Waiman Long
6f08452c56
copy_process(): Move fd_install() out of sighand->siglock critical section
commit ddc204b517e60ae64db34f9832dc41dafa77c751 upstream.
I was made aware of the following lockdep splat:
[ 2516.308763] =====================================================
[ 2516.309085] WARNING: HARDIRQ-safe -> HARDIRQ-unsafe lock order detected
[ 2516.309433] 5.14.0-51.el9.aarch64+debug #1 Not tainted
[ 2516.309703] -----------------------------------------------------
[ 2516.310149] stress-ng/153663 [HC0[0]:SC0[0]:HE0:SE1] is trying to acquire:
[ 2516.310512] ffff0000e422b198 (&newf->file_lock){+.+.}-{2:2}, at: fd_install+0x368/0x4f0
[ 2516.310944]
and this task is already holding:
[ 2516.311248] ffff0000c08140d8 (&sighand->siglock){-.-.}-{2:2}, at: copy_process+0x1e2c/0x3e80
[ 2516.311804] which would create a new lock dependency:
[ 2516.312066] (&sighand->siglock){-.-.}-{2:2} -> (&newf->file_lock){+.+.}-{2:2}
[ 2516.312446]
but this new dependency connects a HARDIRQ-irq-safe lock:
[ 2516.312983] (&sighand->siglock){-.-.}-{2:2}
:
[ 2516.330700] Possible interrupt unsafe locking scenario:
[ 2516.331075] CPU0 CPU1
[ 2516.331328] ---- ----
[ 2516.331580] lock(&newf->file_lock);
[ 2516.331790] local_irq_disable();
[ 2516.332231] lock(&sighand->siglock);
[ 2516.332579] lock(&newf->file_lock);
[ 2516.332922] <Interrupt>
[ 2516.333069] lock(&sighand->siglock);
[ 2516.333291]
*** DEADLOCK ***
[ 2516.389845]
stack backtrace:
[ 2516.390101] CPU: 3 PID: 153663 Comm: stress-ng Kdump: loaded Not tainted 5.14.0-51.el9.aarch64+debug #1
[ 2516.390756] Hardware name: QEMU KVM Virtual Machine, BIOS 0.0.0 02/06/2015
[ 2516.391155] Call trace:
[ 2516.391302] dump_backtrace+0x0/0x3e0
[ 2516.391518] show_stack+0x24/0x30
[ 2516.391717] dump_stack_lvl+0x9c/0xd8
[ 2516.391938] dump_stack+0x1c/0x38
[ 2516.392247] print_bad_irq_dependency+0x620/0x710
[ 2516.392525] check_irq_usage+0x4fc/0x86c
[ 2516.392756] check_prev_add+0x180/0x1d90
[ 2516.392988] validate_chain+0x8e0/0xee0
[ 2516.393215] __lock_acquire+0x97c/0x1e40
[ 2516.393449] lock_acquire.part.0+0x240/0x570
[ 2516.393814] lock_acquire+0x90/0xb4
[ 2516.394021] _raw_spin_lock+0xe8/0x154
[ 2516.394244] fd_install+0x368/0x4f0
[ 2516.394451] copy_process+0x1f5c/0x3e80
[ 2516.394678] kernel_clone+0x134/0x660
[ 2516.394895] __do_sys_clone3+0x130/0x1f4
[ 2516.395128] __arm64_sys_clone3+0x5c/0x7c
[ 2516.395478] invoke_syscall.constprop.0+0x78/0x1f0
[ 2516.395762] el0_svc_common.constprop.0+0x22c/0x2c4
[ 2516.396050] do_el0_svc+0xb0/0x10c
[ 2516.396252] el0_svc+0x24/0x34
[ 2516.396436] el0t_64_sync_handler+0xa4/0x12c
[ 2516.396688] el0t_64_sync+0x198/0x19c
[ 2517.491197] NET: Registered PF_ATMPVC protocol family
[ 2517.491524] NET: Registered PF_ATMSVC protocol family
[ 2591.991877] sched: RT throttling activated
One way to solve this problem is to move the fd_install() call out of
the sighand->siglock critical section.
Before commit 6fd2fe494b ("copy_process(): don't use ksys_close()
on cleanups"), the pidfd installation was done without holding both
the task_list lock and the sighand->siglock. Obviously, holding these
two locks are not really needed to protect the fd_install() call.
So move the fd_install() call down to after the releases of both locks.
Link: https://lore.kernel.org/r/20220208163912.1084752-1-longman@redhat.com
Fixes: 6fd2fe494b ("copy_process(): don't use ksys_close() on cleanups")
Reviewed-by: "Eric W. Biederman" <ebiederm@xmission.com>
Signed-off-by: Waiman Long <longman@redhat.com>
Signed-off-by: Christian Brauner <brauner@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
|
2022-02-23 12:00:00 +01:00 |
| .. |
|
bpf
|
bpf: Add kconfig knob for disabling unpriv bpf by default
|
2022-02-16 12:52:49 +01:00 |
|
cgroup
|
cgroup/cpuset: Fix "suspicious RCU usage" lockdep warning
|
2022-02-08 18:24:35 +01:00 |
|
configs
|
|
|
|
debug
|
kdb: Make memory allocations more robust
|
2021-03-04 10:26:10 +01:00 |
|
dma
|
dma-debug: fix sg checks in debug_dma_map_sg()
|
2021-10-27 09:54:25 +02:00 |
|
events
|
perf: Fix list corruption in perf_cgroup_switch()
|
2022-02-16 12:52:53 +01:00 |
|
gcov
|
gcov: re-fix clang-11+ support
|
2021-04-14 08:24:10 +02:00 |
|
irq
|
genirq/timings: Fix error return code in irq_timings_test_irqs()
|
2021-09-15 09:47:29 +02:00 |
|
livepatch
|
|
|
|
locking
|
locking/lockdep: Avoid RCU-induced noinstr fail
|
2021-11-17 09:48:28 +01:00 |
|
power
|
PM: s2idle: ACPI: Fix wakeup interrupts handling
|
2022-02-16 12:52:50 +01:00 |
|
printk
|
printk/console: Allow to disable console output by using console="" or console=null
|
2021-11-12 14:43:03 +01:00 |
|
rcu
|
rcu: Tighten rcu_advance_cbs_nowake() checks
|
2022-01-29 10:25:09 +01:00 |
|
sched
|
psi: Fix uaf issue when psi trigger is destroyed while being polled
|
2022-02-05 12:35:36 +01:00 |
|
time
|
timekeeping: Really make sure wall_to_monotonic isn't positive
|
2021-12-22 09:29:39 +01:00 |
|
trace
|
ftrace: add ftrace_init_nop()
|
2022-02-23 11:59:56 +01:00 |
|
.gitignore
|
kbuild: update config_data.gz only when the content of .config is changed
|
2021-05-11 14:04:16 +02:00 |
|
acct.c
|
|
|
|
async.c
|
Revert "module, async: async_synchronize_full() on module init iff async is used"
|
2022-02-23 11:59:56 +01:00 |
|
audit.c
|
audit: improve audit queue handling when "audit=1" on cmdline
|
2022-02-08 18:24:26 +01:00 |
|
audit.h
|
audit: fix a net reference leak in audit_list_rules_send()
|
2020-06-22 09:30:59 +02:00 |
|
audit_fsnotify.c
|
|
|
|
audit_tree.c
|
audit: move put_tree() to avoid trim_trees refcount underflow and UAF
|
2021-09-03 10:08:16 +02:00 |
|
audit_watch.c
|
audit: CONFIG_CHANGE don't log internal bookkeeping as an event
|
2020-10-01 13:17:32 +02:00 |
|
auditfilter.c
|
audit: fix a net reference leak in audit_list_rules_send()
|
2020-06-22 09:30:59 +02:00 |
|
auditsc.c
|
audit: fix possible null-pointer dereference in audit_filter_rules
|
2021-10-27 09:54:27 +02:00 |
|
backtracetest.c
|
|
|
|
bounds.c
|
|
|
|
capability.c
|
|
|
|
compat.c
|
|
|
|
configs.c
|
|
|
|
context_tracking.c
|
|
|
|
cpu.c
|
cpu/hotplug: Cure the cpusets trainwreck
|
2021-07-19 08:53:15 +02:00 |
|
cpu_pm.c
|
kernel/cpu_pm: Fix uninitted local in cpu_pm
|
2020-06-22 09:31:22 +02:00 |
|
crash_core.c
|
|
|
|
crash_dump.c
|
|
|
|
cred.c
|
keys: Fix request_key() cache
|
2020-01-17 19:48:42 +01:00 |
|
delayacct.c
|
|
|
|
dma.c
|
|
|
|
exec_domain.c
|
|
|
|
exit.c
|
don't dump the threads that had been already exiting when zapped.
|
2020-11-18 19:20:31 +01:00 |
|
extable.c
|
|
|
|
fail_function.c
|
fail_function: Remove a redundant mutex unlock
|
2020-11-24 13:29:18 +01:00 |
|
fork.c
|
copy_process(): Move fd_install() out of sighand->siglock critical section
|
2022-02-23 12:00:00 +01:00 |
|
freezer.c
|
|
|
|
futex.c
|
mm, futex: fix shared futex pgoff on shmem huge page
|
2021-06-30 08:47:55 -04:00 |
|
gen_kheaders.sh
|
kbuild: add variables for compression tools
|
2020-09-03 11:27:10 +02:00 |
|
groups.c
|
|
|
|
hung_task.c
|
|
|
|
iomem.c
|
|
|
|
irq_work.c
|
|
|
|
jump_label.c
|
|
|
|
kallsyms.c
|
kallsyms: Refactor kallsyms_show_value() to take cred
|
2020-07-16 08:16:44 +02:00 |
|
kcmp.c
|
exec: Transform exec_update_mutex into a rw_semaphore
|
2021-01-09 13:44:55 +01:00 |
|
Kconfig.freezer
|
|
|
|
Kconfig.hz
|
|
|
|
Kconfig.locks
|
|
|
|
Kconfig.preempt
|
|
|
|
kcov.c
|
|
|
|
kexec.c
|
|
|
|
kexec_core.c
|
kernel: kexec: remove the lock operation of system_transition_mutex
|
2021-02-03 23:25:56 +01:00 |
|
kexec_elf.c
|
|
|
|
kexec_file.c
|
kernel: kexec_file: fix error return code of kexec_calculate_store_digests()
|
2021-05-19 10:08:28 +02:00 |
|
kexec_internal.h
|
|
|
|
kheaders.c
|
|
|
|
kmod.c
|
kmod: make request_module() return an error when autoloading is disabled
|
2020-04-17 10:50:22 +02:00 |
|
kprobes.c
|
kprobes: Limit max data_size of the kretprobe instances
|
2021-12-08 09:01:10 +01:00 |
|
ksysfs.c
|
|
|
|
kthread.c
|
kthread: Fix PF_KTHREAD vs to_kthread() race
|
2021-09-12 08:56:39 +02:00 |
|
latencytop.c
|
|
|
|
Makefile
|
kbuild: update config_data.gz only when the content of .config is changed
|
2021-05-11 14:04:16 +02:00 |
|
module-internal.h
|
|
|
|
module.c
|
module/ftrace: handle patchable-function-entry
|
2022-02-23 11:59:56 +01:00 |
|
module_signature.c
|
module: harden ELF info handling
|
2021-04-07 14:47:38 +02:00 |
|
module_signing.c
|
module: harden ELF info handling
|
2021-04-07 14:47:38 +02:00 |
|
notifier.c
|
kernel/notifier.c: intercept duplicate registrations to avoid infinite loops
|
2020-10-01 13:17:23 +02:00 |
|
nsproxy.c
|
|
|
|
padata.c
|
padata: add separate cpuhp node for CPUHP_PADATA_DEAD
|
2020-06-17 16:40:22 +02:00 |
|
panic.c
|
|
|
|
params.c
|
|
|
|
pid.c
|
|
|
|
pid_namespace.c
|
memcg: enable accounting for pids in nested pid namespaces
|
2021-09-22 12:26:37 +02:00 |
|
profile.c
|
profiling: fix shift-out-of-bounds bugs
|
2021-09-26 14:07:09 +02:00 |
|
ptrace.c
|
ptrace: make ptrace() fail if the tracee changed its pid unexpectedly
|
2021-05-26 12:05:15 +02:00 |
|
range.c
|
|
|
|
reboot.c
|
reboot: fix overflow parsing reboot cpu number
|
2020-11-18 19:20:30 +01:00 |
|
relay.c
|
kernel/relay.c: fix memleak on destroy relay channel
|
2020-08-26 10:40:51 +02:00 |
|
resource.c
|
/dev/mem: Revoke mappings when a driver claims the region
|
2020-06-24 17:50:35 +02:00 |
|
rseq.c
|
|
|
|
seccomp.c
|
seccomp: Invalidate seccomp mode to catch death failures
|
2022-02-16 12:52:53 +01:00 |
|
signal.c
|
signal: Remove the bogus sigkill_pending in ptrace_stop
|
2021-11-17 09:48:24 +01:00 |
|
smp.c
|
smp: Fix smp_call_function_single_async prototype
|
2021-05-14 09:44:33 +02:00 |
|
smpboot.c
|
kthread: Extract KTHREAD_IS_PER_CPU
|
2021-02-07 15:35:49 +01:00 |
|
smpboot.h
|
|
|
|
softirq.c
|
|
|
|
stackleak.c
|
|
|
|
stacktrace.c
|
stacktrace: Don't skip first entry on noncurrent tasks
|
2019-11-04 21:19:25 +01:00 |
|
stop_machine.c
|
|
|
|
sys.c
|
prctl: allow to setup brk for et_dyn executables
|
2021-09-26 14:07:08 +02:00 |
|
sys_ni.c
|
|
|
|
sysctl-test.c
|
kernel/sysctl-test: Add null pointer test for sysctl.c:proc_dointvec()
|
2020-10-01 13:17:10 +02:00 |
|
sysctl.c
|
bpf: Add kconfig knob for disabling unpriv bpf by default
|
2022-02-16 12:52:49 +01:00 |
|
sysctl_binary.c
|
|
|
|
task_work.c
|
|
|
|
taskstats.c
|
taskstats: fix data-race
|
2020-01-09 10:19:54 +01:00 |
|
test_kprobes.c
|
|
|
|
torture.c
|
|
|
|
tracepoint.c
|
tracepoint: Add tracepoint_probe_register_may_exist() for BPF tracing
|
2021-07-14 16:53:08 +02:00 |
|
tsacct.c
|
taskstats: Cleanup the use of task->exit_code
|
2022-02-23 11:59:57 +01:00 |
|
ucount.c
|
|
|
|
uid16.c
|
|
|
|
uid16.h
|
|
|
|
umh.c
|
usermodehelper: reset umask to default before executing user process
|
2020-10-14 10:32:58 +02:00 |
|
up.c
|
smp: Fix smp_call_function_single_async prototype
|
2021-05-14 09:44:33 +02:00 |
|
user-return-notifier.c
|
|
|
|
user.c
|
|
|
|
user_namespace.c
|
|
|
|
utsname.c
|
|
|
|
utsname_sysctl.c
|
|
|
|
watchdog.c
|
watchdog/softlockup: Enforce that timestamp is valid on boot
|
2020-02-24 08:36:52 +01:00 |
|
watchdog_hld.c
|
|
|
|
workqueue.c
|
workqueue: Fix unbind_workers() VS wq_worker_running() race
|
2022-01-16 09:15:38 +01:00 |
|
workqueue_internal.h
|
|
|