From: Eric Paris <eparis@redhat.com>
To: Linus Torvalds <torvalds@linux-foundation.org>
Cc: Christoph Thielecke <christoph.thielecke@gmx.de>,
Andrew Morton <akpm@linux-foundation.org>,
Al Viro <viro@ZenIV.linux.org.uk>,
Linux Kernel Mailing List <linux-kernel@vger.kernel.org>,
"Rafael J. Wysocki" <rjw@sisk.pl>
Subject: Re: kernel bugs 2.6.31-rc6
Date: Sat, 15 Aug 2009 19:19:05 -0400 [thread overview]
Message-ID: <1250378345.14501.92.camel@dhcp231-106.rdu.redhat.com> (raw)
In-Reply-To: <alpine.LFD.2.01.0908151036290.3162@localhost.localdomain>
On Sat, 2009-08-15 at 10:52 -0700, Linus Torvalds wrote:
>
> On Sat, 15 Aug 2009, Linus Torvalds wrote:
> >
> > For example, fsnotify_remove_priv_from_event() will remove the private
> > data event from the list, but what if there are _multiple_ entries with
> > the same 'group' entry? If so, it will remove just the first one.
I can happen, but ONLY for the staticly declared q_overflow_event in
notification.c. If the refcnt on that ever hits 0 to trigger this bug
we are in some serious dodo.
> Hmm. Looking closer, that shouldn't much matter. Each time we added an
> entry in private_data_list, we would have done a
> 'fsnotify_get_event(event)' due to adding it to the 'golder->event_list'.
>
> That said, there does seem to be some dubious code there. For example,
> in 'inotify_ignored_and_remove_idr()', we do this:
>
> fsnotify_add_notify_event(group, ignored_event, fsn_event_priv);
>
> /* did the private data get added? */
> if (list_empty(&fsn_event_priv->event_list))
> inotify_free_event_priv(fsn_event_priv);
> and we do it without holding any locks at all. So as far as I can tell,
> what could happen is that 'fsnotify_add_notify_event()' actually adds the
> private event (fsn_event_priv), but then before we check that the
> event_list is empty, another user (on another CPU, or preempted on the
> same CPU - Christoph has both PREEMPT and SMP on) comes along, picks up
> the private event and frees it (and re-uses it).
Actually you look correct in your assessment that there is a race here.
I guess I could imagine a way to make it panic like this, but I would
have expected a different problem in that after I freed this memory
(which wasn't mine any more) the other task which owned this memory
would have to still be able to run list_for_each_entry, but find that
it's group was no longer there. Not sure how could screw up the group,
but not the list entries.
I'll fix this race tonight or in the morning.
I'm downloading and installing KDE, as I guess kde uses inotify pretty
hard since both Mikko and Christoph were using kde.
-Eric
next prev parent reply other threads:[~2009-08-15 23:19 UTC|newest]
Thread overview: 5+ messages / expand[flat|nested] mbox.gz Atom feed top
[not found] <200908151014.22910.christoph.thielecke@gmx.de>
2009-08-15 17:29 ` Linus Torvalds
2009-08-15 17:52 ` Linus Torvalds
2009-08-15 23:19 ` Eric Paris [this message]
2009-08-24 9:06 ` Zdenek Kabelac
2009-08-24 13:29 ` Eric Paris
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=1250378345.14501.92.camel@dhcp231-106.rdu.redhat.com \
--to=eparis@redhat.com \
--cc=akpm@linux-foundation.org \
--cc=christoph.thielecke@gmx.de \
--cc=linux-kernel@vger.kernel.org \
--cc=rjw@sisk.pl \
--cc=torvalds@linux-foundation.org \
--cc=viro@ZenIV.linux.org.uk \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®