From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1751781AbeAWQTT (ORCPT ); Tue, 23 Jan 2018 11:19:19 -0500 Received: from bombadil.infradead.org ([65.50.211.133]:32977 "EHLO bombadil.infradead.org" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1751256AbeAWQTR (ORCPT ); Tue, 23 Jan 2018 11:19:17 -0500 Date: Tue, 23 Jan 2018 17:19:11 +0100 From: Peter Zijlstra To: Geert Uytterhoeven Cc: Ingo Molnar , Linus Torvalds , Linux Kernel Mailing List , Thomas Gleixner , "Paul E. McKenney" , Andrew Morton , davej@codemonkey.org.uk Subject: [PATCH] futex: Fix OWNER_DEAD fixup Message-ID: <20180123161911.GD2295@hirez.programming.kicks-ass.net> References: <20180117152416.eazu647rhjvy4rw6@gmail.com> <20180122103947.GD2228@hirez.programming.kicks-ass.net> MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <20180122103947.GD2228@hirez.programming.kicks-ass.net> User-Agent: Mutt/1.9.2 (2017-12-15) Sender: linux-kernel-owner@vger.kernel.org List-ID: X-Mailing-List: linux-kernel@vger.kernel.org On Mon, Jan 22, 2018 at 11:39:47AM +0100, Peter Zijlstra wrote: > No, I think you actually spotted a bug there. We now can't set > OWNER_DIED anymore, which is bad. > > I think the below fixes things, but let me go trawl through the various > futex test things, because I think I've seen a unit test for this > _somewhere_. glibc has robustpi tests, but nothing there triggered this case. --- Subject: futex: Fix OWNER_DEAD fixup From: Peter Zijlstra Date: Mon, 22 Jan 2018 11:39:47 +0100 Both Geert and DaveJ reported that the recent futex commit: c1e2f0eaf015 ("futex: Avoid violating the 10th rule of futex") introduced a problem with setting OWNER_DEAD. We set the bit on an uninitialized variable and then entirely optimize it away as a dead-store. Move the setting of the bit to where it is more useful. Reported-by: Geert Uytterhoeven Reported-by: Dave Jones Cc: Ingo Molnar Cc: Andrew Morton Cc: Linus Torvalds Cc: Thomas Gleixner Cc: "Paul E. McKenney" Fixes: c1e2f0eaf015 ("futex: Avoid violating the 10th rule of futex") Signed-off-by: Peter Zijlstra (Intel) --- kernel/futex.c | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/kernel/futex.c b/kernel/futex.c index 8c5424dd5924..7f719d110908 100644 --- a/kernel/futex.c +++ b/kernel/futex.c @@ -2311,9 +2311,6 @@ static int fixup_pi_state_owner(u32 __user *uaddr, struct futex_q *q, raw_spin_lock_irq(&pi_state->pi_mutex.wait_lock); oldowner = pi_state->owner; - /* Owner died? */ - if (!pi_state->owner) - newtid |= FUTEX_OWNER_DIED; /* * We are here because either: @@ -2374,6 +2371,9 @@ static int fixup_pi_state_owner(u32 __user *uaddr, struct futex_q *q, } newtid = task_pid_vnr(newowner) | FUTEX_WAITERS; + /* Owner died? */ + if (!pi_state->owner) + newtid |= FUTEX_OWNER_DIED; if (get_futex_value_locked(&uval, uaddr)) goto handle_fault;