From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1755090AbcEEN1w (ORCPT ); Thu, 5 May 2016 09:27:52 -0400 Received: from mx1.redhat.com ([209.132.183.28]:45082 "EHLO mx1.redhat.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1751345AbcEEN1u (ORCPT ); Thu, 5 May 2016 09:27:50 -0400 Date: Thu, 5 May 2016 08:27:48 -0500 From: Josh Poimboeuf To: Miroslav Benes Cc: Jiri Kosina , jeyu@redhat.com, pmladek@suse.com, jslaby@suse.cz, live-patching@vger.kernel.org, linux-kernel@vger.kernel.org, huawei.libin@huawei.com, minfei.huang@yahoo.com Subject: Re: [RFC PATCH] livepatch: allow removal of a disabled patch Message-ID: <20160505132748.kwk3pmgetud3c66r@treble> References: <1462190242-24731-1-git-send-email-mbenes@suse.cz> <20160503213709.g66xr624pwn7oguu@treble> <20160504023948.ttb3ko2wnicwruwy@treble> <20160504033619.5osteklgal3ixcbo@treble> <20160504131423.5yqvie2zy67jspak@treble> <20160504161423.pvupipravfxuyktz@treble> MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Disposition: inline In-Reply-To: User-Agent: Mutt/1.6.0.1 (2016-04-01) Sender: linux-kernel-owner@vger.kernel.org List-ID: X-Mailing-List: linux-kernel@vger.kernel.org On Thu, May 05, 2016 at 10:28:12AM +0200, Miroslav Benes wrote: > I think it boils down to the following problem. > > 1. CONFIG_DEBUG_KOBJECT_RELEASE=y > > 2. we have dynamic kobjects, so there is a pointer in klp_patch to struct > kobject > > 3. it is allocated during klp_init_patch() and all is fine > > 4. now we want to remove the patch module. It is disabled and module_put() > is called. User calls rmmod on the module. > > 5. klp_unregister_patch() is called in __exit method. > > 6. klp_free_patch() is called. > > 7. kobject_put(patch->kobj) is called. > > ...now it gets interesting... > > 8. among others kobject_cleanup() is scheduled as a delayed work (this is > important). > > 9. there is no completion, so kobject_put returns and the module goes > away. > > 10. someone calls patch enabled_store attribute (for example). They can > because kobject_cleanup() has not been called yet. It is delayed > scheduled. > > ...crash... But what exactly causes the crash? In enabled_store() we can see that the patch isn't in the list, so we can return -EINVAL. -- Josh