From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1030482AbcBRIHN (ORCPT ); Thu, 18 Feb 2016 03:07:13 -0500 Received: from mailout1.samsung.com ([203.254.224.24]:51781 "EHLO mailout1.samsung.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1030343AbcBRIHK (ORCPT ); Thu, 18 Feb 2016 03:07:10 -0500 X-AuditID: cbfee68e-f793c6d00000136c-cc-56c57babe070 Date: Thu, 18 Feb 2016 08:07:07 +0000 (GMT) From: EunTaik Lee Subject: Re: Re: [RFC PATCH] staging/android/ion : fix a race condition in the ion driver To: Laura Abbott , =?euc-kr?Q?=C0=CC=C0=BA=C5=C3?= , "gregkh@linuxfoundation.org" , "arve@android.com" , "riandrews@android.com" , "sumit.semwal@linaro.org" , "gioh.kim@lge.com" , "dan.carpenter@oracle.com" , Rohit Kumar , "sriram@marirs.net.in" , "shawn.lin@rock-chips.com" , "devel@driverdev.osuosl.org" , "linux-kernel@vger.kernel.org" Reply-to: eun.taik.lee@samsung.com MIME-version: 1.0 X-MTR: 20160218080500317@eun.taik.lee Msgkey: 20160218080500317@eun.taik.lee X-EPLocale: ko_KR.euc-kr X-Priority: 3 X-EPWebmail-Msg-Type: personal X-EPWebmail-Reply-Demand: 0 X-EPApproval-Locale: X-EPHeader: ML X-MLAttribute: X-RootMTR: 20160218080500317@eun.taik.lee X-ParentMTR: X-ArchiveUser: EV X-CPGSPASS: Y X-ConfirmMail: N,general Content-type: text/plain; charset=euc-kr MIME-version: 1.0 Message-id: <700032691.1082951455782822577.JavaMail.weblogic@epmlwas08c> X-Brightmail-Tracker: H4sIAAAAAAAAA+NgFprNJsWRmVeSWpSXmKPExsVy+t8zHd3V1UfDDP6eMLK4vGsOmwOjx+dN cgGMUQ2MNolFyRmZZakKqXnJ+SmZeem2SqEhbroWSgoZ+cUltkrRRgbGekamJnpGJuZ6lgax VkamSgp5ibmptkoVulC9SgpFyQVAtbmVxUADclL1oOJ6xal5KQ5Z+aUgl+gVJ+YWl+al6yXn 5yoplCXmlAKNUNJPmMqYMW/CG+aCJrGK3xunMTYwbhHtYuTkEBJQlzixew0LiC0hYCJxcsJE NghbTOLCvfVsEDXLGCWWXbDuYuQAqzlwqbCLkQsoPIdRYuaT6ewgNSwCqhKTuraB2WwCuhL/ P3aB2cICkRJdGz+ygjSICKxkldi0ezHUUCWJ+YcbwBbzCghKnJz5BOoIVYnrE2cyQ8TVJPbf v8IMEZeQmDX9AiuEzSsxo/0pVL2cxLSva6BqpCXOz9rACPPA4u+PoeL8Esdu72CCsAUkpp45 CFWjJfH17xGomXwSaxa+hZopKHH6WjczzK6Gjb/ZYW7Y2vIErJ5ZQFFiSvdDdghbS+LLj31s 6H7hFfCQeHN/IhPI8xICvRwSDS0zoaElIPFt8iGWCYyKs5D0zEIydxaSuchqFjCyrGIUTS1I LihOSi8yQo7uTYyQVNi3g/HmAetDjAIcjEo8vByvj4QJsSaWFVfmHmJMBlo9kVlKNDkfmHDz SuINjc2MLExNTI2NzC3NMIRNTC0sTIxwCCuJ8yZI/QwWEkhPLEnNTk0tSC2KLyrNSS0+xMjE wSnVwBivcrjklZNaWHqy1v8ZG6YauZY9YO9Ur9Q7cXj/j5c1tY++/bV1UbKY8OyezTz7BrWN bgWbr0/bGxzC/cLI4uF/AbFOlWNcD3J9Yxn2qS5tZ8iQv2Jrol6stvvCFPnyqovzDn074DLj odbPGYJ5D46d/XAg5gjD4YdBlw5ZbG9VWqDwqbWiO0uJpTgj0VCLuag4EQCEcN+PrgMAAA== X-Brightmail-Tracker: H4sIAAAAAAAAA+NgFtrLKsWRmVeSWpSXmKPExsVy+t/tPt3V1UfDDFZt1bO4vGsOmwOjx+dN cgGMURk2GamJKalFCql5yfkpmXnptkrewfHO8aZmBoa6hpYW5koKeYm5qbZKLj4Bum6ZOUBD lRTKEnNKgUIBicXFSvp2NkX5pSWpChn5xSW2StFGBsZ6RqYmekbGBnomBrFWhgYGRqZAVQkZ GfMmvGEuaBKr+L1xGmMD4xbRLkZODiEBdYkTu9ewdDFycEgImEgcuFQIEpYQEJO4cG89Wxcj F1DJHEaJmU+ms4MkWARUJSZ1bQOz2QR0Jf5/7AKzhQUiJbo2fmQFaRARWMkqsWn3YjaIBUoS 8w83sIDYvAKCEidnPmGB2KAqcX3iTGaIuJrE/vtXmCHiEhKzpl9ghbB5JWa0P4Wql5OY9nUN VI20xPlZGxhhLl38/TFUnF/i2O0dTBC2gMTUMweharQkvv49AjWTT2LNwrdQMwUlTl/rZobZ 1bDxNzvMDVtbnoDVMwsoSkzpfsgOYWtJfPmxjw3dL7wCHhJv7k9kmsAoMwtJahaS9llI2pHV LGBkWcUomlqQXFCclF5hrFecmFtcmpeul5yfu4kRnHSeLd7B+P+89SFGAQ5GJR7eDS+OhAmx JpYVV+YeYpTgYFYS4f3mfjRMiDclsbIqtSg/vqg0J7X4EKMpMKomMkuJJucDE2JeSbyhsYGx oaGluYGpoZGFkjhvwN91YUIC6YklqdmpqQWpRTB9TBycUg2MtRzmb0umTN4zP2reEfU0ncBc qTPTTkz2OKIv9alhlmuNm11Vlb75n6NVFvKSafEZK5r/2WvPvXRl63vJ2C+hlSvdb3kc3q0S tl7/6tNwpbs+Px5lRXzZcoXFTm/TPFaZ5BLVAzvj6g7UxIvoTNYIU3z4W45ZI/JohUdIe9Xr 1WqGFxjn/wtUYinOSDTUYi4qTgQAoeHASVADAAA= DLP-Filter: Pass X-CFilter-Loop: Reflected Sender: linux-kernel-owner@vger.kernel.org List-ID: X-Mailing-List: linux-kernel@vger.kernel.org Content-Transfer-Encoding: 8bit X-MIME-Autoconverted: from base64 to 8bit by mail.home.local id u1I887CA012086 2016-02-18 3:54 GMT+09:00 Laura Abbott : > On 02/16/2016 10:32 PM, EunTaik Lee wrote: >> There was a use-after-free problem in the ion driver. >> >> The problem is detected as an unaligned access in the >> spin lock functions since it uses load exclusive >> instruction. In some cases it corrupts the slub's >> free pointer which causes a unaligned access to the >> next free pointer.(thus the kmalloc function returns >> a pointer like ffffc0745b4580aa). And it causes lots of other >> hard-to-debug problems. >> >> This symptom is caused since the first member in the >> ion_handle structure is the reference count and the >> ion driver decrements the reference after it has been >> freed. >> >> To fix this problem client->lock mutex is extended >> to protect all the codes that uses the handle. >> > > This describes the symptoms very well but what's the actual > race condition? The actual race condition was in case ION_IOC_FREE of ion_ioctl() function. A handle has ref count of 1 and two tasks on different cpus calls ION_IOC_FREE simultaneously. cpu 0 cpu 1 ------------------------------------------------------- ion_handle_get_by_id() (ref == 2) ion_handle_get_by_id() (ref == 3) ion_free() (ref == 2) ion_handle_put() (ref == 1) ion_free() (ref == 0 so ion_handle_destroy() is called and the handle is freed.) ion_handle_put() is called and it decreases the slub's next free pointer So it's basically a double free on the userspace. But I made this patch since I don't think we should take a risk of such a malicious code to mess up the kernel. > Also what tree did you generate this against? It doesn't > seem to apply. The patch was generated against the stable-kernel. I will resend the patch using the latest stable-kernel along with a silly mistake that I've made when merging the patch(made against 3.18.20) to the stable-kernel. (Thank you Julia for pointing out my mistake)