mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* [PATCH] mqueue: sys_mq_open: do not call mnt_drop_write() if read-only
@ 2013-03-19  9:31 Vladimir Davydov
  2013-03-19 21:09 ` Andrew Morton
  0 siblings, 1 reply; 3+ messages in thread
From: Vladimir Davydov @ 2013-03-19  9:31 UTC (permalink / raw)
  To: Al Viro
  Cc: linux-kernel, devel, Doug Ledford, Andrew Morton,
	KOSAKI Motohiro, Eric W. Biederman

mnt_drop_write() must be called only if mnt_want_write() succeeded,
otherwise the mnt_writers counter will diverge.

Signed-off-by: Vladimir Davydov <vdavydov@parallels.com>
Cc: Doug Ledford <dledford@redhat.com>
Cc: Andrew Morton <akpm@linux-foundation.org>
Cc: KOSAKI Motohiro <kosaki.motohiro@jp.fujitsu.com>
Cc: "Eric W. Biederman" <ebiederm@xmission.com>
---
 ipc/mqueue.c |    3 ++-
 1 files changed, 2 insertions(+), 1 deletions(-)

diff --git a/ipc/mqueue.c b/ipc/mqueue.c
index e5c4f60..3953fda 100644
--- a/ipc/mqueue.c
+++ b/ipc/mqueue.c
@@ -840,7 +840,8 @@ out_putfd:
 		fd = error;
 	}
 	mutex_unlock(&root->d_inode->i_mutex);
-	mnt_drop_write(mnt);
+	if (!ro)
+		mnt_drop_write(mnt);
 out_putname:
 	putname(name);
 	return fd;
-- 
1.7.1


^ permalink raw reply	[flat|nested] 3+ messages in thread

* Re: [PATCH] mqueue: sys_mq_open: do not call mnt_drop_write() if read-only
  2013-03-19  9:31 [PATCH] mqueue: sys_mq_open: do not call mnt_drop_write() if read-only Vladimir Davydov
@ 2013-03-19 21:09 ` Andrew Morton
  2013-03-19 22:04   ` Vladimir Davydov
  0 siblings, 1 reply; 3+ messages in thread
From: Andrew Morton @ 2013-03-19 21:09 UTC (permalink / raw)
  To: Vladimir Davydov
  Cc: Al Viro, linux-kernel, devel, Doug Ledford, KOSAKI Motohiro,
	Eric W. Biederman

On Tue, 19 Mar 2013 13:31:18 +0400 Vladimir Davydov <vdavydov@parallels.com> wrote:

> mnt_drop_write() must be called only if mnt_want_write() succeeded,
> otherwise the mnt_writers counter will diverge.
> 
> ...
>
> --- a/ipc/mqueue.c
> +++ b/ipc/mqueue.c
> @@ -840,7 +840,8 @@ out_putfd:
>  		fd = error;
>  	}
>  	mutex_unlock(&root->d_inode->i_mutex);
> -	mnt_drop_write(mnt);
> +	if (!ro)
> +		mnt_drop_write(mnt);
>  out_putname:
>  	putname(name);
>  	return fd;

huh, that's been there for a while.  What were the runtime-visible
effects of the bug?

^ permalink raw reply	[flat|nested] 3+ messages in thread

* Re: [PATCH] mqueue: sys_mq_open: do not call mnt_drop_write() if read-only
  2013-03-19 21:09 ` Andrew Morton
@ 2013-03-19 22:04   ` Vladimir Davydov
  0 siblings, 0 replies; 3+ messages in thread
From: Vladimir Davydov @ 2013-03-19 22:04 UTC (permalink / raw)
  To: Andrew Morton
  Cc: Al Viro, <linux-kernel@vger.kernel.org>,
	<devel@openvz.org>,
	Doug Ledford, KOSAKI Motohiro, Eric W. Biederman

On Mar 20, 2013, at 1:09 AM, Andrew Morton <akpm@linux-foundation.org>
 wrote:

> On Tue, 19 Mar 2013 13:31:18 +0400 Vladimir Davydov <vdavydov@parallels.com> wrote:
> 
>> mnt_drop_write() must be called only if mnt_want_write() succeeded,
>> otherwise the mnt_writers counter will diverge.
>> 
>> ...
>> 
>> --- a/ipc/mqueue.c
>> +++ b/ipc/mqueue.c
>> @@ -840,7 +840,8 @@ out_putfd:
>> 		fd = error;
>> 	}
>> 	mutex_unlock(&root->d_inode->i_mutex);
>> -	mnt_drop_write(mnt);
>> +	if (!ro)
>> +		mnt_drop_write(mnt);
>> out_putname:
>> 	putname(name);
>> 	return fd;
> 
> huh, that's been there for a while.  What were the runtime-visible
> effects of the bug?

mnt_writers counters are used to check if remounting FS as read-only is OK, so after an extra mnt_drop_write() call, it would be impossible to remount mqueue FS as read-only. Besides, on umount a warning would be printed like this one:

[  194.714880] =====================================
[  194.719680] [ BUG: bad unlock balance detected! ]
[  194.724488] 3.9.0-rc3 #5 Not tainted
[  194.728159] -------------------------------------
[  194.732958] a.out/12486 is trying to release lock (sb_writers) at:
[  194.739355] [<ffffffff811b177f>] mnt_drop_write+0x1f/0x30
[  194.744851] but there are no more locks to release!


^ permalink raw reply	[flat|nested] 3+ messages in thread

end of thread, other threads:[~2013-03-19 22:04 UTC | newest]

Thread overview: 3+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2013-03-19  9:31 [PATCH] mqueue: sys_mq_open: do not call mnt_drop_write() if read-only Vladimir Davydov
2013-03-19 21:09 ` Andrew Morton
2013-03-19 22:04   ` Vladimir Davydov

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

Powered by JetHome