/alsa-hda-add-inverted-dmic-for-packard-bell-dots.patch queue-4.3/alsa-usb-add-native-dsd-support-for-oppo-ha-1.patch queue-4.3/alsa-hda-add-intel-lewisburg-device-ids-audio.patch queue-4.3/alsa-hda-add-keycode-map-for-alc-input-device.patch queue-4.3/alsa-hda-add-a-fixup-for-thinkpad-x1-carbon-2nd.patch queue-4.3/alsa-seq-fix-race-at-timer-setup-and-close.patch queue-4.3/alsa-hda-skip-eld-notification-during-system-suspend.patch queue-4.3/alsa-pcm-fix-snd_pcm_hw_params-struct-copy-in-compat-mode.patch queue-4.3/alsa-hda-add-mic-mute-hotkey-quirk-for-lenovo-thinkcentre-aio.patch queue-4.3/alsa-seq-fix-snd_seq_call_port_info_ioctl-in-compat-mode.patch queue-4.3/alsa-hda-disable-64bit-address-for-creative-hda-controllers.patch queue-4.3/alsa-hda-fix-noise-on-dell-latitude-e6440.patch queue-4.3/alsa-seq-fix-missing-null-check-at-remove_events-ioctl.patch queue-4.3/alsa-hda-ca0132-quirk-for-alienware-17-2015.patch queue-4.3/alsa-usb-audio-fix-mixer-ctl-regression-of-native-instrument-devices.patch queue-4.3/alsa-usb-audio-add-a-more-accurate-volume-quirk-for-audioquest-dragonfly.patch queue-4.3/alsa-hda-fix-headphone-noise-after-dell-xps-13-resume-back-from-s3.patch queue-4.3/alsa-hda-fix-noise-problems-on-thinkpad-t440s.patch queue-4.3/alsa-hda-fix-lost-4k-bdl-boundary-workaround.patch queue-4.3/alsa-timer-handle-disconnection-more-safely.patch queue-4.3/alsa-hda-fix-bass-pin-fixup-for-asus-n550jx.patch queue-4.3/alsa-timer-fix-race-among-timer-ioctls.patch queue-4.3/alsa-hda-apply-pin-fixup-for-hp-probook-6550b.patch queue-4.3/alsa-hda-fixing-speaker-noise-on-the-two-latest-thinkpad-models.patch queue-4.3/alsa-hda-add-fixup-for-dell-latitidue-e6540.patch queue-4.3/alsa-usb-audio-avoid-calling-usb_autopm_put_interface-at-disconnect.patch queue-4.3/alsa-hda-apply-click-noise-workaround-for-thinkpads-generically.patch queue-4.3/alsa-hda-fix-noise-on-gigabyte-z170x-mobo.patch