From: Greg KH <gregkh@suse.de>
To: linux-kernel@vger.kernel.org, stable@kernel.org
Cc: stable-review@kernel.org, torvalds@linux-foundation.org,
akpm@linux-foundation.org, alan@lxorguk.ukuu.org.uk,
gnb@fmeh.org, "J. Bruce Fields" <bfields@redhat.com>
Subject: [36/55] svcrpc: fix list-corrupting race on nfsd shutdown
Date: Fri, 05 Aug 2011 17:02:06 -0700 [thread overview]
Message-ID: <20110806000252.472319197@clark.kroah.org> (raw)
In-Reply-To: <20110806000257.GA25498@kroah.com>
2.6.32-longterm review patch. If anyone has any objections, please let us know.
------------------
From: "J. Bruce Fields" <bfields@redhat.com>
commit ebc63e531cc6a457595dd110b07ac530eae788c3 upstream.
After commit 3262c816a3d7fb1eaabce633caa317887ed549ae "[PATCH] knfsd:
split svc_serv into pools", svc_delete_xprt (then svc_delete_socket) no
longer removed its xpt_ready (then sk_ready) field from whatever list it
was on, noting that there was no point since the whole list was about to
be destroyed anyway.
That was mostly true, but forgot that a few svc_xprt_enqueue()'s might
still be hanging around playing with the about-to-be-destroyed list, and
could get themselves into trouble writing to freed memory if we left
this xprt on the list after freeing it.
(This is actually functionally identical to a patch made first by Ben
Greear, but with more comments.)
Cc: gnb@fmeh.org
Reported-by: Ben Greear <greearb@candelatech.com>
Tested-by: Ben Greear <greearb@candelatech.com>
Signed-off-by: J. Bruce Fields <bfields@redhat.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@suse.de>
---
net/sunrpc/svc_xprt.c | 11 ++++++-----
1 file changed, 6 insertions(+), 5 deletions(-)
--- a/net/sunrpc/svc_xprt.c
+++ b/net/sunrpc/svc_xprt.c
@@ -896,12 +896,13 @@ void svc_delete_xprt(struct svc_xprt *xp
if (!test_and_set_bit(XPT_DETACHED, &xprt->xpt_flags))
list_del_init(&xprt->xpt_list);
/*
- * We used to delete the transport from whichever list
- * it's sk_xprt.xpt_ready node was on, but we don't actually
- * need to. This is because the only time we're called
- * while still attached to a queue, the queue itself
- * is about to be destroyed (in svc_destroy).
+ * The only time we're called while xpt_ready is still on a list
+ * is while the list itself is about to be destroyed (in
+ * svc_destroy). BUT svc_xprt_enqueue could still be attempting
+ * to add new entries to the sp_sockets list, so we can't leave
+ * a freed xprt on it.
*/
+ list_del_init(&xprt->xpt_ready);
if (test_bit(XPT_TEMP, &xprt->xpt_flags))
serv->sv_tmpcnt--;
next prev parent reply other threads:[~2011-08-06 0:22 UTC|newest]
Thread overview: 64+ messages / expand[flat|nested] mbox.gz Atom feed top
2011-08-06 0:02 [00/55] 2.6.32.44-longterm review Greg KH
2011-08-06 0:01 ` [01/55] ASoC: Fix Blackfin I2S _pointer() implementation return in bounds values Greg KH
2011-08-06 0:01 ` [02/55] [media] v4l2-ioctl.c: prefill tuner type for g_frequency and g/s_tuner Greg KH
2011-08-06 0:01 ` [03/55] [media] pvrusb2: fix g/s_tuner support Greg KH
2011-08-06 0:01 ` [04/55] [media] bttv: fix s_tuner for radio Greg KH
2011-08-06 0:01 ` [05/55] gro: Only reset frag0 when skb can be pulled Greg KH
2011-08-06 0:01 ` [06/55] NFSv4.1: update nfs4_fattr_bitmap_maxsz Greg KH
2011-08-06 0:01 ` [07/55] SUNRPC: Fix a race between work-queue and rpc_killall_tasks Greg KH
2011-08-07 17:38 ` [Stable-review] " Ben Hutchings
2011-08-08 17:03 ` Greg KH
2011-08-08 18:07 ` Ben Hutchings
2011-08-06 0:01 ` [08/55] SUNRPC: Fix use of static variable in rpcb_getport_async Greg KH
2011-08-06 0:01 ` [09/55] si4713-i2c: avoid potential buffer overflow on si4713 Greg KH
2011-08-06 0:01 ` [10/55] hwmon: (max1111) Fix race condition causing NULL pointer exception Greg KH
2011-08-06 0:01 ` [11/55] bridge: send proper message_age in config BPDU Greg KH
2011-08-06 0:01 ` [12/55] davinci: DM365 EVM: fix video input mux bits Greg KH
2011-08-06 0:01 ` [13/55] libata: fix unexpectedly frozen port after ata_eh_reset() Greg KH
2011-08-06 0:01 ` [14/55] x86: Make Dell Latitude E5420 use reboot=pci Greg KH
2011-08-06 0:01 ` [15/55] USB: pl2303: add AdLink ND-6530 USB IDs Greg KH
2011-08-06 0:01 ` [16/55] USB: pl2303.h: checkpatch cleanups Greg KH
2011-08-06 0:01 ` [17/55] USB: serial: add IDs for WinChipHead USB->RS232 adapter Greg KH
2011-08-06 0:01 ` [18/55] staging: comedi: fix infoleak to userspace Greg KH
2011-08-06 0:01 ` [19/55] USB: OHCI: fix another regression for NVIDIA controllers Greg KH
2011-08-06 0:01 ` [20/55] usb: musb: restore INDEX register in resume path Greg KH
2011-08-06 0:01 ` [21/55] USB: dummy-hcd needs the has_tt flag Greg KH
2011-08-06 0:01 ` [22/55] ARM: pxa/cm-x300: fix V3020 RTC functionality Greg KH
2011-08-06 0:01 ` [23/55] jme: Fix unmap error (Causing system freeze) Greg KH
2011-08-06 0:01 ` [24/55] [SCSI] libsas: remove expander from dev list on error Greg KH
2011-08-06 0:01 ` [25/55] mac80211: Restart STA timers only on associated state Greg KH
2011-08-06 0:01 ` [26/55] [SCSI] Blacklist Traxdata CDR4120 and IOMEGA Zip drive to avoid lock ups Greg KH
2011-08-06 0:01 ` [27/55] [SCSI] ses: requesting a fault indication Greg KH
2011-08-06 0:01 ` [28/55] [SCSI] fix crash in scsi_dispatch_cmd() Greg KH
[not found] ` <1312739411.2591.1026.camel@deadeye>
2011-08-07 17:51 ` [Stable-review] " Ben Hutchings
2011-08-08 17:04 ` Greg KH
2011-08-08 18:10 ` Ben Hutchings
2011-08-08 19:17 ` Dave Jones
2011-08-09 20:22 ` James Bottomley
2011-08-06 0:01 ` [29/55] [SCSI] pmcraid: reject negative request size Greg KH
2011-08-06 0:02 ` [30/55] kexec, x86: Fix incorrect jump back address if not Greg KH
2011-08-06 0:02 ` [31/55] powerpc/kdump: Fix timeout in crash_kexec_wait_realmode Greg KH
2011-08-06 0:02 ` [32/55] PCI: ARI is a PCIe v2 feature Greg KH
2011-08-06 0:02 ` [33/55] cciss: do not attempt to read from a write-only register Greg KH
2011-08-06 0:02 ` [34/55] xtensa: prevent arbitrary read in ptrace Greg KH
2011-08-06 0:02 ` [35/55] ext3: Fix oops in ext3_try_to_allocate_with_rsv() Greg KH
2011-08-06 0:02 ` Greg KH [this message]
2011-08-06 0:02 ` [37/55] EHCI: only power off port if over-current is active Greg KH
2011-08-06 0:02 ` [38/55] EHCI: fix direction handling for interrupt data toggles Greg KH
2011-08-06 0:02 ` [39/55] powerpc/pseries/hvconsole: Fix dropped console output Greg KH
2011-08-06 0:02 ` [40/55] x86: Hpet: Avoid the comparator readback penalty Greg KH
2011-08-06 0:02 ` [41/55] x86: HPET: Chose a paranoid safe value for the ETIME check Greg KH
2011-08-06 0:02 ` [42/55] Revert "block: rescan partitions on invalidated devices on -ENOMEDIA Greg KH
2011-08-06 0:02 ` [43/55] cifs: clean up cifs_find_smb_ses (try #2) Greg KH
2011-08-06 0:02 ` [44/55] cifs: fix NULL pointer dereference in cifs_find_smb_ses Greg KH
2011-08-06 0:02 ` [45/55] cifs: check for NULL session password Greg KH
2011-08-06 0:02 ` [46/55] gre: fix netns vs proto registration ordering Greg KH
2011-08-06 0:02 ` [47/55] netns xfrm: fixup xfrm6_tunnel error propagation Greg KH
2011-08-06 0:02 ` [48/55] tunnels: fix netns vs proto registration ordering Greg KH
2011-08-06 0:02 ` [49/55] alpha: fix several security issues Greg KH
2011-08-06 0:02 ` [50/55] proc: restrict access to /proc/PID/io Greg KH
2011-08-06 0:02 ` [51/55] ALSA: sound/core/pcm_compat.c: adjust array index Greg KH
2011-08-06 0:02 ` [52/55] dm mpath: fix potential NULL pointer in feature arg processing Greg KH
2011-08-06 0:02 ` [53/55] dm: fix idr leak on module removal Greg KH
2011-08-06 0:02 ` [54/55] perf: overflow/perf_count_sw_cpu_clock crashes recent kernels Greg KH
2011-08-06 0:02 ` [55/55] atm: [br2684] allow routed mode operation again Greg KH
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20110806000252.472319197@clark.kroah.org \
--to=gregkh@suse.de \
--cc=akpm@linux-foundation.org \
--cc=alan@lxorguk.ukuu.org.uk \
--cc=bfields@redhat.com \
--cc=gnb@fmeh.org \
--cc=linux-kernel@vger.kernel.org \
--cc=stable-review@kernel.org \
--cc=stable@kernel.org \
--cc=torvalds@linux-foundation.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®