android_kernel_motorola_sm6375/kernel
Repository files (latest commit first)
Filename Latest commit message Latest commit date
Thomas Gleixner 904fb159c9 UPSTREAM: futex: Handle faults correctly for PI futexes
commit 34b1a1ce1458f50ef27c54e28eb9b1947012907a upstream

fixup_pi_state_owner() tries to ensure that the state of the rtmutex,
pi_state and the user space value related to the PI futex are consistent
before returning to user space. In case that the user space value update
faults and the fault cannot be resolved by faulting the page in via
fault_in_user_writeable() the function returns with -EFAULT and leaves
the rtmutex and pi_state owner state inconsistent.

A subsequent futex_unlock_pi() operates on the inconsistent pi_state and
releases the rtmutex despite not owning it which can corrupt the RB tree of
the rtmutex and cause a subsequent kernel stack use after free.

It was suggested to loop forever in fixup_pi_state_owner() if the fault
cannot be resolved, but that results in runaway tasks which is especially
undesired when the problem happens due to a programming error and not due
to malice.

As the user space value cannot be fixed up, the proper solution is to make
the rtmutex and the pi_state consistent so both have the same owner. This
leaves the user space value out of sync. Any subsequent operation on the
futex will fail because the 10th rule of PI futexes (pi_state owner and
user space value are consistent) has been violated.

As a consequence this removes the inept attempts of 'fixing' the situation
in case that the current task owns the rtmutex when returning with an
unresolvable fault by unlocking the rtmutex which left pi_state::owner and
rtmutex::owner out of sync in a different and only slightly less dangerous
way.

Fixes: 1b7558e457 ("futexes: fix fault handling in futex_lock_pi")
Reported-by: gzobqq@gmail.com
Signed-off-by: Thomas Gleixner <tglx@linutronix.de>
Acked-by: Peter Zijlstra (Intel) <peterz@infradead.org>
Cc: stable@vger.kernel.org
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
(cherry picked from commit 34b1a1ce1458f50ef27c54e28eb9b1947012907a)
Signed-off-by: Greg Kroah-Hartman <gregkh@google.com>
Change-Id: Iabd44dad5d4b8385b8a20e44d18308708cc3b701
2021-01-29 13:16:10 +01:00
..
bpf This is the 5.4.57 stable release 2020-08-07 10:07:58 +02:00
cgroup This is the 5.4.53 stable release 2020-07-23 12:36:54 +02:00
configs
debug kgdb: Avoid suspicious RCU usage warning 2020-07-09 09:37:51 +02:00
dma This is the 5.4.36 stable release 2020-04-29 17:24:24 +02:00
events This is the 5.4.61 stable release 2020-08-26 11:11:38 +02:00
gcov kernel/gcov/fs.c: gcov_seq_next() should increase position index 2020-04-29 16:33:00 +02:00
irq Revert "ANDROID: Revert: Merge 5.4.60 into android11-5.4" 2020-08-23 13:12:51 +02:00
livepatch ANDROID: kallsyms: increase KSYM_NAME_LEN 2020-08-04 19:33:41 +00:00
locking UPSTREAM: rtmutex: Remove unused argument from rt_mutex_proxy_unlock() 2021-01-29 13:15:42 +01:00
power ANDROID: power: Export log_{suspend_abort,abnormal_wakeup}_reason 2020-08-25 20:46:53 +00:00
printk ANDROID: vendor_hooks: Add vendor hooks for getting printk messages 2020-09-14 14:42:20 +00:00
rcu BACKPORT: rcu/tree: Export rcu_idle_{enter,exit} to modules 2020-11-04 01:02:40 +00:00
sched ANDROID: sched: add em_pd_energy vendor hook 2021-01-21 10:32:49 +08:00
time UPSTREAM: tick/common: Touch watchdog in tick_unfreeze() on all CPUs 2020-11-18 02:12:36 +00:00
trace Revert "tracing: Move pipe reference to trace array instead of current_tracer" 2020-08-23 13:12:53 +02:00
.gitignore
acct.c
async.c
audit.c audit: fix a net reference leak in audit_list_rules_send() 2020-06-22 09:30:59 +02:00
audit.h audit: fix a net reference leak in audit_list_rules_send() 2020-06-22 09:30:59 +02:00
audit_fsnotify.c
audit_tree.c
audit_watch.c audit_get_nd(): don't unlock parent too early 2019-11-10 11:56:55 -05:00
auditfilter.c audit: fix a net reference leak in audit_list_rules_send() 2020-06-22 09:30:59 +02:00
auditsc.c
backtracetest.c
bounds.c
capability.c
cfi.c ANDROID: cfi: ensure RCU is watching in __cfi_slowpath 2020-11-02 18:55:52 +00:00
compat.c
configs.c
context_tracking.c
cpu.c This is the 5.4.48 stable release 2020-06-22 11:43:59 +02:00
cpu_pm.c kernel/cpu_pm: Fix uninitted local in cpu_pm 2020-06-22 09:31:22 +02:00
crash_core.c
crash_dump.c
cred.c keys: Fix request_key() cache 2020-01-17 19:48:42 +01:00
delayacct.c
dma.c
elfcore.c kernel/elfcore.c: include proper prototypes 2019-09-25 17:51:39 -07:00
exec_domain.c
exit.c exit: Move preemption fixup up, move blocking operations down 2020-06-22 09:31:01 +02:00
extable.c
fail_function.c
fork.c FROMGIT: mm, oom_adj: don't loop through tasks in __set_oom_adj when not necessary 2020-09-15 09:34:00 -07:00
freezer.c Revert "libata, freezer: avoid block device removal while system is frozen" 2019-10-06 09:11:37 -06:00
futex.c UPSTREAM: futex: Handle faults correctly for PI futexes 2021-01-29 13:16:10 +01:00
gen_kheaders.sh kheaders: substituting --sort in archive creation 2019-10-17 09:08:19 +09:00
groups.c
hung_task.c
iomem.c
irq_work.c
jump_label.c
kallsyms.c ANDROID: kallsyms: ignore ThinLTO+CFI hash suffix in kallsyms_lookup_name() 2020-09-22 20:17:26 +00:00
kcmp.c
Kconfig.freezer
Kconfig.hz
Kconfig.locks
Kconfig.preempt
kcov.c UPSTREAM: kcov: remote coverage support 2020-01-13 18:54:56 +00:00
kexec.c
kexec_core.c kexec: bail out upon SIGKILL when allocating memory. 2019-09-25 17:51:40 -07:00
kexec_elf.c
kexec_file.c Merge branch 'next-lockdown' of git://git.kernel.org/pub/scm/linux/kernel/git/jmorris/linux-security 2019-09-28 08:14:15 -07:00
kexec_internal.h
kheaders.c
kmod.c kmod: make request_module() return an error when autoloading is disabled 2020-04-17 10:50:22 +02:00
kprobes.c Revert "ANDROID: Revert: Merge 5.4.60 into android11-5.4" 2020-08-23 13:12:51 +02:00
ksysfs.c
kthread.c ANDROID: kthread: break dependency between worker->lock and task_struct->pi_lock 2020-12-08 11:48:06 -08:00
latencytop.c
Makefile ANDROID: add support for Clang's Control Flow Integrity (CFI) 2019-11-27 12:49:12 -08:00
module-internal.h
module.c ANDROID: modules: cfi cleanup for module load failure 2020-11-06 10:09:05 +05:30
module_signature.c
module_signing.c
notifier.c x86/mm: split vmalloc_sync_all() 2020-03-25 08:25:58 +01:00
nsproxy.c
padata.c padata: add separate cpuhp node for CPUHP_PADATA_DEAD 2020-06-17 16:40:22 +02:00
panic.c panic: ensure preemption is disabled during panic() 2019-10-07 15:47:19 -07:00
params.c
pid.c ANDROID: GKI: pid: Export for find_task_by_vpid 2020-09-28 18:10:49 +00:00
pid_namespace.c
profile.c
ptrace.c ptrace: reintroduce usage of subjective credentials in ptrace_has_cap() 2020-01-23 08:22:36 +01:00
range.c
reboot.c FROMLIST: reboot: Export reboot_mode 2019-11-25 11:46:31 -08:00
relay.c kernel/relay.c: fix memleak on destroy relay channel 2020-08-26 10:40:51 +02:00
resource.c /dev/mem: Revoke mappings when a driver claims the region 2020-06-24 17:50:35 +02:00
rseq.c
scs.c ANDROID: scs: fix recursive spinlock in scs_check_usage 2020-06-09 08:28:50 +00:00
seccomp.c seccomp: Fix ioctl number for SECCOMP_IOCTL_NOTIF_ID_VALID 2020-08-19 08:15:58 +02:00
signal.c ANDROID: GKI: signal: Export for __lock_task_sighand 2020-09-28 18:10:21 +00:00
smp.c
smpboot.c
smpboot.h
softirq.c
stackleak.c
stacktrace.c stacktrace: Don't skip first entry on noncurrent tasks 2019-11-04 21:19:25 +01:00
stop_machine.c stop_machine: Avoid potential race behaviour 2019-10-17 12:47:12 +02:00
sys.c Merge Linus's 5.4-rc1-prerelease branch into android-mainline 2019-09-20 16:07:54 -07:00
sys_ni.c
sysctl.c This is the 5.4.8 stable release 2020-01-04 19:40:03 +01:00
sysctl_binary.c
task_work.c
taskstats.c taskstats: fix data-race 2020-01-09 10:19:54 +01:00
test_kprobes.c
torture.c
tracepoint.c
tsacct.c
ucount.c
uid16.c
uid16.h
umh.c umh: fix memory leak on execve failure 2020-05-20 08:20:13 +02:00
up.c
user-return-notifier.c
user.c Revert "ANDROID: proc: Add /proc/uid directory" 2020-03-06 20:23:08 +00:00
user_namespace.c
utsname.c
utsname_sysctl.c
watchdog.c watchdog/softlockup: Enforce that timestamp is valid on boot 2020-02-24 08:36:52 +01:00
watchdog_hld.c
workqueue.c ANDROID: workqueue: add vendor hook for wq lockup information 2020-10-05 10:27:15 +09:00
workqueue_internal.h