Jiri Olsa
c5cf5c7b58
perf/core: Fix race in the perf_mmap_close() function
...
commit f91072ed1b7283b13ca57fcfbece5a3b92726143 upstream.
There's a possible race in perf_mmap_close() when checking ring buffer's
mmap_count refcount value. The problem is that the mmap_count check is
not atomic because we call atomic_dec() and atomic_read() separately.
perf_mmap_close:
...
atomic_dec(&rb->mmap_count);
...
if (atomic_read(&rb->mmap_count))
goto out_put;
<ring buffer detach>
free_uid
out_put:
ring_buffer_put(rb); /* could be last */
The race can happen when we have two (or more) events sharing same ring
buffer and they go through atomic_dec() and then they both see 0 as refcount
value later in atomic_read(). Then both will go on and execute code which
is meant to be run just once.
The code that detaches ring buffer is probably fine to be executed more
than once, but the problem is in calling free_uid(), which will later on
demonstrate in related crashes and refcount warnings, like:
refcount_t: addition on 0; use-after-free.
...
RIP: 0010:refcount_warn_saturate+0x6d/0xf
...
Call Trace:
prepare_creds+0x190/0x1e0
copy_creds+0x35/0x172
copy_process+0x471/0x1a80
_do_fork+0x83/0x3a0
__do_sys_wait4+0x83/0x90
__do_sys_clone+0x85/0xa0
do_syscall_64+0x5b/0x1e0
entry_SYSCALL_64_after_hwframe+0x44/0xa9
Using atomic decrease and check instead of separated calls.
Tested-by: Michael Petlan <mpetlan@redhat.com>
Signed-off-by: Jiri Olsa <jolsa@kernel.org>
Signed-off-by: Ingo Molnar <mingo@kernel.org>
Acked-by: Peter Zijlstra <a.p.zijlstra@chello.nl>
Acked-by: Namhyung Kim <namhyung@kernel.org>
Acked-by: Wade Mealing <wmealing@redhat.com>
Fixes: 9bb5d40cd9 ("perf: Fix mmap() accounting hole");
Link: https://lore.kernel.org/r/20200916115311.GE2301783@krava
[sudip: used ring_buffer]
Signed-off-by: Sudip Mukherjee <sudipm.mukherjee@gmail.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2020-11-18 19:20:33 +01:00
..
bpf
bpf: Zero-fill re-used per-cpu map element
2020-11-18 19:20:26 +01:00
cgroup
cgroup: fix cgroup_sk_alloc() for sk_clone_lock()
2020-07-22 09:32:49 +02:00
configs
debug
kgdb: Make "kgdbcon" work properly with "kgdb_earlycon"
2020-11-05 11:43:16 +01:00
dma
swiotlb: fix "x86: Don't panic if can not alloc buffer for swiotlb"
2020-11-18 19:20:32 +01:00
events
perf/core: Fix race in the perf_mmap_close() function
2020-11-18 19:20:33 +01:00
gcov
gcov: add support for GCC 10.1
2020-09-17 13:47:56 +02:00
irq
genirq: Let GENERIC_IRQ_IPI select IRQ_DOMAIN_HIERARCHY
2020-11-18 19:20:16 +01:00
livepatch
locking
locking/lockdep: Decrement IRQ context counters when removing lock chain
2020-10-01 13:17:33 +02:00
power
PM: hibernate: remove the bogus call to get_gendisk() in software_resume()
2020-10-29 09:58:04 +01:00
printk
printk: handle blank console arguments passed in.
2020-10-01 13:18:04 +02:00
rcu
rcu: Allow only one expedited GP to run concurrently with wakeups
2020-03-05 16:43:50 +01:00
sched
sched/features: Fix !CONFIG_JUMP_LABEL case
2020-10-29 09:58:00 +01:00
time
tick/common: Touch watchdog in tick_unfreeze() on all CPUs
2020-11-18 19:20:26 +01:00
trace
tracing: Fix the checking of stackidx in __ftrace_trace_stack
2020-11-18 19:20:23 +01:00
.gitignore
acct.c
async.c
audit.c
audit: fix a net reference leak in audit_list_rules_send()
2020-06-22 09:30:59 +02:00
audit.h
audit: fix a net reference leak in audit_list_rules_send()
2020-06-22 09:30:59 +02:00
audit_fsnotify.c
audit_tree.c
audit_watch.c
audit: CONFIG_CHANGE don't log internal bookkeeping as an event
2020-10-01 13:17:32 +02:00
auditfilter.c
audit: fix a net reference leak in audit_list_rules_send()
2020-06-22 09:30:59 +02:00
auditsc.c
backtracetest.c
bounds.c
capability.c
compat.c
configs.c
context_tracking.c
cpu.c
sched/core: Fix illegal RCU from offline CPUs
2020-06-22 09:31:01 +02:00
cpu_pm.c
kernel/cpu_pm: Fix uninitted local in cpu_pm
2020-06-22 09:31:22 +02:00
crash_core.c
crash_dump.c
cred.c
keys: Fix request_key() cache
2020-01-17 19:48:42 +01:00
delayacct.c
dma.c
elfcore.c
kernel/elfcore.c: include proper prototypes
2019-09-25 17:51:39 -07:00
exec_domain.c
exit.c
don't dump the threads that had been already exiting when zapped.
2020-11-18 19:20:31 +01:00
extable.c
fail_function.c
fork.c
fork: fix copy_process(CLONE_PARENT) race with the exiting ->real_parent
2020-11-10 12:37:32 +01:00
freezer.c
Revert "libata, freezer: avoid block device removal while system is frozen"
2019-10-06 09:11:37 -06:00
futex.c
futex: Don't enable IRQs unconditionally in put_pi_state()
2020-11-18 19:20:30 +01:00
gen_kheaders.sh
kbuild: add variables for compression tools
2020-09-03 11:27:10 +02:00
groups.c
hung_task.c
iomem.c
irq_work.c
jump_label.c
kallsyms.c
kallsyms: Refactor kallsyms_show_value() to take cred
2020-07-16 08:16:44 +02:00
kcmp.c
kernel/kcmp.c: Use new infrastructure to fix deadlocks in execve
2020-10-01 13:17:48 +02:00
Kconfig.freezer
Kconfig.hz
Kconfig.locks
Kconfig.preempt
kcov.c
kexec.c
kexec_core.c
kexec: bail out upon SIGKILL when allocating memory.
2019-09-25 17:51:40 -07:00
kexec_elf.c
kexec_file.c
Merge branch 'next-lockdown' of git://git.kernel.org/pub/scm/linux/kernel/git/jmorris/linux-security
2019-09-28 08:14:15 -07:00
kexec_internal.h
kheaders.c
kmod.c
kmod: make request_module() return an error when autoloading is disabled
2020-04-17 10:50:22 +02:00
kprobes.c
kprobes: Fix compiler warning for !CONFIG_KPROBES_ON_FTRACE
2020-10-01 13:18:25 +02:00
ksysfs.c
kthread.c
kthread_worker: prevent queuing delayed work from timer_fn when it is being canceled
2020-11-10 12:37:27 +01:00
latencytop.c
Makefile
kernel/sysctl-test: Add null pointer test for sysctl.c:proc_dointvec()
2020-10-01 13:17:10 +02:00
module-internal.h
module.c
module: statically initialize init section freeing data
2020-10-29 09:57:55 +01:00
module_signature.c
module_signing.c
notifier.c
kernel/notifier.c: intercept duplicate registrations to avoid infinite loops
2020-10-01 13:17:23 +02:00
nsproxy.c
padata.c
padata: add separate cpuhp node for CPUHP_PADATA_DEAD
2020-06-17 16:40:22 +02:00
panic.c
panic: ensure preemption is disabled during panic()
2019-10-07 15:47:19 -07:00
params.c
pid.c
pid_namespace.c
profile.c
ptrace.c
ptrace: reintroduce usage of subjective credentials in ptrace_has_cap()
2020-01-23 08:22:36 +01:00
range.c
reboot.c
reboot: fix overflow parsing reboot cpu number
2020-11-18 19:20:30 +01:00
relay.c
kernel/relay.c: fix memleak on destroy relay channel
2020-08-26 10:40:51 +02:00
resource.c
/dev/mem: Revoke mappings when a driver claims the region
2020-06-24 17:50:35 +02:00
rseq.c
seccomp.c
seccomp: Make duplicate listener detection non-racy
2020-11-05 11:43:23 +01:00
signal.c
ptrace: fix task_join_group_stop() for the case when current is traced
2020-11-10 12:37:24 +01:00
smp.c
smpboot.c
smpboot.h
softirq.c
stackleak.c
stacktrace.c
stacktrace: Don't skip first entry on noncurrent tasks
2019-11-04 21:19:25 +01:00
stop_machine.c
stop_machine: Avoid potential race behaviour
2019-10-17 12:47:12 +02:00
sys.c
kernel/sys.c: avoid copying possible padding bytes in copy_to_user
2020-10-01 13:17:23 +02:00
sys_ni.c
sysctl-test.c
kernel/sysctl-test: Add null pointer test for sysctl.c:proc_dointvec()
2020-10-01 13:17:10 +02:00
sysctl.c
kernel: sysctl: make drop_caches write-only
2020-01-04 19:18:32 +01:00
sysctl_binary.c
task_work.c
taskstats.c
taskstats: fix data-race
2020-01-09 10:19:54 +01:00
test_kprobes.c
torture.c
tracepoint.c
tsacct.c
ucount.c
uid16.c
uid16.h
umh.c
usermodehelper: reset umask to default before executing user process
2020-10-14 10:32:58 +02:00
up.c
user-return-notifier.c
user.c
user_namespace.c
utsname.c
utsname_sysctl.c
watchdog.c
watchdog/softlockup: Enforce that timestamp is valid on boot
2020-02-24 08:36:52 +01:00
watchdog_hld.c
workqueue.c
workqueue: Remove the warning in wq_worker_sleeping()
2020-10-01 13:17:54 +02:00
workqueue_internal.h