From: Benjamin Herrenschmidt <benh@kernel.crashing.org>
To: Linus Torvalds <torvalds@linux-foundation.org>
Cc: Linux Kernel Mailing List <linux-kernel@vger.kernel.org>,
Greg Kroah-Hartman <gregkh@linuxfoundation.org>,
"Eric W. Biederman" <ebiederm@xmission.com>,
Joel Stanley <joel@jms.id.au>
Subject: Re: [PATCH 2/2] drivers: core: Remove glue dirs from sysfs earlier
Date: Mon, 02 Jul 2018 20:22:17 +1000 [thread overview]
Message-ID: <280670daea92b750dd215d876ed2e400ce589a13.camel@kernel.crashing.org> (raw)
In-Reply-To: <CA+55aFzUhe7j+6XL_BB+gvSnCvMCOePZhanTBk5tq=zqvFFWSw@mail.gmail.com>
On Sun, 2018-07-01 at 10:04 -0700, Linus Torvalds wrote:
> On Sun, Jul 1, 2018 at 12:16 AM Benjamin Herrenschmidt
> <benh@kernel.crashing.org> wrote:
> >
> > I suspect you didn't read it my entire argument or I wasn't clear
> > enough :-) This is actually the crux of the problem:
> >
> > Yes the object continues to exist. However, the *last* kobject_put to
> > it will no longer be done under whatever higher level locking the
> > subsystem provides (whatever prevents for example concurrent add and
> > removes).
>
> Well, yes and no.
>
> Why "no"?
>
> The last dropping is actually not necessarily that interesting.
> Especially with the sysfs interface, we basically know that you can
> look up the object using RCU (since that's what the filesystem lookup
> does), and that basically means that the refcount is always the final
> serialization mechanism.There is nothing else that can possibly lock
> it.
>
> So this is where we disagree:
>
> > Thus in that scenario the "last minute" kobject_release() done by the
> > last kobject_put() will be effectively unprotected from for example the
> > gdp_mutex (in the case of the gluedirs) or whatever other locking the
> > subsystem owning the kobject is using to avoid making that "refount 0"
> > object "discoverable".
>
> No. *Fundamentally*, there is only one thing that protects that
> object: the refcount.
>
> And my argument is that anything that has this model (which means
> anything that has any sysfs linkage, which pretty much means any
> kobject) absolutely *must* use "kobject_get_unless_zero()" unless it
> had an existing stable pointer and just wants to increase the refcount
> (ie "already got a reference throuigh one of my data structures that
> use the lock")
>
> But if you have that model, that means that the "last drop" is
> actually almost totally irrelevant. Because it doesn't matter if it's
> done inside the lock or not - you know that once it has been done,
> that object is entirely gone. It's not discoverable any more -
> regardless of locking. The discoverability is basically controlled
> entirely by the refcount.
>
> So what happens then?
>
> The locking isn't important for the last release, but it *is*
> important for new object *creation*.
>
> Why?
>
> The refcount means that once an object is gone, it's gone for
> *everyone*. It's a one-way thing, and it's thread-safe. So the code
> that does *creation* can do this:
>
> - get subsystem lock
> - look up object (using the "unless_zero()" model)
> - if you got the object, re-use it, and you're done: drop lock and return
> - otherwise, you know that nobody else can get it either
> - create new object and instantiate it
> - drop lock
>
> and this means that you create a new object IFF the old object had its
> refcount drop to zero. So you always have exactly one copy (or no copy
> at all, in between the last drop and the creation of the new one).
>
> See? The lack of locking at drop time didn't matter. The refcount
> itself serialized things.
>
> So the above is what I *think* the "glue_dir" logic should be. No need
> for any other count. Just re-use the old glue dir if you can find it,
> and create a new one if you can't.
>
> The one important thing is that the object lookup above needs to use
> the lookup needs to find the object all the way until the refcount has
> become zero. And that actually means that the object MUST NOT be
> removed from the object lists until *after* the refcount has been
> decremented to zero. Which is actually why that "automatic cleanup"
> that you hate is actually an integral and important part of the
> process: removing the object *before* the refcount went to zero is
> broken, because that means that the "look up object" phase can now
> miss an object that still has a non-zero refcount.
>
> > So my patch 1/2 prevents us from finding the old dying object (and thus
> > from crashing) but replaces this with the duplicate name problem.
>
> So I absolutely agree with your patch 1/2. My argument against it is
> actually that I think the "unless_zero" thing needs to be more
> universal.
>
> > My patch 2/2 removes that second problem by ensuring we remove the
> > object from sysfs synchronously in device_del when it no longer
> > contains any children, explicitely rather than implicitely by the
> > virtue of doing the "last" kobject_put.
>
> No. See above. The reason I think your patch 2/2 is wrong is that is
> actually *breaks* the above model, exactly because of that thing that
> you hatre.
>
> The explicit removal is actively wrong for the "I want to reuse the
> object" model, exactly because it happens before the refcount has gone
> to zero.
>
> > > No. That the zero kobject_get() will not result in a warning. It just
> > > does a kref_get(), no warnings anywhere.
> >
> > It's there but it's in refcount:
> >
> > void refcount_inc(refcount_t *r)
> > {
> > WARN_ONCE(!refcount_inc_not_zero(r), "refcount_t: increment on 0; use-after-free.\n");
> > }
> > EXPORT_SYMBOL(refcount_inc);
> >
> > In fact that's how I started digging into that problem in the first place :-)
>
> Hey, you are again hitting this because of extra config options.
>
> Because the refcount_inc() that I found looks like this:
>
> static inline void refcount_inc(refcount_t *r)
> {
> atomic_inc(&r->refs);
> }
>
> and has no warning.
>
> I wonder how many people actually run with REFCOUNT_FULL that warns -
> because it's way too expensive. It's not set in the default Fedora
> config, for example, and that's despite how Fedora tends to set all
> the other debug options.
>
> So no, it really doesn't warn normally.
>
> Linus
next prev parent reply other threads:[~2018-07-02 10:22 UTC|newest]
Thread overview: 42+ messages / expand[flat|nested] mbox.gz Atom feed top
[not found] <c40fe912fe008b1b531a3867e8784ed79d68023e.camel@kernel.crashing.org>
[not found] ` <CA+55aFxR0qg0yY-NWnH0DDruVWw8qRqp8=CRLq13p=TyxosJKw@mail.gmail.com>
2018-06-29 2:21 ` [PATCH 1/2] drivers: core: Don't try to use a dead glue_dir Benjamin Herrenschmidt
2018-06-30 19:45 ` Linus Torvalds
2018-07-07 16:48 ` Greg Kroah-Hartman
2018-07-09 23:44 ` Benjamin Herrenschmidt
2018-07-10 14:55 ` Greg Kroah-Hartman
2018-07-10 23:32 ` Benjamin Herrenschmidt
2018-07-10 23:55 ` Linus Torvalds
2018-07-11 0:07 ` Benjamin Herrenschmidt
2018-07-21 7:53 ` Greg Kroah-Hartman
2018-07-23 0:35 ` Benjamin Herrenschmidt
2018-07-07 16:51 ` Greg Kroah-Hartman
2018-07-09 23:50 ` Benjamin Herrenschmidt
2018-06-29 2:21 ` [PATCH 2/2] drivers: core: Remove glue dirs from sysfs earlier Benjamin Herrenschmidt
2018-06-29 13:56 ` Linus Torvalds
2018-06-29 13:57 ` Linus Torvalds
2018-06-30 1:04 ` Benjamin Herrenschmidt
2018-06-30 3:51 ` Benjamin Herrenschmidt
[not found] ` <edc7b03b9550ddcf1291ebf5a6dafd24f4455c23.camel@kernel.crashing.org>
[not found] ` <CA+55aFxS7OVEN5XrxceC5ibz780mhn-qRa50w1gVFjsz2JjMbw@mail.gmail.com>
[not found] ` <7eb06b499f2be366cf68c6b6588b16c603e6a567.camel@kernel.crashing.org>
2018-07-01 2:07 ` Linus Torvalds
2018-07-01 2:18 ` Linus Torvalds
2018-07-01 3:49 ` Benjamin Herrenschmidt
2018-07-01 3:42 ` Benjamin Herrenschmidt
2018-07-01 3:57 ` Linus Torvalds
2018-07-01 7:16 ` Benjamin Herrenschmidt
2018-07-01 17:04 ` Linus Torvalds
2018-07-01 23:36 ` Benjamin Herrenschmidt
2018-07-02 10:23 ` Benjamin Herrenschmidt
2018-07-02 19:24 ` Linus Torvalds
2018-07-03 0:57 ` Benjamin Herrenschmidt
2018-07-03 2:15 ` Linus Torvalds
2018-07-03 2:26 ` Linus Torvalds
2018-07-03 2:39 ` Benjamin Herrenschmidt
2018-07-03 5:22 ` Benjamin Herrenschmidt
2018-07-03 15:46 ` Tejun Heo
2018-07-04 1:10 ` Benjamin Herrenschmidt
[not found] ` <CA+55aFzKmzC-2_6+RsRRu9KfK_r=UGgLN2Q0hSNBV=ScGR7=8g@mail.gmail.com>
[not found] ` <6e3ca577f8dd5f3621d1054447d3f928a73dfcf9.camel@kernel.crashing.org>
[not found] ` <CA+55aFy+ZSu5cPzk887N-ZgXqvTB=Bp1JQYMWT1SZY81MqLH6Q@mail.gmail.com>
[not found] ` <1bc873980e7f63291fbe19dbc7e1607b8e126241.camel@kernel.crashing.org>
[not found] ` <20180707164241.GB16279@kroah.com>
[not found] ` <CA+55aFx-UX8nxewRFFWdBgYfPqfipnxaqJuJCUni9h4JvhoPFw@mail.gmail.com>
2018-07-10 0:29 ` [PATCH v2 " Benjamin Herrenschmidt
2018-07-10 0:33 ` Linus Torvalds
2018-07-10 1:37 ` Benjamin Herrenschmidt
2018-07-10 14:55 ` Greg Kroah-Hartman
2018-07-10 23:31 ` Benjamin Herrenschmidt
2018-07-03 2:37 ` [PATCH " Benjamin Herrenschmidt
2018-07-02 10:22 ` Benjamin Herrenschmidt [this message]
2018-07-01 3:52 ` Benjamin Herrenschmidt
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=280670daea92b750dd215d876ed2e400ce589a13.camel@kernel.crashing.org \
--to=benh@kernel.crashing.org \
--cc=ebiederm@xmission.com \
--cc=gregkh@linuxfoundation.org \
--cc=joel@jms.id.au \
--cc=linux-kernel@vger.kernel.org \
--cc=torvalds@linux-foundation.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
Powered by JetHome