mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: Dmitry Torokhov <dmitry.torokhov@gmail.com>
To: "Eric W. Biederman" <ebiederm@xmission.com>
Cc: Tejun Heo <tj@kernel.org>,
	Linus Torvalds <torvalds@linux-foundation.org>,
	KOSAKI Motohiro <kosaki.motohiro@jp.fujitsu.com>,
	Borislav Petkov <petkovbb@googlemail.com>,
	David Airlie <airlied@linux.ie>,
	Linux Kernel Mailing List <linux-kernel@vger.kernel.org>,
	Greg KH <greg@kroah.com>, Al Viro <viro@ZenIV.linux.org.uk>
Subject: Re: drm_vm.c:drm_mmap: possible circular locking dependency detected
Date: Mon, 4 Jan 2010 13:12:33 -0800	[thread overview]
Message-ID: <20100104211233.GA6282@core.coreip.homeip.net> (raw)
In-Reply-To: <m14on1fygh.fsf@fess.ebiederm.org>

On Mon, Jan 04, 2010 at 11:43:10AM -0800, Eric W. Biederman wrote:
> Dmitry Torokhov <dmitry.torokhov@gmail.com> writes:
> 
> > On Sun, Jan 03, 2010 at 02:57:15AM -0800, Eric W. Biederman wrote:
> >> Dmitry Torokhov <dmitry.torokhov@gmail.com> writes:
> >> 
> >> >
> >> > Overall I am not concerned about lockdep bitching about serio because it
> >> > still bitches if you simply reload psmouse on a box with Synaptics with a
> >> > pass-through port even though there are nested annotations and it is
> >> > silent first time around.
> >> 
> >> This is a new lockdep annotation, and looking into it this appears to
> >> be a true possible deadlock in the serio/sysfs interactions.
> >> 
> >> We have serio_pin_driver() called from all of the sysfs attributes
> >> which does:
> >>    mutex_lock(&serio->drv_mutex);
> >> 
> >> We have serio_disconnect_driver() called on an unplug which does:
> >>    mutex_lock(&serio->drv_mutex);
> >> 
> >> The deadlock potential is if someone reads say the psmouse rate
> >> sysfs file while the mouse is being unplugged.  There is a race
> >> such that we can have:
> >> 
> >> 						  sysfs_read_file()
> >>                                                     fill_read_buffer()
> >> 						       sysfs_get_active_two()
> >> 							 psmouse_attr_show_helper()
> >>                                         		   serio_pin_driver()
> >> serio_disconnect_driver()		
> >>   mutex_lock(&serio->drv_mutex);		
> >> 				<----------------->	   mutex_lock(&serio_drv_mutex);
> >>     psmouse_disconnect()
> >>       sysfs_remove_group(... psmouse_attr_group);
> >> 	....
> >> 	sysfs_deactivate(); 
> >> 	  wait_for_completion();
> >> 
> >> 
> >> So it is unlikely but possible to deadlock by accessing a serio
> >> attribute of a serio device that is being removed.
> >
> > Hmm, I guess I was too quick dismissing lockdep complaints here. Now
> > that sysfs remove waits deadlock indeed is possible. Actually the locks
> > on serio->drv_mutex in attributes were added to make sure we don't
> > access device that was unbound from the driver through stale sysfs
> > attributes.
> 
> Cool.  So we have solved the problem generically but we have left over
> layer specific solutions.  That seems like a good problem to have.
> 
> >> What to do about it is another question.
> >
> > I think we should simply not take serio->drv_mutex in attributes and use
> > driver-private mutex to serialize "set" methods that may alter device
> > state.
> 
> Do you have any ideas what those might be?  It looks like we are only
> talking about psmouse and atkbd.  So the audit for this chunk should
> not be too bad.

Right, only these 2.

> 
> The psmouse code already has a mutex on it's set operations only the
> atkbd does not.  The atkbd code does do a driver stop/start, which is
> similar (but race prone without the serio->drv_mutex).
> 
> Except for the lack of atkbd_enable/disable locking the patch below should
> be good.  Opinions from someone who knows the serio code better than I do
> would be helpful.

Thanks Eric, this looks good. I'll add the missing mutex to atkbd and
apply. I think it can wait for .34 though - the window is quite small.

-- 
Dmitry

  reply	other threads:[~2010-01-04 21:12 UTC|newest]

Thread overview: 60+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2009-12-24 22:00 Linux 2.6.33-rc2 - Merry Christmas Linus Torvalds
2009-12-25 10:27 ` -tip: origin tree boot crash Ingo Molnar
2009-12-25 19:49   ` Dmitry Torokhov
2009-12-26 20:19     ` Len Brown
2009-12-26 20:17   ` Len Brown
2009-12-27  4:20     ` Len Brown
2009-12-28  9:44       ` Ingo Molnar
2009-12-28 12:01         ` Ingo Molnar
2009-12-28 15:02           ` Paul Rolland
2009-12-28 16:15             ` Paul Rolland
2009-12-28 16:53             ` Paul Rolland
2009-12-28 20:17               ` Dmitry Torokhov
2009-12-30  6:14               ` Len Brown
2009-12-30  7:13                 ` Paul Rolland
2009-12-30  6:19               ` [PATCH] wmi: check find_guid() return value to prevent oops Len Brown
2009-12-30  6:21               ` [PATCH] dell-wmi: sys_init_module: 'dell_wmi'->init suspiciously returned 21, it should follow 0/-E convention Len Brown
2009-12-25 13:10 ` Linux 2.6.33-rc2 - Blank screen for Intel KMS Miguel Calleja
2009-12-29  9:50   ` Miguel Calleja
2009-12-29 14:01     ` Rafael J. Wysocki
2009-12-25 20:00 ` Linux 2.6.33-rc2 - Merry Christmas Borislav Petkov
2009-12-25 21:50   ` Borislav Petkov
2009-12-26  6:00     ` Jesse Barnes
2009-12-26  8:02       ` Borislav Petkov
2009-12-26  9:36 ` EHCI resume sysfs duplicates (was: Re: Linux 2.6.33-rc2 - Merry Christmas ...) Borislav Petkov
2009-12-26  9:45 ` drm_vm.c:drm_mmap: possible circular locking dependency detected " Borislav Petkov
2009-12-28  0:40   ` KOSAKI Motohiro
2009-12-30 21:10     ` Linus Torvalds
2009-12-30 21:34       ` Eric W. Biederman
2009-12-30 22:03         ` Linus Torvalds
2009-12-31  8:40           ` Eric W. Biederman
2009-12-31 19:04             ` Linus Torvalds
2010-01-01 13:58               ` [PATCH] sysfs: Cache the last sysfs_dirent to improve readdir scalability Eric W. Biederman
2010-01-01 15:33                 ` Borislav Petkov
2010-01-01 18:56                 ` Linus Torvalds
2010-01-01 22:43                   ` [PATCH] sysfs: Cache the last sysfs_dirent to improve readdir scalability v2 Eric W. Biederman
2010-01-01 23:10                     ` Linus Torvalds
2010-01-02  5:59                       ` Greg KH
2010-01-02 15:40                       ` Borislav Petkov
2010-01-01 15:16               ` drm_vm.c:drm_mmap: possible circular locking dependency detected (was: Re: Linux 2.6.33-rc2 - Merry Christmas ...) Eric W. Biederman
2010-01-02  2:59                 ` drm_vm.c:drm_mmap: possible circular locking dependency detected Tejun Heo
2010-01-02 21:37                   ` [PATCH] sysfs: Add lockdep annotations for the sysfs active reference Eric W. Biederman
2010-01-03  0:02                     ` Tejun Heo
2010-01-17 16:26                     ` Ming Lei
2010-01-17 17:18                       ` Eric W. Biederman
2010-01-17 18:03                         ` Dominik Brodowski
2010-01-02 21:49                   ` drm_vm.c:drm_mmap: possible circular locking dependency detected Eric W. Biederman
2010-01-03  0:32                     ` Tejun Heo
2010-01-03  2:06                       ` Eric W. Biederman
2010-01-03  5:01                         ` Tejun Heo
2010-01-03  5:38                           ` Eric W. Biederman
2010-01-03  6:05                             ` Tejun Heo
2010-01-03  7:47                       ` Dmitry Torokhov
2010-01-03 10:57                         ` Eric W. Biederman
2010-01-03 11:14                           ` Eric W. Biederman
2010-01-04 19:16                             ` Dmitry Torokhov
2010-01-04 18:57                           ` Dmitry Torokhov
2010-01-04 19:43                             ` Eric W. Biederman
2010-01-04 21:12                               ` Dmitry Torokhov [this message]
2010-01-04 23:09                               ` Tejun Heo
2009-12-31  8:40           ` drm_vm.c:drm_mmap: possible circular locking dependency detected (was: Re: Linux 2.6.33-rc2 - Merry Christmas ...) Eric W. Biederman

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20100104211233.GA6282@core.coreip.homeip.net \
    --to=dmitry.torokhov@gmail.com \
    --cc=airlied@linux.ie \
    --cc=ebiederm@xmission.com \
    --cc=greg@kroah.com \
    --cc=kosaki.motohiro@jp.fujitsu.com \
    --cc=linux-kernel@vger.kernel.org \
    --cc=petkovbb@googlemail.com \
    --cc=tj@kernel.org \
    --cc=torvalds@linux-foundation.org \
    --cc=viro@ZenIV.linux.org.uk \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

Powered by JetHome