android_kernel_motorola_sm6375/kernel/time
Repository files (latest commit first)
Filename Latest commit message Latest commit date
Thomas Gleixner 8ad6679a5b posix-timers: Ensure timer ID search-loop limit is valid
[ Upstream commit 8ce8849dd1e78dadcee0ec9acbd259d239b7069f ]

posix_timer_add() tries to allocate a posix timer ID by starting from the
cached ID which was stored by the last successful allocation.

This is done in a loop searching the ID space for a free slot one by
one. The loop has to terminate when the search wrapped around to the
starting point.

But that's racy vs. establishing the starting point. That is read out
lockless, which leads to the following problem:

CPU0	  	      	     	   CPU1
posix_timer_add()
  start = sig->posix_timer_id;
  lock(hash_lock);
  ...				   posix_timer_add()
  if (++sig->posix_timer_id < 0)
      			             start = sig->posix_timer_id;
     sig->posix_timer_id = 0;

So CPU1 can observe a negative start value, i.e. -1, and the loop break
never happens because the condition can never be true:

  if (sig->posix_timer_id == start)
     break;

While this is unlikely to ever turn into an endless loop as the ID space is
huge (INT_MAX), the racy read of the start value caught the attention of
KCSAN and Dmitry unearthed that incorrectness.

Rewrite it so that all id operations are under the hash lock.

Reported-by: syzbot+5c54bd3eb218bb595aa9@syzkaller.appspotmail.com
Reported-by: Dmitry Vyukov <dvyukov@google.com>
Signed-off-by: Thomas Gleixner <tglx@linutronix.de>
Reviewed-by: Frederic Weisbecker <frederic@kernel.org>
Link: https://lore.kernel.org/r/87bkhzdn6g.ffs@tglx
Signed-off-by: Sasha Levin <sashal@kernel.org>
2023-07-27 08:37:42 +02:00
..
alarmtimer.c alarmtimer: Prevent starvation by small intervals and SIG_IGN 2023-02-25 11:53:26 +01:00
clockevents.c
clocksource.c
hrtimer.c timers: Prevent union confusion from unexpected restart_syscall() 2023-03-11 16:43:54 +01:00
itimer.c
jiffies.c timekeeping: Split jiffies seqlock 2023-05-17 11:35:39 +02:00
Kconfig
Makefile
ntp.c
ntp_internal.h
posix-clock.c
posix-cpu-timers.c Revert "posix-cpu-timers: Force next expiration recalc after itimer reset" 2021-09-16 12:56:13 +02:00
posix-stubs.c timers: Prevent union confusion from unexpected restart_syscall() 2023-03-11 16:43:54 +01:00
posix-timers.c posix-timers: Ensure timer ID search-loop limit is valid 2023-07-27 08:37:42 +02:00
posix-timers.h
sched_clock.c
test_udelay.c
tick-broadcast-hrtimer.c
tick-broadcast.c tick: Get rid of tick_period 2023-05-17 11:35:40 +02:00
tick-common.c tick/common: Align tick period during sched_timer setup 2023-06-28 10:18:36 +02:00
tick-internal.h tick: Get rid of tick_period 2023-05-17 11:35:40 +02:00
tick-oneshot.c
tick-sched.c tick/common: Align tick period during sched_timer setup 2023-06-28 10:18:36 +02:00
tick-sched.h
time.c
timeconst.bc
timeconv.c
timecounter.c
timekeeping.c timekeeping: Split jiffies seqlock 2023-05-17 11:35:39 +02:00
timekeeping.h timekeeping: Split jiffies seqlock 2023-05-17 11:35:39 +02:00
timekeeping_debug.c
timekeeping_internal.h
timer.c
timer_list.c
vsyscall.c