mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* aic7(censored) use after free in 2.5.66
@ 2003-04-01  6:48 Zwane Mwaikambo
  2003-04-01  7:00 ` Zwane Mwaikambo
  0 siblings, 1 reply; 7+ messages in thread
From: Zwane Mwaikambo @ 2003-04-01  6:48 UTC (permalink / raw)
  To: Linux Kernel; +Cc: gibbs

I got this on boot on an 8way/16G box, perhaps Justin should try 
and push his latest? CONFIG_PREEMPT=y if that makes any difference at 
all.. If anyone is interested i can provide more info.

scsi0 : Adaptec AIC7XXX EISA/VLB/PCI SCSI HBA DRIVER, Rev 6.2.28

Slab corruption: start=f7d66248, expend=f7d662c7, problemat=f7d662ac
Last user: [<c024f0b7>](ahc_linux_free_device+0x27/0x60)
Data: 
****************************************************************************************************6C 
**************************A5 
Next: 71 F0 2C .B7 F0 24 C0 A5 C2 0F 17 00 A0 E8 EB 00 80 85 EC C2 03 00 00 C2 03 00 00 00 00 00 A0 
slab error in check_poison_obj(): cache `size-128': object was modified 
after freeing
Call Trace:
 [<c01436c9>] check_poison_obj+0x179/0x190
 [<c0144f5d>] kmalloc+0xdd/0x190
 [<c01dd4fa>] con_insert_unipair+0x8a/0xe0
 [<c0144f5d>] kmalloc+0xdd/0x190
 [<c01dd5a4>] con_clear_unimap+0x54/0xc0
 [<c0143583>] check_poison_obj+0x33/0x190
 [<c01dd4fa>] con_insert_unipair+0x8a/0xe0
 [<c01dd926>] con_set_default_unimap+0xc6/0x140
 [<c01e0a35>] vc_allocate+0x95/0x130
 [<c01e4039>] con_open+0x19/0x90
 [<c01d2389>] tty_open+0x249/0x460
 [<c0143583>] check_poison_obj+0x33/0x190
 [<c0164e57>] get_chrfops+0x27/0xb0
 [<c015cf97>] get_empty_filp+0x47/0xe0
 [<c0165262>] chrdev_open+0x82/0x100
 [<c015b3e7>] dentry_open+0xc7/0x160
 [<c0144dde>] kmem_cache_alloc+0x9e/0x140
 [<c015b30d>] filp_open+0x4d/0x60
 [<c016933e>] getname+0x5e/0xa0
 [<c015b765>] sys_open+0x35/0x70
 [<c010aecf>] syscall_call+0x7/0xb


-- 
function.linuxpower.ca

^ permalink raw reply	[flat|nested] 7+ messages in thread

* Re: aic7(censored) use after free in 2.5.66
  2003-04-01  6:48 aic7(censored) use after free in 2.5.66 Zwane Mwaikambo
@ 2003-04-01  7:00 ` Zwane Mwaikambo
  2003-04-01  7:22   ` Andrew Morton
  0 siblings, 1 reply; 7+ messages in thread
From: Zwane Mwaikambo @ 2003-04-01  7:00 UTC (permalink / raw)
  To: Linux Kernel; +Cc: gibbs

On Tue, 1 Apr 2003, Zwane Mwaikambo wrote:

> I got this on boot on an 8way/16G box, perhaps Justin should try 
> and push his latest? CONFIG_PREEMPT=y if that makes any difference at 
> all.. If anyone is interested i can provide more info.
> 
> scsi0 : Adaptec AIC7XXX EISA/VLB/PCI SCSI HBA DRIVER, Rev 6.2.28
> 
> Slab corruption: start=f7d66248, expend=f7d662c7, problemat=f7d662ac
> Last user: [<c024f0b7>](ahc_linux_free_device+0x27/0x60)
> Data: 

This probably wants; Or if we can sleep in all the paths, a  
synchronize_kernel after del_timer should suffice.

Justin?

Index: linux-2.5.66/drivers/scsi/aic7xxx/aic7xxx_osm.c
===================================================================
RCS file: /build/cvsroot/linux-2.5.66/drivers/scsi/aic7xxx/aic7xxx_osm.c,v
retrieving revision 1.1.1.1
diff -u -p -B -r1.1.1.1 aic7xxx_osm.c
--- linux-2.5.66/drivers/scsi/aic7xxx/aic7xxx_osm.c	24 Mar 2003 23:39:44 -0000	1.1.1.1
+++ linux-2.5.66/drivers/scsi/aic7xxx/aic7xxx_osm.c	1 Apr 2003 06:54:01 -0000
@@ -4097,7 +4097,7 @@ ahc_linux_free_device(struct ahc_softc *
 {
 	struct ahc_linux_target *targ;
 
-	del_timer(&dev->timer);
+	del_timer_sync(&dev->timer);
 	targ = dev->target;
 	targ->devices[dev->lun] = NULL;
 	free(dev, M_DEVBUF);
-- 
function.linuxpower.ca

^ permalink raw reply	[flat|nested] 7+ messages in thread

* Re: aic7(censored) use after free in 2.5.66
  2003-04-01  7:00 ` Zwane Mwaikambo
@ 2003-04-01  7:22   ` Andrew Morton
  2003-04-01  7:40     ` Zwane Mwaikambo
  0 siblings, 1 reply; 7+ messages in thread
From: Andrew Morton @ 2003-04-01  7:22 UTC (permalink / raw)
  To: Zwane Mwaikambo; +Cc: linux-kernel, gibbs

Zwane Mwaikambo <zwane@linuxpower.ca> wrote:
>
> > Slab corruption: start=f7d66248, expend=f7d662c7, problemat=f7d662ac
> > Last user: [<c024f0b7>](ahc_linux_free_device+0x27/0x60)
> > Data: 
> 
> This probably wants; Or if we can sleep in all the paths, a  
> synchronize_kernel after del_timer should suffice.

Yes, but no.

The corruption was at offset 52 decimal into struct ahc_linux_device. 
Without knowing your config it is hard for me to work out what you have at
that offset.   Rebuild your kernel with -g and do:

(gdb) p/d &(((struct ahc_linux_device *)0)->maxtags)

until you find which member is at offset 52.

Something incremented that field by one after it was freed.


^ permalink raw reply	[flat|nested] 7+ messages in thread

* Re: aic7(censored) use after free in 2.5.66
  2003-04-01  7:22   ` Andrew Morton
@ 2003-04-01  7:40     ` Zwane Mwaikambo
  2003-04-01  7:52       ` Andrew Morton
  0 siblings, 1 reply; 7+ messages in thread
From: Zwane Mwaikambo @ 2003-04-01  7:40 UTC (permalink / raw)
  To: Andrew Morton; +Cc: linux-kernel, gibbs

On Mon, 31 Mar 2003, Andrew Morton wrote:

> The corruption was at offset 52 decimal into struct ahc_linux_device. 
> Without knowing your config it is hard for me to work out what you have at
> that offset.   Rebuild your kernel with -g and do:
> 
> (gdb) p/d &(((struct ahc_linux_device *)0)->maxtags)
> 
> until you find which member is at offset 52.
> 
> Something incremented that field by one after it was freed.

(gdb) p/d &(((struct ahc_linux_device *)0)->timer.lock)
$4 = 52

That would be a lock free it appears.

-- 
function.linuxpower.ca

^ permalink raw reply	[flat|nested] 7+ messages in thread

* Re: aic7(censored) use after free in 2.5.66
  2003-04-01  7:40     ` Zwane Mwaikambo
@ 2003-04-01  7:52       ` Andrew Morton
  2003-04-01  7:55         ` Zwane Mwaikambo
  0 siblings, 1 reply; 7+ messages in thread
From: Andrew Morton @ 2003-04-01  7:52 UTC (permalink / raw)
  To: Zwane Mwaikambo; +Cc: linux-kernel, gibbs

Zwane Mwaikambo <zwane@linuxpower.ca> wrote:
>
> On Mon, 31 Mar 2003, Andrew Morton wrote:
> 
> > The corruption was at offset 52 decimal into struct ahc_linux_device. 
> > Without knowing your config it is hard for me to work out what you have at
> > that offset.   Rebuild your kernel with -g and do:
> > 
> > (gdb) p/d &(((struct ahc_linux_device *)0)->maxtags)
> > 
> > until you find which member is at offset 52.
> > 
> > Something incremented that field by one after it was freed.
> 
> (gdb) p/d &(((struct ahc_linux_device *)0)->timer.lock)
> $4 = 52
> 
> That would be a lock free it appears.

OK, so that's a spin_unlock(&timer->lock) in the timer code itself.  Your
patch will fix that up.

We just need to be sure that the del_timer_sync() is not called while holding
any locks which would prevent the timer handler from completing.  



^ permalink raw reply	[flat|nested] 7+ messages in thread

* Re: aic7(censored) use after free in 2.5.66
  2003-04-01  7:52       ` Andrew Morton
@ 2003-04-01  7:55         ` Zwane Mwaikambo
  2003-04-01  8:35           ` Zwane Mwaikambo
  0 siblings, 1 reply; 7+ messages in thread
From: Zwane Mwaikambo @ 2003-04-01  7:55 UTC (permalink / raw)
  To: Andrew Morton; +Cc: linux-kernel, gibbs

On Mon, 31 Mar 2003, Andrew Morton wrote:

> OK, so that's a spin_unlock(&timer->lock) in the timer code itself.  Your
> patch will fix that up.
> 
> We just need to be sure that the del_timer_sync() is not called while holding
> any locks which would prevent the timer handler from completing.  

Quick audit says we should be ok. I can do a few simple tests on this.

-- 
function.linuxpower.ca

^ permalink raw reply	[flat|nested] 7+ messages in thread

* Re: aic7(censored) use after free in 2.5.66
  2003-04-01  7:55         ` Zwane Mwaikambo
@ 2003-04-01  8:35           ` Zwane Mwaikambo
  0 siblings, 0 replies; 7+ messages in thread
From: Zwane Mwaikambo @ 2003-04-01  8:35 UTC (permalink / raw)
  To: Andrew Morton; +Cc: linux-kernel, gibbs

On Tue, 1 Apr 2003, Zwane Mwaikambo wrote:

> On Mon, 31 Mar 2003, Andrew Morton wrote:
> 
> > OK, so that's a spin_unlock(&timer->lock) in the timer code itself.  Your
> > patch will fix that up.
> > 
> > We just need to be sure that the del_timer_sync() is not called while holding
> > any locks which would prevent the timer handler from completing.  
> 
> Quick audit says we should be ok. I can do a few simple tests on this.

Ok came up and went down clean.

-- 
function.linuxpower.ca

^ permalink raw reply	[flat|nested] 7+ messages in thread

end of thread, other threads:[~2003-04-01  8:28 UTC | newest]

Thread overview: 7+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2003-04-01  6:48 aic7(censored) use after free in 2.5.66 Zwane Mwaikambo
2003-04-01  7:00 ` Zwane Mwaikambo
2003-04-01  7:22   ` Andrew Morton
2003-04-01  7:40     ` Zwane Mwaikambo
2003-04-01  7:52       ` Andrew Morton
2003-04-01  7:55         ` Zwane Mwaikambo
2003-04-01  8:35           ` Zwane Mwaikambo

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®