* Re: [BUG][RESEND] Bluetooth: L2CAP: possible data race in __sco_sock_close() [not found] <CADm8TemwbUWDP0R_t7axFk4=4-srnm5c+2oJSy7aeSzdKFSVCA@mail.gmail.com> @ 2023-04-28 21:24 ` Luiz Augusto von Dentz 2023-05-01 9:51 ` Tuo Li 0 siblings, 1 reply; 2+ messages in thread From: Luiz Augusto von Dentz @ 2023-04-28 21:24 UTC (permalink / raw) To: Li Tuo Cc: marcel, johan.hedberg, David S. Miller, edumazet, Jakub Kicinski, pabeni, linux-bluetooth, netdev, Linux Kernel, baijiaju1990 Hi, On Fri, Apr 28, 2023 at 3:27 AM Li Tuo <islituo@gmail.com> wrote: > > Hello, > > Our static analysis tool finds a possible data race in the l2cap protocol > in Linux 6.3.0-rc7: > > In most calling contexts, the variable sk->sk_socket is accessed > with holding the lock sk->sk_callback_lock. Here is an example: > > l2cap_sock_accept() --> Line 346 in net/bluetooth/l2cap_sock.c > bt_accept_dequeue() --> Line 368 in net/bluetooth/l2cap_sock.c > sock_graft() --> Line 240 in net/bluetooth/af_bluetooth.c > write_lock_bh(&sk->sk_callback_lock); --> Line 2081 in include/net/sock.h (Lock sk->sk_callback_lock) > sk_set_socket() --> Line 2084 in include/net/sock.h > sk->sk_socket = sock; --> Line 2054 in include/net/sock.h (Access sk->sk_socket) > > However, in the following calling context: > > sco_sock_shutdown() --> Line 1227 in net/bluetooth/sco.c > __sco_sock_close() --> Line 1243 in net/bluetooth/sco.c > BT_DBG(..., sk->sk_socket); --> Line 431 in net/bluetooth/sco.c (Access sk->sk_socket) > > the variable sk->sk_socket is accessed without holding the lock > sk->sk_callback_lock, and thus a data race may occur. > > Reported-by: BassCheck <bass@buaa.edu.cn> Need to check in detail what it means to hold the sk_callback_lock, btw is this static analysis tool of yours something public that we can use in our CI to detect these problems? -- Luiz Augusto von Dentz ^ permalink raw reply [flat|nested] 2+ messages in thread
* Re: [BUG][RESEND] Bluetooth: L2CAP: possible data race in __sco_sock_close() 2023-04-28 21:24 ` [BUG][RESEND] Bluetooth: L2CAP: possible data race in __sco_sock_close() Luiz Augusto von Dentz @ 2023-05-01 9:51 ` Tuo Li 0 siblings, 0 replies; 2+ messages in thread From: Tuo Li @ 2023-05-01 9:51 UTC (permalink / raw) To: Luiz Augusto von Dentz Cc: marcel, johan.hedberg, David S. Miller, edumazet, Jakub Kicinski, pabeni, linux-bluetooth, netdev, Linux Kernel, baijiaju1990 Thanks for your reply and interests. Our static analysis tool is still to be improved, and any feedback on it would be appreciated. On 2023/4/29 5:24, Luiz Augusto von Dentz wrote: > Hi, > > On Fri, Apr 28, 2023 at 3:27 AM Li Tuo <islituo@gmail.com> wrote: >> Hello, >> >> Our static analysis tool finds a possible data race in the l2cap protocol >> in Linux 6.3.0-rc7: >> >> In most calling contexts, the variable sk->sk_socket is accessed >> with holding the lock sk->sk_callback_lock. Here is an example: >> >> l2cap_sock_accept() --> Line 346 in net/bluetooth/l2cap_sock.c >> bt_accept_dequeue() --> Line 368 in net/bluetooth/l2cap_sock.c >> sock_graft() --> Line 240 in net/bluetooth/af_bluetooth.c >> write_lock_bh(&sk->sk_callback_lock); --> Line 2081 in include/net/sock.h (Lock sk->sk_callback_lock) >> sk_set_socket() --> Line 2084 in include/net/sock.h >> sk->sk_socket = sock; --> Line 2054 in include/net/sock.h (Access sk->sk_socket) >> >> However, in the following calling context: >> >> sco_sock_shutdown() --> Line 1227 in net/bluetooth/sco.c >> __sco_sock_close() --> Line 1243 in net/bluetooth/sco.c >> BT_DBG(..., sk->sk_socket); --> Line 431 in net/bluetooth/sco.c (Access sk->sk_socket) >> >> the variable sk->sk_socket is accessed without holding the lock >> sk->sk_callback_lock, and thus a data race may occur. >> >> Reported-by: BassCheck <bass@buaa.edu.cn> > Need to check in detail what it means to hold the sk_callback_lock, > btw is this static analysis tool of yours something public that we can > use in our CI to detect these problems? > > ^ permalink raw reply [flat|nested] 2+ messages in thread
end of thread, other threads:[~2023-05-01 9:51 UTC | newest]
Thread overview: 2+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
[not found] <CADm8TemwbUWDP0R_t7axFk4=4-srnm5c+2oJSy7aeSzdKFSVCA@mail.gmail.com>
2023-04-28 21:24 ` [BUG][RESEND] Bluetooth: L2CAP: possible data race in __sco_sock_close() Luiz Augusto von Dentz
2023-05-01 9:51 ` Tuo Li
This is a public inbox, see mirroring instructions for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®