Eric Dumazet
43b6375db5
inetpeer: fix data-race in inet_putpeer / inet_putpeer
...
commit 71685eb4ce80ae9c49eff82ca4dd15acab215de9 upstream.
We need to explicitely forbid read/store tearing in inet_peer_gc()
and inet_putpeer().
The following syzbot report reminds us about inet_putpeer()
running without a lock held.
BUG: KCSAN: data-race in inet_putpeer / inet_putpeer
write to 0xffff888121fb2ed0 of 4 bytes by interrupt on cpu 0:
inet_putpeer+0x37/0xa0 net/ipv4/inetpeer.c:240
ip4_frag_free+0x3d/0x50 net/ipv4/ip_fragment.c:102
inet_frag_destroy_rcu+0x58/0x80 net/ipv4/inet_fragment.c:228
__rcu_reclaim kernel/rcu/rcu.h:222 [inline]
rcu_do_batch+0x256/0x5b0 kernel/rcu/tree.c:2157
rcu_core+0x369/0x4d0 kernel/rcu/tree.c:2377
rcu_core_si+0x12/0x20 kernel/rcu/tree.c:2386
__do_softirq+0x115/0x33f kernel/softirq.c:292
invoke_softirq kernel/softirq.c:373 [inline]
irq_exit+0xbb/0xe0 kernel/softirq.c:413
exiting_irq arch/x86/include/asm/apic.h:536 [inline]
smp_apic_timer_interrupt+0xe6/0x280 arch/x86/kernel/apic/apic.c:1137
apic_timer_interrupt+0xf/0x20 arch/x86/entry/entry_64.S:830
native_safe_halt+0xe/0x10 arch/x86/kernel/paravirt.c:71
arch_cpu_idle+0x1f/0x30 arch/x86/kernel/process.c:571
default_idle_call+0x1e/0x40 kernel/sched/idle.c:94
cpuidle_idle_call kernel/sched/idle.c:154 [inline]
do_idle+0x1af/0x280 kernel/sched/idle.c:263
write to 0xffff888121fb2ed0 of 4 bytes by interrupt on cpu 1:
inet_putpeer+0x37/0xa0 net/ipv4/inetpeer.c:240
ip4_frag_free+0x3d/0x50 net/ipv4/ip_fragment.c:102
inet_frag_destroy_rcu+0x58/0x80 net/ipv4/inet_fragment.c:228
__rcu_reclaim kernel/rcu/rcu.h:222 [inline]
rcu_do_batch+0x256/0x5b0 kernel/rcu/tree.c:2157
rcu_core+0x369/0x4d0 kernel/rcu/tree.c:2377
rcu_core_si+0x12/0x20 kernel/rcu/tree.c:2386
__do_softirq+0x115/0x33f kernel/softirq.c:292
run_ksoftirqd+0x46/0x60 kernel/softirq.c:603
smpboot_thread_fn+0x37d/0x4a0 kernel/smpboot.c:165
kthread+0x1d4/0x200 drivers/block/aoe/aoecmd.c:1253
ret_from_fork+0x1f/0x30 arch/x86/entry/entry_64.S:352
Reported by Kernel Concurrency Sanitizer on:
CPU: 1 PID: 16 Comm: ksoftirqd/1 Not tainted 5.4.0-rc3+ #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 01/01/2011
Fixes: 4b9d9be839fd ("inetpeer: remove unused list")
Signed-off-by: Eric Dumazet <edumazet@google.com>
Reported-by: syzbot <syzkaller@googlegroups.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2020-01-04 14:00:07 +01:00
..
2018-10-03 17:00:47 -07:00
2019-07-31 07:28:39 +02:00
2017-11-02 11:10:55 +01:00
2019-05-16 19:42:34 +02:00
2019-12-17 20:38:59 +01:00
2019-11-10 11:25:34 +01:00
2019-10-05 12:47:43 +02:00
2019-09-21 07:15:35 +02:00
2019-12-31 12:37:19 +01:00
2020-01-04 14:00:06 +01:00
2019-11-10 11:25:34 +01:00
2019-07-21 09:04:22 +02:00
2019-08-29 08:26:42 +02:00
2020-01-04 13:59:59 +01:00
2018-09-19 22:43:43 +02:00
2019-11-10 11:25:37 +01:00
2019-12-05 15:37:56 +01:00
2018-07-22 14:28:49 +02:00
2019-11-10 11:25:32 +01:00
2019-03-19 13:13:22 +01:00
2019-10-05 12:47:44 +02:00
2018-04-29 11:33:13 +02:00
2020-01-04 14:00:07 +01:00
2019-12-01 09:14:14 +01:00
2017-11-02 11:10:55 +01:00
2018-03-31 18:10:41 +02:00
2019-04-17 08:37:45 +02:00
2019-09-16 08:20:44 +02:00
2019-08-09 17:53:35 +02:00
2019-06-22 08:16:14 +02:00
2019-11-20 17:59:59 +01:00
2019-12-31 12:37:49 +01:00
2018-09-09 19:55:52 +02:00
2019-03-13 14:03:09 -07:00
2017-10-21 01:56:38 +01:00
2020-01-04 13:59:59 +01:00
2019-03-13 14:03:08 -07:00
2019-04-03 06:25:08 +02:00
2019-07-31 07:28:46 +02:00
2019-12-31 12:36:41 +01:00
2018-07-22 14:28:49 +02:00
2019-12-21 10:47:34 +01:00
2019-12-31 12:36:38 +01:00
2019-11-10 11:25:34 +01:00
2019-12-05 15:38:15 +01:00
2019-10-05 12:47:40 +02:00
2019-10-07 18:55:20 +02:00
2019-12-31 12:37:21 +01:00
2019-05-02 09:40:34 +02:00
2019-11-06 12:43:37 +01:00
2019-12-05 15:38:19 +01:00
2019-12-31 12:36:43 +01:00
2019-12-17 20:38:01 +01:00
2018-07-22 14:28:47 +02:00
2019-12-17 20:40:00 +01:00
2019-12-21 10:47:35 +01:00
2018-12-05 19:41:11 +01:00
2019-12-01 09:13:35 +01:00
2019-12-05 15:37:24 +01:00
2017-11-02 11:10:55 +01:00
2019-12-01 09:14:15 +01:00
2019-12-17 20:38:25 +01:00
2019-12-17 20:37:28 +01:00
2019-01-09 17:14:46 +01:00
2017-09-04 13:25:20 +02:00
2017-11-02 11:10:55 +01:00
2019-08-25 10:50:02 +02:00