Thomas Gleixner
904fb159c9
UPSTREAM: futex: Handle faults correctly for PI futexes
...
commit 34b1a1ce1458f50ef27c54e28eb9b1947012907a upstream
fixup_pi_state_owner() tries to ensure that the state of the rtmutex,
pi_state and the user space value related to the PI futex are consistent
before returning to user space. In case that the user space value update
faults and the fault cannot be resolved by faulting the page in via
fault_in_user_writeable() the function returns with -EFAULT and leaves
the rtmutex and pi_state owner state inconsistent.
A subsequent futex_unlock_pi() operates on the inconsistent pi_state and
releases the rtmutex despite not owning it which can corrupt the RB tree of
the rtmutex and cause a subsequent kernel stack use after free.
It was suggested to loop forever in fixup_pi_state_owner() if the fault
cannot be resolved, but that results in runaway tasks which is especially
undesired when the problem happens due to a programming error and not due
to malice.
As the user space value cannot be fixed up, the proper solution is to make
the rtmutex and the pi_state consistent so both have the same owner. This
leaves the user space value out of sync. Any subsequent operation on the
futex will fail because the 10th rule of PI futexes (pi_state owner and
user space value are consistent) has been violated.
As a consequence this removes the inept attempts of 'fixing' the situation
in case that the current task owns the rtmutex when returning with an
unresolvable fault by unlocking the rtmutex which left pi_state::owner and
rtmutex::owner out of sync in a different and only slightly less dangerous
way.
Fixes: 1b7558e457 ("futexes: fix fault handling in futex_lock_pi")
Reported-by: gzobqq@gmail.com
Signed-off-by: Thomas Gleixner <tglx@linutronix.de>
Acked-by: Peter Zijlstra (Intel) <peterz@infradead.org>
Cc: stable@vger.kernel.org
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
(cherry picked from commit 34b1a1ce1458f50ef27c54e28eb9b1947012907a)
Signed-off-by: Greg Kroah-Hartman <gregkh@google.com>
Change-Id: Iabd44dad5d4b8385b8a20e44d18308708cc3b701
2021-01-29 13:16:10 +01:00
..
bpf
This is the 5.4.57 stable release
2020-08-07 10:07:58 +02:00
cgroup
This is the 5.4.53 stable release
2020-07-23 12:36:54 +02:00
configs
debug
kgdb: Avoid suspicious RCU usage warning
2020-07-09 09:37:51 +02:00
dma
This is the 5.4.36 stable release
2020-04-29 17:24:24 +02:00
events
This is the 5.4.61 stable release
2020-08-26 11:11:38 +02:00
gcov
kernel/gcov/fs.c: gcov_seq_next() should increase position index
2020-04-29 16:33:00 +02:00
irq
Revert "ANDROID: Revert: Merge 5.4.60 into android11-5.4"
2020-08-23 13:12:51 +02:00
livepatch
ANDROID: kallsyms: increase KSYM_NAME_LEN
2020-08-04 19:33:41 +00:00
locking
UPSTREAM: rtmutex: Remove unused argument from rt_mutex_proxy_unlock()
2021-01-29 13:15:42 +01:00
power
ANDROID: power: Export log_{suspend_abort,abnormal_wakeup}_reason
2020-08-25 20:46:53 +00:00
printk
ANDROID: vendor_hooks: Add vendor hooks for getting printk messages
2020-09-14 14:42:20 +00:00
rcu
BACKPORT: rcu/tree: Export rcu_idle_{enter,exit} to modules
2020-11-04 01:02:40 +00:00
sched
ANDROID: sched: add em_pd_energy vendor hook
2021-01-21 10:32:49 +08:00
time
UPSTREAM: tick/common: Touch watchdog in tick_unfreeze() on all CPUs
2020-11-18 02:12:36 +00:00
trace
Revert "tracing: Move pipe reference to trace array instead of current_tracer"
2020-08-23 13:12:53 +02:00
.gitignore
acct.c
async.c
audit.c
audit: fix a net reference leak in audit_list_rules_send()
2020-06-22 09:30:59 +02:00
audit.h
audit: fix a net reference leak in audit_list_rules_send()
2020-06-22 09:30:59 +02:00
audit_fsnotify.c
audit_tree.c
audit_watch.c
audit_get_nd(): don't unlock parent too early
2019-11-10 11:56:55 -05:00
auditfilter.c
audit: fix a net reference leak in audit_list_rules_send()
2020-06-22 09:30:59 +02:00
auditsc.c
backtracetest.c
bounds.c
capability.c
cfi.c
ANDROID: cfi: ensure RCU is watching in __cfi_slowpath
2020-11-02 18:55:52 +00:00
compat.c
configs.c
context_tracking.c
cpu.c
This is the 5.4.48 stable release
2020-06-22 11:43:59 +02:00
cpu_pm.c
kernel/cpu_pm: Fix uninitted local in cpu_pm
2020-06-22 09:31:22 +02:00
crash_core.c
crash_dump.c
cred.c
keys: Fix request_key() cache
2020-01-17 19:48:42 +01:00
delayacct.c
dma.c
elfcore.c
kernel/elfcore.c: include proper prototypes
2019-09-25 17:51:39 -07:00
exec_domain.c
exit.c
exit: Move preemption fixup up, move blocking operations down
2020-06-22 09:31:01 +02:00
extable.c
fail_function.c
fork.c
FROMGIT: mm, oom_adj: don't loop through tasks in __set_oom_adj when not necessary
2020-09-15 09:34:00 -07:00
freezer.c
Revert "libata, freezer: avoid block device removal while system is frozen"
2019-10-06 09:11:37 -06:00
futex.c
UPSTREAM: futex: Handle faults correctly for PI futexes
2021-01-29 13:16:10 +01:00
gen_kheaders.sh
kheaders: substituting --sort in archive creation
2019-10-17 09:08:19 +09:00
groups.c
hung_task.c
iomem.c
irq_work.c
jump_label.c
kallsyms.c
ANDROID: kallsyms: ignore ThinLTO+CFI hash suffix in kallsyms_lookup_name()
2020-09-22 20:17:26 +00:00
kcmp.c
Kconfig.freezer
Kconfig.hz
Kconfig.locks
Kconfig.preempt
kcov.c
UPSTREAM: kcov: remote coverage support
2020-01-13 18:54:56 +00:00
kexec.c
kexec_core.c
kexec: bail out upon SIGKILL when allocating memory.
2019-09-25 17:51:40 -07:00
kexec_elf.c
kexec_file.c
Merge branch 'next-lockdown' of git://git.kernel.org/pub/scm/linux/kernel/git/jmorris/linux-security
2019-09-28 08:14:15 -07:00
kexec_internal.h
kheaders.c
kmod.c
kmod: make request_module() return an error when autoloading is disabled
2020-04-17 10:50:22 +02:00
kprobes.c
Revert "ANDROID: Revert: Merge 5.4.60 into android11-5.4"
2020-08-23 13:12:51 +02:00
ksysfs.c
kthread.c
ANDROID: kthread: break dependency between worker->lock and task_struct->pi_lock
2020-12-08 11:48:06 -08:00
latencytop.c
Makefile
ANDROID: add support for Clang's Control Flow Integrity (CFI)
2019-11-27 12:49:12 -08:00
module-internal.h
module.c
ANDROID: modules: cfi cleanup for module load failure
2020-11-06 10:09:05 +05:30
module_signature.c
module_signing.c
notifier.c
x86/mm: split vmalloc_sync_all()
2020-03-25 08:25:58 +01:00
nsproxy.c
padata.c
padata: add separate cpuhp node for CPUHP_PADATA_DEAD
2020-06-17 16:40:22 +02:00
panic.c
panic: ensure preemption is disabled during panic()
2019-10-07 15:47:19 -07:00
params.c
pid.c
ANDROID: GKI: pid: Export for find_task_by_vpid
2020-09-28 18:10:49 +00:00
pid_namespace.c
profile.c
ptrace.c
ptrace: reintroduce usage of subjective credentials in ptrace_has_cap()
2020-01-23 08:22:36 +01:00
range.c
reboot.c
FROMLIST: reboot: Export reboot_mode
2019-11-25 11:46:31 -08:00
relay.c
kernel/relay.c: fix memleak on destroy relay channel
2020-08-26 10:40:51 +02:00
resource.c
/dev/mem: Revoke mappings when a driver claims the region
2020-06-24 17:50:35 +02:00
rseq.c
scs.c
ANDROID: scs: fix recursive spinlock in scs_check_usage
2020-06-09 08:28:50 +00:00
seccomp.c
seccomp: Fix ioctl number for SECCOMP_IOCTL_NOTIF_ID_VALID
2020-08-19 08:15:58 +02:00
signal.c
ANDROID: GKI: signal: Export for __lock_task_sighand
2020-09-28 18:10:21 +00:00
smp.c
smpboot.c
smpboot.h
softirq.c
stackleak.c
stacktrace.c
stacktrace: Don't skip first entry on noncurrent tasks
2019-11-04 21:19:25 +01:00
stop_machine.c
stop_machine: Avoid potential race behaviour
2019-10-17 12:47:12 +02:00
sys.c
Merge Linus's 5.4-rc1-prerelease branch into android-mainline
2019-09-20 16:07:54 -07:00
sys_ni.c
sysctl.c
This is the 5.4.8 stable release
2020-01-04 19:40:03 +01:00
sysctl_binary.c
task_work.c
taskstats.c
taskstats: fix data-race
2020-01-09 10:19:54 +01:00
test_kprobes.c
torture.c
tracepoint.c
tsacct.c
ucount.c
uid16.c
uid16.h
umh.c
umh: fix memory leak on execve failure
2020-05-20 08:20:13 +02:00
up.c
user-return-notifier.c
user.c
Revert "ANDROID: proc: Add /proc/uid directory"
2020-03-06 20:23:08 +00:00
user_namespace.c
utsname.c
utsname_sysctl.c
watchdog.c
watchdog/softlockup: Enforce that timestamp is valid on boot
2020-02-24 08:36:52 +01:00
watchdog_hld.c
workqueue.c
ANDROID: workqueue: add vendor hook for wq lockup information
2020-10-05 10:27:15 +09:00
workqueue_internal.h