No description
  • C 96.9%
  • Assembly 0.9%
  • Rust 0.6%
  • Shell 0.6%
  • Python 0.5%
  • Other 0.3%
Find a file
David Howells 2b984480a8 rxrpc: Fix call RCU cleanup using non-bh-safe locks
commit 963485d436 upstream.

rxrpc_rcu_destroy_call(), which is called as an RCU callback to clean up a
put call, calls rxrpc_put_connection() which, deep in its bowels, takes a
number of spinlocks in a non-BH-safe way, including rxrpc_conn_id_lock and
local->client_conns_lock.  RCU callbacks, however, are normally called from
softirq context, which can cause lockdep to notice the locking
inconsistency.

To get lockdep to detect this, it's necessary to have the connection
cleaned up on the put at the end of the last of its calls, though normally
the clean up is deferred.  This can be induced, however, by starting a call
on an AF_RXRPC socket and then closing the socket without reading the
reply.

Fix this by having rxrpc_rcu_destroy_call() punt the destruction to a
workqueue if in softirq-mode and defer the destruction to process context.

Note that another way to fix this could be to add a bunch of bh-disable
annotations to the spinlocks concerned - and there might be more than just
those two - but that means spending more time with BHs disabled.

Note also that some of these places were covered by bh-disable spinlocks
belonging to the rxrpc_transport object, but these got removed without the
_bh annotation being retained on the next lock in.

Fixes: 999b69f892 ("rxrpc: Kill the client connection bundle concept")
Reported-by: syzbot+d82f3ac8d87e7ccbb2c9@syzkaller.appspotmail.com
Reported-by: syzbot+3f1fd6b8cbf8702d134e@syzkaller.appspotmail.com
Signed-off-by: David Howells <dhowells@redhat.com>
cc: Hillf Danton <hdanton@sina.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
History 2020-02-28 17:23:44 +01:00
arch arm64: lse: Fix LSE atomics with LLVM 2020-02-28 17:23:43 +01:00
block block, bfq: do not plug I/O for bfq_queues with no proc refs 2020-02-24 08:38:09 +01:00
certs certs: Add wrapper function to check blacklisted binary hash 2019-11-12 12:25:50 +11:00
crypto crypto: rename sm3-256 to sm3 in hash_algo_name 2020-02-28 17:23:43 +01:00
Documentation mm: Avoid creating virtual address aliases in brk()/mmap()/mremap() 2020-02-28 17:23:37 +01:00
drivers staging: greybus: use after free in gb_audio_manager_remove_all() 2020-02-28 17:23:42 +01:00
fs io_uring: fix __io_iopoll_check deadlock in io_sq_thread 2020-02-28 17:23:43 +01:00
include ALSA: rawmidi: Avoid bit fields for state flags 2020-02-28 17:23:44 +01:00
init Revert "um: Enable CONFIG_CONSTRUCTORS" 2020-02-01 09:33:00 +00:00
ipc Revert "ipc,sem: remove uneeded sem_undo_list lock usage in exit_sem()" 2020-02-28 17:23:36 +01:00
kernel dma-direct: relax addressability checks in dma_direct_supported 2020-02-28 17:23:44 +01:00
lib crypto: chacha20poly1305 - prevent integer overflow on large input 2020-02-28 17:23:40 +01:00
LICENSES LICENSES: Rename other to deprecated 2019-05-03 06:34:32 -06:00
mm mm: Avoid creating virtual address aliases in brk()/mmap()/mremap() 2020-02-28 17:23:37 +01:00
net rxrpc: Fix call RCU cleanup using non-bh-safe locks 2020-02-28 17:23:44 +01:00
samples samples/bpf: Set -fno-stack-protector when building BPF programs 2020-02-24 08:38:15 +01:00
scripts scripts/get_maintainer.pl: deprioritize old Fixes: addresses 2020-02-28 17:23:43 +01:00
security selinux: ensure we cleanup the internal AVC counters on error in avc_update() 2020-02-24 08:38:19 +01:00
sound ALSA: seq: Fix concurrent access to queue current tick/time 2020-02-28 17:23:44 +01:00
tools tc-testing: add missing 'nsPlugin' to basic.json 2020-02-24 08:38:49 +01:00
usr gen_initramfs_list.sh: fix 'bad variable name' error 2020-01-04 00:00:48 +09:00
virt KVM: arm64: Treat emulated TVAL TimerValue as a signed 32-bit integer 2020-02-14 16:53:04 -05:00
.clang-format clang-format: Update with the latest for_each macro list 2019-08-31 10:00:51 +02:00
.cocciconfig scripts: add Linux .cocciconfig for coccinelle 2016-07-22 12:13:39 +02:00
.get_maintainer.ignore Opt out of scripts/get_maintainer.pl 2019-05-16 10:53:40 -07:00
.gitattributes .gitattributes: use 'dts' diff driver for dts files 2019-12-04 19:44:11 -08:00
.gitignore modpost: dump missing namespaces into a single modules.nsdeps file 2019-11-11 20:10:01 +09:00
.mailmap MAINTAINERS: update my email address 2020-01-11 14:33:39 -08:00
COPYING COPYING: use the new text with points to the license files 2018-03-23 12:41:45 -06:00
CREDITS Linux 5.4-rc4 2019-10-29 04:43:29 -06:00
Kbuild kbuild: do not descend to ./Kbuild when cleaning 2019-08-21 21:03:58 +09:00
Kconfig docs: kbuild: convert docs to ReST and rename to *.rst 2019-06-14 14:21:21 -06:00
MAINTAINERS MAINTAINERS: Update drm/i915 bug filing URL 2020-02-28 17:23:36 +01:00
Makefile Linux 5.5.6 2020-02-24 08:38:51 +01:00
README Drop all 00-INDEX files from Documentation/ 2018-09-09 15:08:58 -06:00

Linux kernel
============

There are several guides for kernel developers and users. These guides can
be rendered in a number of formats, like HTML and PDF. Please read
Documentation/admin-guide/README.rst first.

In order to build the documentation, use ``make htmldocs`` or
``make pdfdocs``.  The formatted documentation can also be read online at:

    https://www.kernel.org/doc/html/latest/

There are various text files in the Documentation/ subdirectory,
several of them using the Restructured Text markup notation.

Please read the Documentation/process/changes.rst file, as it contains the
requirements for building and running the kernel, and information about
the problems which may result by upgrading your kernel.