mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* debugfs_remove() vs. anything that is dynamic
@ 2008-04-03 23:56 Johannes Berg
  2008-04-04 15:34 ` Greg KH
  0 siblings, 1 reply; 6+ messages in thread
From: Johannes Berg @ 2008-04-03 23:56 UTC (permalink / raw)
  To: Linux Kernel list; +Cc: Greg KH

[-- Attachment #1: Type: text/plain, Size: 1254 bytes --]

Consider the following trivial module:

--- %< ---
#include <linux/module.h>
#include <linux/debugfs.h>

static struct dentry *f;
static u32 tmp;

int __init mod_enter(void)
{
	f = debugfs_create_u32("tmp-test", 0666, NULL, &tmp);

	return 0;
}

void __exit mod_leave(void)
{
	debugfs_remove(f);
}

module_init(mod_enter);
module_exit(mod_leave);
MODULE_LICENSE("GPL");
--- >% ---

How do I make that safe?


FWIW, the problem is:

thread 1			thread 2
 fd = open("tmp-test")

 sleep(30);			rmmod test-module

 read(fd, buf, 100);

--> accesses now invalid memory because debugfs doesn't actually stop
you from accessing "&tmp" after debugfs_remove(). [yes, I actually
tested a variation of this where I dynamically allocated the 'tmp'
variable, I got the slab poison in my test program]


Personally, I tend to think this makes debugfs rather unusable in
modules and with anything that is dynamically allocated [1]. AFAICT
sysfs avoids this by having object lifetime imposed by sysfs, but
debugfs doesn't work that way.

What am I missing?

johannes

[1] which covers many many current users, it seems at least usbmon,
ohci/ehci/uhci-dbg, pktcdvd, fault injection code, blktrace and probably
more.

[-- Attachment #2: This is a digitally signed message part --]
[-- Type: application/pgp-signature, Size: 828 bytes --]

^ permalink raw reply	[flat|nested] 6+ messages in thread

end of thread, other threads:[~2008-04-04 21:20 UTC | newest]

Thread overview: 6+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2008-04-03 23:56 debugfs_remove() vs. anything that is dynamic Johannes Berg
2008-04-04 15:34 ` Greg KH
2008-04-04 15:41   ` Johannes Berg
2008-04-04 20:20     ` Greg KH
2008-04-04 20:57       ` Johannes Berg
2008-04-04 21:20         ` Johannes Berg

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®