Thomas Gleixner
22d7ec50ff
debugobject: Prevent init race with static objects
...
[ Upstream commit 63a759694eed61025713b3e14dd827c8548daadc ]
Statically initialized objects are usually not initialized via the init()
function of the subsystem. They are special cased and the subsystem
provides a function to validate whether an object which is not yet tracked
by debugobjects is statically initialized. This means the object is started
to be tracked on first use, e.g. activation.
This works perfectly fine, unless there are two concurrent operations on
that object. Schspa decoded the problem:
T0 T1
debug_object_assert_init(addr)
lock_hash_bucket()
obj = lookup_object(addr);
if (!obj) {
unlock_hash_bucket();
- > preemption
lock_subsytem_object(addr);
activate_object(addr)
lock_hash_bucket();
obj = lookup_object(addr);
if (!obj) {
unlock_hash_bucket();
if (is_static_object(addr))
init_and_track(addr);
lock_hash_bucket();
obj = lookup_object(addr);
obj->state = ACTIVATED;
unlock_hash_bucket();
subsys function modifies content of addr,
so static object detection does
not longer work.
unlock_subsytem_object(addr);
if (is_static_object(addr)) <- Fails
debugobject emits a warning and invokes the fixup function which
reinitializes the already active object in the worst case.
This race exists forever, but was never observed until mod_timer() got a
debug_object_assert_init() added which is outside of the timer base lock
held section right at the beginning of the function to cover the lockless
early exit points too.
Rework the code so that the lookup, the static object check and the
tracking object association happens atomically under the hash bucket
lock. This prevents the issue completely as all callers are serialized on
the hash bucket lock and therefore cannot observe inconsistent state.
Fixes: 3ac7fe5a4a ("infrastructure to debug (dynamic) objects")
Reported-by: syzbot+5093ba19745994288b53@syzkaller.appspotmail.com
Debugged-by: Schspa Shi <schspa@gmail.com>
Signed-off-by: Thomas Gleixner <tglx@linutronix.de>
Reviewed-by: Stephen Boyd <swboyd@chromium.org>
Link: https://syzkaller.appspot.com/bug?id=22c8a5938eab640d1c6bcc0e3dc7be519d878462
Link: https://lore.kernel.org/lkml/20230303161906.831686-1-schspa@gmail.com
Link: https://lore.kernel.org/r/87zg7dzgao.ffs@tglx
Signed-off-by: Sasha Levin <sashal@kernel.org>
2023-05-17 11:35:39 +02:00
..
842
crypto
lib/crypto: blake2s: move hmac construction into wireguard
2022-06-22 14:11:02 +02:00
dim
dim: initialize all struct fields
2022-05-18 09:47:25 +02:00
fonts
lib/fonts: fix undefined behavior in bit shift for get_default_font
2023-01-18 11:40:54 +01:00
livepatch
lz4
lz4: fix LZ4_decompress_safe_partial read out of bound
2022-04-15 14:18:39 +02:00
lzo
lib/lzo: fix ambiguous encoding bug in lzo-rle
2020-06-17 16:40:28 +02:00
math
mpi
lib/mpi: Fix buffer overrun when SG is too long
2023-03-11 16:43:38 +01:00
raid6
lib/raid6/test/Makefile: Use $(pound) instead of \# for Make 4.3
2022-04-15 14:18:23 +02:00
reed_solomon
vdso
lib/vdso: use "grep -E" instead of "egrep"
2022-12-08 11:22:59 +01:00
xz
lib/xz: Validate the value before assigning it to an enum variable
2021-11-17 09:48:31 +01:00
zlib_deflate
zlib_inflate
lib/zlib: remove outdated and incorrect pre-increment optimization
2020-06-24 17:50:39 +02:00
zstd
.gitignore
argv_split.c
ashldi3.c
ashrdi3.c
asn1_decoder.c
assoc_array.c
assoc_array: Fix BUG_ON during garbage collect
2022-06-06 08:33:50 +02:00
atomic64.c
atomic64_test.c
audit.c
bcd.c
bch.c
bitmap.c
bitrev.c
bsearch.c
btree.c
bucket_locks.c
bug.c
bug: Remove redundant condition check in report_bug
2021-05-14 09:44:27 +02:00
build_OID_registry
bust_spinlocks.c
chacha.c
check_signature.c
checksum.c
clz_ctz.c
clz_tab.c
cmdline.c
cmpdi2.c
compat_audit.c
cpu_rmap.c
cpumask.c
crc-ccitt.c
crc-itu-t.c
crc-t10dif.c
crc-t10dif: Fix potential crypto notify dead-lock
2020-08-19 08:15:54 +02:00
crc4.c
crc7.c
crc8.c
crc16.c
crc32.c
lib/crc32.c: fix trivial typo in preprocessor condition
2020-10-29 09:57:52 +01:00
crc32defs.h
crc32test.c
lib/crc32test: remove extra local_irq_disable/enable
2020-11-10 12:37:27 +01:00
crc64.c
ctype.c
debug_info.c
debug_locks.c
debugobjects.c
debugobject: Prevent init race with static objects
2023-05-17 11:35:39 +02:00
dec_and_lock.c
decompress.c
decompress_bunzip2.c
decompress_inflate.c
decompress_unlz4.c
lib/decompress_unlz4.c: correctly handle zero-padding around initrds.
2021-07-20 16:10:46 +02:00
decompress_unlzma.c
decompress_unlzo.c
decompress_unxz.c
lib/xz: Avoid overlapping memcpy() with invalid input with in-place decompression
2021-11-17 09:48:31 +01:00
devres.c
devres: keep both device name and resource name in pretty name
2020-08-21 13:05:32 +02:00
digsig.c
dump_stack.c
dump_stack: avoid the livelock of the dump_lock
2019-11-06 08:47:50 -08:00
dynamic_debug.c
dyndbg: let query-modname override actual module name
2022-10-26 13:22:37 +02:00
dynamic_queue_limits.c
earlycpio.c
error-inject.c
errseq.c
extable.c
lib/extable.c: add missing prototypes
2019-09-25 17:51:39 -07:00
fault-inject.c
fdt.c
fdt_empty_tree.c
fdt_ro.c
fdt_rw.c
fdt_strerror.c
fdt_sw.c
fdt_wip.c
find_bit.c
uapi: rename ext2_swab() to swab() and share globally in swab.h
2020-04-13 10:48:07 +02:00
find_bit_benchmark.c
flex_proportions.c
gen_crc32table.c
gen_crc64table.c
genalloc.c
lib/genalloc: fix the overflow when size is too big
2021-01-12 20:16:10 +01:00
generic-radix-tree.c
lib/generic-radix-tree.c: add kmemleak annotations
2019-10-14 15:04:00 -07:00
glob.c
globtest.c
hexdump.c
hex2bin: fix access beyond string end
2022-05-09 09:03:22 +02:00
hweight.c
idr.c
ida: don't use BUG_ON() for debugging
2022-07-12 16:30:49 +02:00
inflate.c
interval_tree.c
interval_tree_test.c
iomap.c
iomap_copy.c
iommu-helper.c
ioremap.c
iov_iter.c
mm/highmem: Lift memcpy_[to|from]_page to core
2023-01-18 11:41:55 +01:00
irq_poll.c
irq_regs.c
is_single_threaded.c
kasprintf.c
Kconfig
ARM: 9178/1: fix unmet dependency on BITREVERSE for HAVE_ARCH_BITREVERSE
2022-03-19 13:40:16 +01:00
Kconfig.debug
Kconfig.debug: provide a little extra FRAME_WARN leeway when KASAN is enabled
2022-12-08 11:23:05 +01:00
Kconfig.kasan
kasan: add memory corruption identification for software tag-based mode
2019-09-24 15:54:07 -07:00
Kconfig.kgdb
Kconfig.ubsan
kfifo.c
klist.c
kobject.c
kobject: Restore old behaviour of kobject_del(NULL)
2020-09-17 13:47:52 +02:00
kobject_uevent.c
kobject_uevent: remove warning in init_uevent_argv()
2021-05-19 10:08:33 +02:00
kstrtox.c
lib: vsprintf: Fix handling of number field widths in vsscanf
2021-07-14 16:53:16 +02:00
kstrtox.h
lib: vsprintf: Fix handling of number field widths in vsscanf
2021-07-14 16:53:16 +02:00
libcrc32c.c
list_debug.c
lib/list_debug.c: Detect uninitialized lists
2022-08-25 11:18:36 +02:00
list_sort.c
llist.c
locking-selftest-hardirq.h
locking-selftest-mutex.h
locking-selftest-rlock-hardirq.h
locking-selftest-rlock-softirq.h
locking-selftest-rlock.h
locking-selftest-rsem.h
locking-selftest-rtmutex.h
locking-selftest-softirq.h
locking-selftest-spin-hardirq.h
locking-selftest-spin-softirq.h
locking-selftest-spin.h
locking-selftest-wlock-hardirq.h
locking-selftest-wlock-softirq.h
locking-selftest-wlock.h
locking-selftest-wsem.h
locking-selftest.c
lockref.c
lockref: stop doing cpu_relax in the cmpxchg loop
2023-02-06 07:52:42 +01:00
logic_pio.c
PCI: Fix pci_register_io_range() memory leak
2021-03-17 17:03:44 +01:00
lru_cache.c
lshrdi3.c
Makefile
avoid __memcat_p link failure
2021-05-07 10:51:37 +02:00
memcat_p.c
memory-notifier-error-inject.c
memweight.c
muldi3.c
net_utils.c
netdev-notifier-error-inject.c
nlattr.c
netlink: prevent potential spectre v1 gadgets
2023-02-06 07:52:45 +01:00
nmi_backtrace.c
nodemask.c
nodemask: Fix return values to be unsigned
2022-06-14 18:12:02 +02:00
notifier-error-inject.c
lib/notifier-error-inject: fix error when writing -errno to debugfs file
2023-01-18 11:40:55 +01:00
notifier-error-inject.h
objagg.c
of-reconfig-notifier-error-inject.c
oid_registry.c
once.c
once: add DO_ONCE_SLOW() for sleepable contexts
2022-10-26 13:22:27 +02:00
packing.c
parman.c
parser.c
pci_iomap.c
percpu-refcount.c
percpu_counter.c
percpu_test.c
plist.c
pm-notifier-error-inject.c
radix-tree.c
idr: Fix idr_alloc_u32 on 32-bit systems
2019-11-03 06:36:50 -05:00
random32.c
random: replace custom notifier chain with standard one
2022-06-22 14:11:13 +02:00
ratelimit.c
ratelimit: Fix data-races in ___ratelimit().
2022-09-05 10:27:42 +02:00
rbtree.c
rbtree_test.c
augmented rbtree: add new RB_DECLARE_CALLBACKS_MAX macro
2019-09-25 17:51:39 -07:00
refcount.c
locking/refcount: Consolidate implementations of refcount_t
2022-07-29 17:14:17 +02:00
rhashtable.c
sbitmap.c
sbitmap: only queue kyber's wait callback if not already active
2020-01-12 12:21:44 +01:00
scatterlist.c
sgl_alloc_order: fix memory leak
2020-11-05 11:43:22 +01:00
seq_buf.c
seq_buf: Fix overflow in seq_buf_putmem_hex()
2021-07-19 08:53:16 +02:00
sg_pool.c
sg_split.c
sha1.c
lib/crypto: sha1: re-roll loops to reduce code size
2022-06-22 14:11:03 +02:00
show_mem.c
mm: remove quicklist page table caches
2019-09-24 15:54:09 -07:00
siphash.c
siphash: use one source of truth for siphash permutations
2022-06-22 14:11:16 +02:00
smp_processor_id.c
sort.c
stackdepot.c
lib: stackdepot: turn depot_lock spinlock to raw_spinlock
2021-05-22 11:38:30 +02:00
stmp_device.c
string.c
lib/string.c: implement stpcpy
2020-10-01 13:18:23 +02:00
string_helpers.c
strncpy_from_user.c
lib: Reduce user_access_begin() boundaries in strncpy_from_user() and strnlen_user()
2020-01-29 16:45:29 +01:00
strnlen_user.c
lib: Reduce user_access_begin() boundaries in strncpy_from_user() and strnlen_user()
2020-01-29 16:45:29 +01:00
syscall.c
lib/syscall: fix syscall registers retrieval on 32-bit platforms
2020-12-11 13:23:32 +01:00
test-kstrtox.c
test-string_helpers.c
test_bitfield.c
test_bitmap.c
test_blackhole_dev.c
test_bpf.c
bpf/tests: Do not PASS tests without actually testing the result
2021-09-22 12:26:29 +02:00
test_debug_virtual.c
test_firmware.c
test_firmware: fix memory leak in test_firmware_init()
2023-01-18 11:41:23 +01:00
test_hash.c
test_hexdump.c
test_ida.c
test_kasan.c
kasan: stop tests being eliminated as dead code with FORTIFY_SOURCE
2020-06-22 09:31:12 +02:00
test_kmod.c
lib/test: use after free in register_test_dev_kmod()
2022-04-15 14:18:21 +02:00
test_list_sort.c
test_memcat_p.c
test_meminit.c
lib/test_meminit: destroy cache in kmem_cache_alloc_bulk() test
2022-01-27 09:19:55 +01:00
test_module.c
test_objagg.c
test_objagg: Fix potential memory leak in error handling
2020-06-30 15:37:04 -04:00
test_overflow.c
test_parman.c
test_printf.c
vsprintf: don't obfuscate NULL and error pointers
2020-05-27 17:46:43 +02:00
test_rhashtable.c
test_siphash.c
test_sort.c
test_stackinit.c
lib/test_stackinit: Fix static initializer test
2021-09-22 12:26:38 +02:00
test_static_key_base.c
test_static_keys.c
test_string.c
test_strscpy.c
test_sysctl.c
test_ubsan.c
test_user_copy.c
usercopy: Avoid soft lockups in test_check_nonzero_user()
2019-10-16 14:56:21 +02:00
test_uuid.c
test_vmalloc.c
test_xarray.c
XArray: Fix xas_create_range() when multi-order entry present
2022-04-15 14:18:28 +02:00
textsearch.c
lib: textsearch: fix escapes in example code
2019-10-03 12:12:23 -04:00
timerqueue.c
ts_bm.c
ts_fsm.c
ts_kmp.c
ubsan.c
lib/ubsan: don't serialize UBSAN report
2020-01-09 10:20:07 +01:00
ubsan.h
ucmpdi2.c
ucs2_string.c
usercopy.c
uaccess: Add speculation barrier to copy_from_user()
2023-02-25 11:53:26 +01:00
uuid.c
vsprintf.c
random: replace custom notifier chain with standard one
2022-06-22 14:11:13 +02:00
win_minmax.c
xarray.c
XArray: Update the LRU list in xas_split()
2022-04-15 14:18:28 +02:00
xxhash.c