android_kernel_motorola_sm6375/drivers/md
Repository files (latest commit first)
Filename Latest commit message Latest commit date
Krister Johansen ec037fe8c0 dm thin: make get_first_thin use rcu-safe list first function
commit 80f130bfad1dab93b95683fc39b87235682b8f72 upstream.

The documentation in rculist.h explains the absence of list_empty_rcu()
and cautions programmers against relying on a list_empty() ->
list_first() sequence in RCU safe code.  This is because each of these
functions performs its own READ_ONCE() of the list head.  This can lead
to a situation where the list_empty() sees a valid list entry, but the
subsequent list_first() sees a different view of list head state after a
modification.

In the case of dm-thin, this author had a production box crash from a GP
fault in the process_deferred_bios path.  This function saw a valid list
head in get_first_thin() but when it subsequently dereferenced that and
turned it into a thin_c, it got the inside of the struct pool, since the
list was now empty and referring to itself.  The kernel on which this
occurred printed both a warning about a refcount_t being saturated, and
a UBSAN error for an out-of-bounds cpuid access in the queued spinlock,
prior to the fault itself.  When the resulting kdump was examined, it
was possible to see another thread patiently waiting in thin_dtr's
synchronize_rcu.

The thin_dtr call managed to pull the thin_c out of the active thins
list (and have it be the last entry in the active_thins list) at just
the wrong moment which lead to this crash.

Fortunately, the fix here is straight forward.  Switch get_first_thin()
function to use list_first_or_null_rcu() which performs just a single
READ_ONCE() and returns NULL if the list is already empty.

This was run against the devicemapper test suite's thin-provisioning
suites for delete and suspend and no regressions were observed.

Signed-off-by: Krister Johansen <kjlx@templeofstupid.com>
Fixes: b10ebd34cc ("dm thin: fix rcu_read_lock being held in code that can sleep")
Cc: stable@vger.kernel.org
Acked-by: Ming-Hung Tsai <mtsai@redhat.com>
Signed-off-by: Mikulas Patocka <mpatocka@redhat.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2025-02-01 18:18:45 +01:00
..
bcache bcache: revert replacing IS_ERR_OR_NULL with IS_ERR again 2024-12-14 19:44:49 +01:00
persistent-data dm array: fix cursor index when skipping across block boundaries 2025-02-01 18:18:44 +01:00
dm-bio-prison-v1.c
dm-bio-prison-v1.h
dm-bio-prison-v2.c
dm-bio-prison-v2.h
dm-bio-record.h
dm-bufio.c
dm-builtin.c
dm-cache-background-tracker.c
dm-cache-background-tracker.h
dm-cache-block-types.h
dm-cache-metadata.c
dm-cache-metadata.h
dm-cache-policy-internal.h
dm-cache-policy-smq.c dm cache policy smq: ensure IO doesn't prevent cleaner policy progress 2023-08-11 11:53:53 +02:00
dm-cache-policy.c
dm-cache-policy.h
dm-cache-target.c dm cache: fix potential out-of-bounds access on the first resume 2024-11-17 14:58:51 +01:00
dm-clone-metadata.c bitmap: introduce generic optimized bitmap_size() 2024-09-04 13:14:50 +02:00
dm-clone-metadata.h
dm-clone-target.c dm clone: call kmem_cache_destroy() in dm_clone_init() error path 2023-05-17 11:35:56 +02:00
dm-core.h dm: limit the number of targets and parameter size area 2024-05-02 16:18:37 +02:00
dm-crypt.c dm-verity, dm-crypt: align "struct bvec_iter" correctly 2024-03-26 18:22:12 -04:00
dm-delay.c dm-delay: fix a race between delay_presuspend and delay_bio 2023-12-08 08:44:25 +01:00
dm-dust.c
dm-era-target.c
dm-exception-store.c
dm-exception-store.h
dm-flakey.c dm flakey: fix a crash with invalid table line 2023-05-17 11:35:56 +02:00
dm-init.c dm init: Handle minors larger than 255 2024-09-12 11:03:53 +02:00
dm-integrity.c dm integrity: fix out-of-range warning 2024-04-13 12:51:33 +02:00
dm-io.c treewide: Remove uninitialized_var() usage 2023-06-09 10:29:01 +02:00
dm-ioctl.c dm resume: don't return EINVAL when signalled 2024-09-04 13:14:49 +02:00
dm-kcopyd.c
dm-linear.c
dm-log-userspace-base.c
dm-log-userspace-transfer.c
dm-log-userspace-transfer.h
dm-log-writes.c
dm-log.c
dm-mpath.c dm mpath: pass IO start time to path selector 2024-09-04 13:14:58 +02:00
dm-mpath.h
dm-path-selector.c
dm-path-selector.h dm mpath: pass IO start time to path selector 2024-09-04 13:14:58 +02:00
dm-queue-length.c dm mpath: pass IO start time to path selector 2024-09-04 13:14:58 +02:00
dm-raid.c dm-raid: fix lockdep waring in "pers->hot_add_disk" 2024-04-13 12:51:25 +02:00
dm-raid1.c
dm-region-hash.c
dm-round-robin.c
dm-rq.c dm: do not use waitqueue for request-based DM 2024-09-04 13:14:58 +02:00
dm-rq.h
dm-service-time.c dm mpath: pass IO start time to path selector 2024-09-04 13:14:58 +02:00
dm-snap-persistent.c treewide: Remove uninitialized_var() usage 2023-06-09 10:29:01 +02:00
dm-snap-transient.c
dm-snap.c dm snapshot: fix lockup in dm_exception_table_exit 2024-04-13 12:51:28 +02:00
dm-stats.c dm stats: check for and propagate alloc_percpu failure 2023-04-05 11:16:41 +02:00
dm-stats.h dm stats: check for and propagate alloc_percpu failure 2023-04-05 11:16:41 +02:00
dm-stripe.c
dm-switch.c
dm-sysfs.c
dm-table.c dm: limit the number of targets and parameter size area 2024-05-02 16:18:37 +02:00
dm-target.c
dm-thin-metadata.c
dm-thin-metadata.h
dm-thin.c dm thin: make get_first_thin use rcu-safe list first function 2025-02-01 18:18:45 +01:00
dm-uevent.c
dm-uevent.h
dm-unstripe.c dm-unstriped: cast an operand to sector_t to prevent potential uint32_t overflow 2024-11-17 14:58:51 +01:00
dm-verity-fec.c dm-verity: align struct dm_verity_fec_io properly 2023-12-08 08:44:26 +01:00
dm-verity-fec.h
dm-verity-target.c dm verity: don't perform FEC for failed readahead IO 2023-12-08 08:44:26 +01:00
dm-verity-verify-sig.c
dm-verity-verify-sig.h
dm-verity.h dm-verity, dm-crypt: align "struct bvec_iter" correctly 2024-03-26 18:22:12 -04:00
dm-writecache.c
dm-zero.c
dm-zoned-metadata.c
dm-zoned-reclaim.c
dm-zoned-target.c
dm-zoned.h
dm.c dm suspend: return -ERESTARTSYS instead of -EINTR 2024-09-04 13:14:58 +02:00
dm.h
Kconfig
Makefile
md-bitmap.c md: fix resync softlockup when bitmap size is less than array size 2024-06-16 13:28:33 +02:00
md-bitmap.h
md-cluster.c
md-cluster.h
md-faulty.c
md-linear.c
md-linear.h
md-multipath.c
md-multipath.h
md.c md: clean up invalid BUG_ON in md_ioctl 2024-09-04 13:14:55 +02:00
md.h
raid0.c md/raid0: add discard support for the 'original' layout 2023-07-27 08:37:37 +02:00
raid0.h md/raid0: add discard support for the 'original' layout 2023-07-27 08:37:37 +02:00
raid1-10.c
raid1.c md/raid1: fix error: ISO C90 forbids mixed declarations 2023-09-23 11:00:06 +02:00
raid1.h
raid5-cache.c
raid5-log.h
raid5-ppl.c
raid5.c md/raid5: avoid BUG_ON() while continue reshape after reassembling 2024-08-19 05:33:46 +02:00
raid5.h
raid10.c md/raid10: improve code of mrdev in raid10_sync_request 2024-11-17 14:58:53 +01:00
raid10.h