Thomas Gleixner
42ac2c6348
timers: Move clearing of base::timer_running under base:: Lock
...
commit bb7262b295472eb6858b5c49893954794027cd84 upstream.
syzbot reported KCSAN data races vs. timer_base::timer_running being set to
NULL without holding base::lock in expire_timers().
This looks innocent and most reads are clearly not problematic, but
Frederic identified an issue which is:
int data = 0;
void timer_func(struct timer_list *t)
{
data = 1;
}
CPU 0 CPU 1
------------------------------ --------------------------
base = lock_timer_base(timer, &flags); raw_spin_unlock(&base->lock);
if (base->running_timer != timer) call_timer_fn(timer, fn, baseclk);
ret = detach_if_pending(timer, base, true); base->running_timer = NULL;
raw_spin_unlock_irqrestore(&base->lock, flags); raw_spin_lock(&base->lock);
x = data;
If the timer has previously executed on CPU 1 and then CPU 0 can observe
base->running_timer == NULL and returns, assuming the timer has completed,
but it's not guaranteed on all architectures. The comment for
del_timer_sync() makes that guarantee. Moving the assignment under
base->lock prevents this.
For non-RT kernel it's performance wise completely irrelevant whether the
store happens before or after taking the lock. For an RT kernel moving the
store under the lock requires an extra unlock/lock pair in the case that
there is a waiter for the timer, but that's not the end of the world.
Reported-by: syzbot+aa7c2385d46c5eba0b89@syzkaller.appspotmail.com
Reported-by: syzbot+abea4558531bae1ba9fe@syzkaller.appspotmail.com
Fixes: 030dcdd197 ("timers: Prepare support for PREEMPT_RT")
Signed-off-by: Thomas Gleixner <tglx@linutronix.de>
Tested-by: Sebastian Andrzej Siewior <bigeasy@linutronix.de>
Link: https://lore.kernel.org/r/87lfea7gw8.fsf@nanos.tec.linutronix.de
Cc: stable@vger.kernel.org
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2021-08-12 13:21:03 +02:00
..
bpf
bpf: Fix leakage under speculation on mispredicted branches
2021-08-08 09:04:08 +02:00
cgroup
cgroup1: fix leaked context root causing sporadic NULL deref in LTP
2021-07-31 08:19:37 +02:00
configs
debug
kdb: Make memory allocations more robust
2021-03-04 10:26:10 +01:00
dma
swiotlb: fix "x86: Don't panic if can not alloc buffer for swiotlb"
2020-11-18 19:20:32 +01:00
events
perf: Fix data race between pin_count increment/decrement
2021-06-16 11:59:44 +02:00
gcov
gcov: re-fix clang-11+ support
2021-04-14 08:24:10 +02:00
irq
genirq/matrix: Prevent allocation counter corruption
2021-05-11 14:04:05 +02:00
livepatch
locking
lockding/lockdep: Avoid to find wrong lock dep path in check_irq_usage()
2021-07-14 16:53:15 +02:00
power
PM: EM: postpone creating the debugfs dir till fs_initcall
2021-03-30 14:35:28 +02:00
printk
printk: fix deadlock when kernel panic
2021-03-04 10:26:50 +01:00
rcu
srcu: Fix broken node geometry after early ssp init
2021-07-20 16:10:41 +02:00
sched
sched/fair: Fix CFS bandwidth hrtimer expiry type
2021-07-25 14:35:13 +02:00
time
timers: Move clearing of base::timer_running under base:: Lock
2021-08-12 13:21:03 +02:00
trace
tracing / histogram: Give calculation hist_fields a size
2021-08-12 13:21:00 +02:00
.gitignore
kbuild: update config_data.gz only when the content of .config is changed
2021-05-11 14:04:16 +02:00
acct.c
async.c
audit.c
audit: fix a net reference leak in audit_list_rules_send()
2020-06-22 09:30:59 +02:00
audit.h
audit: fix a net reference leak in audit_list_rules_send()
2020-06-22 09:30:59 +02:00
audit_fsnotify.c
audit_tree.c
audit_watch.c
audit: CONFIG_CHANGE don't log internal bookkeeping as an event
2020-10-01 13:17:32 +02:00
auditfilter.c
audit: fix a net reference leak in audit_list_rules_send()
2020-06-22 09:30:59 +02:00
auditsc.c
backtracetest.c
bounds.c
capability.c
compat.c
configs.c
context_tracking.c
cpu.c
cpu/hotplug: Cure the cpusets trainwreck
2021-07-19 08:53:15 +02:00
cpu_pm.c
kernel/cpu_pm: Fix uninitted local in cpu_pm
2020-06-22 09:31:22 +02:00
crash_core.c
crash_dump.c
cred.c
delayacct.c
dma.c
exec_domain.c
exit.c
don't dump the threads that had been already exiting when zapped.
2020-11-18 19:20:31 +01:00
extable.c
fail_function.c
fail_function: Remove a redundant mutex unlock
2020-11-24 13:29:18 +01:00
fork.c
exec: Transform exec_update_mutex into a rw_semaphore
2021-01-09 13:44:55 +01:00
freezer.c
futex.c
mm, futex: fix shared futex pgoff on shmem huge page
2021-06-30 08:47:55 -04:00
gen_kheaders.sh
kbuild: add variables for compression tools
2020-09-03 11:27:10 +02:00
groups.c
hung_task.c
iomem.c
irq_work.c
jump_label.c
kallsyms.c
kallsyms: Refactor kallsyms_show_value() to take cred
2020-07-16 08:16:44 +02:00
kcmp.c
exec: Transform exec_update_mutex into a rw_semaphore
2021-01-09 13:44:55 +01:00
Kconfig.freezer
Kconfig.hz
Kconfig.locks
Kconfig.preempt
kcov.c
kexec.c
kexec_core.c
kernel: kexec: remove the lock operation of system_transition_mutex
2021-02-03 23:25:56 +01:00
kexec_elf.c
kexec_file.c
kernel: kexec_file: fix error return code of kexec_calculate_store_digests()
2021-05-19 10:08:28 +02:00
kexec_internal.h
kheaders.c
kmod.c
kmod: make request_module() return an error when autoloading is disabled
2020-04-17 10:50:22 +02:00
kprobes.c
tracing/kprobe: Fix to support kretprobe events on unloaded modules
2021-02-13 13:52:54 +01:00
ksysfs.c
kthread.c
kthread_worker: fix return value when kthread_mod_delayed_work() races with kthread_cancel_delayed_work_sync()
2021-07-14 16:53:19 +02:00
latencytop.c
Makefile
kbuild: update config_data.gz only when the content of .config is changed
2021-05-11 14:04:16 +02:00
module-internal.h
module.c
module: limit enabling module.sig_enforce
2021-06-30 08:47:42 -04:00
module_signature.c
module: harden ELF info handling
2021-04-07 14:47:38 +02:00
module_signing.c
module: harden ELF info handling
2021-04-07 14:47:38 +02:00
notifier.c
kernel/notifier.c: intercept duplicate registrations to avoid infinite loops
2020-10-01 13:17:23 +02:00
nsproxy.c
padata.c
padata: add separate cpuhp node for CPUHP_PADATA_DEAD
2020-06-17 16:40:22 +02:00
panic.c
params.c
pid.c
pid_namespace.c
profile.c
ptrace.c
ptrace: make ptrace() fail if the tracee changed its pid unexpectedly
2021-05-26 12:05:15 +02:00
range.c
reboot.c
reboot: fix overflow parsing reboot cpu number
2020-11-18 19:20:30 +01:00
relay.c
kernel/relay.c: fix memleak on destroy relay channel
2020-08-26 10:40:51 +02:00
resource.c
/dev/mem: Revoke mappings when a driver claims the region
2020-06-24 17:50:35 +02:00
rseq.c
seccomp.c
seccomp: Add missing return in non-void function
2021-03-04 10:26:45 +01:00
signal.c
ptrace: fix task_join_group_stop() for the case when current is traced
2020-11-10 12:37:24 +01:00
smp.c
smp: Fix smp_call_function_single_async prototype
2021-05-14 09:44:33 +02:00
smpboot.c
kthread: Extract KTHREAD_IS_PER_CPU
2021-02-07 15:35:49 +01:00
smpboot.h
softirq.c
stackleak.c
stacktrace.c
stop_machine.c
sys.c
kernel/sys.c: avoid copying possible padding bytes in copy_to_user
2020-10-01 13:17:23 +02:00
sys_ni.c
sysctl-test.c
kernel/sysctl-test: Add null pointer test for sysctl.c:proc_dointvec()
2020-10-01 13:17:10 +02:00
sysctl.c
sysctl.c: fix underflow value setting risk in vm_table
2021-03-17 17:03:45 +01:00
sysctl_binary.c
task_work.c
taskstats.c
test_kprobes.c
torture.c
tracepoint.c
tracepoint: Add tracepoint_probe_register_may_exist() for BPF tracing
2021-07-14 16:53:08 +02:00
tsacct.c
ucount.c
uid16.c
uid16.h
umh.c
usermodehelper: reset umask to default before executing user process
2020-10-14 10:32:58 +02:00
up.c
smp: Fix smp_call_function_single_async prototype
2021-05-14 09:44:33 +02:00
user-return-notifier.c
user.c
user_namespace.c
utsname.c
utsname_sysctl.c
watchdog.c
watchdog_hld.c
workqueue.c
workqueue: fix UAF in pwq_unbound_release_workfn()
2021-07-31 08:19:37 +02:00
workqueue_internal.h