mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: Ben Hutchings <ben@decadent.org.uk>
To: linux-kernel@vger.kernel.org, stable@vger.kernel.org
Cc: akpm@linux-foundation.org, "Al Viro" <viro@zeniv.linux.org.uk>
Subject: [31/74] Nest rename_lock inside vfsmount_lock
Date: Sun, 07 Apr 2013 23:45:42 +0100	[thread overview]
Message-ID: <lsq.1365374742.832741758@decadent.org.uk> (raw)
In-Reply-To: <lsq.1365374742.214522651@decadent.org.uk>

3.2.43-rc1 review patch.  If anyone has any objections, please let me know.

------------------

From: Al Viro <viro@zeniv.linux.org.uk>

commit 7ea600b5314529f9d1b9d6d3c41cb26fce6a7a4a upstream.

... lest we get livelocks between path_is_under() and d_path() and friends.

The thing is, wrt fairness lglocks are more similar to rwsems than to rwlocks;
it is possible to have thread B spin on attempt to take lock shared while thread
A is already holding it shared, if B is on lower-numbered CPU than A and there's
a thread C spinning on attempt to take the same lock exclusive.

As the result, we need consistent ordering between vfsmount_lock (lglock) and
rename_lock (seq_lock), even though everything that takes both is going to take
vfsmount_lock only shared.

Spotted-by: Brad Spengler <spender@grsecurity.net>
Signed-off-by: Al Viro <viro@zeniv.linux.org.uk>
[bwh: Backported to 3.2:
 - Adjust context
 - s/&vfsmount_lock/vfsmount_lock/]
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
---
 fs/dcache.c |   16 +++++++++++-----
 1 file changed, 11 insertions(+), 5 deletions(-)

--- a/fs/dcache.c
+++ b/fs/dcache.c
@@ -2445,7 +2445,6 @@ static int prepend_path(const struct pat
 	bool slash = false;
 	int error = 0;
 
-	br_read_lock(vfsmount_lock);
 	while (dentry != root->dentry || vfsmnt != root->mnt) {
 		struct dentry * parent;
 
@@ -2475,8 +2474,6 @@ static int prepend_path(const struct pat
 	if (!error && !slash)
 		error = prepend(buffer, buflen, "/", 1);
 
-out:
-	br_read_unlock(vfsmount_lock);
 	return error;
 
 global_root:
@@ -2493,7 +2490,7 @@ global_root:
 		error = prepend(buffer, buflen, "/", 1);
 	if (!error)
 		error = vfsmnt->mnt_ns ? 1 : 2;
-	goto out;
+	return error;
 }
 
 /**
@@ -2520,9 +2517,11 @@ char *__d_path(const struct path *path,
 	int error;
 
 	prepend(&res, &buflen, "\0", 1);
+	br_read_lock(vfsmount_lock);
 	write_seqlock(&rename_lock);
 	error = prepend_path(path, root, &res, &buflen);
 	write_sequnlock(&rename_lock);
+	br_read_unlock(vfsmount_lock);
 
 	if (error < 0)
 		return ERR_PTR(error);
@@ -2539,9 +2538,11 @@ char *d_absolute_path(const struct path
 	int error;
 
 	prepend(&res, &buflen, "\0", 1);
+	br_read_lock(vfsmount_lock);
 	write_seqlock(&rename_lock);
 	error = prepend_path(path, &root, &res, &buflen);
 	write_sequnlock(&rename_lock);
+	br_read_unlock(vfsmount_lock);
 
 	if (error > 1)
 		error = -EINVAL;
@@ -2605,11 +2606,13 @@ char *d_path(const struct path *path, ch
 		return path->dentry->d_op->d_dname(path->dentry, buf, buflen);
 
 	get_fs_root(current->fs, &root);
+	br_read_lock(vfsmount_lock);
 	write_seqlock(&rename_lock);
 	error = path_with_deleted(path, &root, &res, &buflen);
+	write_sequnlock(&rename_lock);
+	br_read_unlock(vfsmount_lock);
 	if (error < 0)
 		res = ERR_PTR(error);
-	write_sequnlock(&rename_lock);
 	path_put(&root);
 	return res;
 }
@@ -2764,6 +2767,7 @@ SYSCALL_DEFINE2(getcwd, char __user *, b
 	get_fs_root_and_pwd(current->fs, &root, &pwd);
 
 	error = -ENOENT;
+	br_read_lock(vfsmount_lock);
 	write_seqlock(&rename_lock);
 	if (!d_unlinked(pwd.dentry)) {
 		unsigned long len;
@@ -2773,6 +2777,7 @@ SYSCALL_DEFINE2(getcwd, char __user *, b
 		prepend(&cwd, &buflen, "\0", 1);
 		error = prepend_path(&pwd, &root, &cwd, &buflen);
 		write_sequnlock(&rename_lock);
+		br_read_unlock(vfsmount_lock);
 
 		if (error < 0)
 			goto out;
@@ -2793,6 +2798,7 @@ SYSCALL_DEFINE2(getcwd, char __user *, b
 		}
 	} else {
 		write_sequnlock(&rename_lock);
+		br_read_unlock(vfsmount_lock);
 	}
 
 out:


  parent reply	other threads:[~2013-04-07 23:31 UTC|newest]

Thread overview: 75+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2013-04-07 22:45 [00/74] 3.2.43-rc1 review Ben Hutchings
2013-04-07 22:45 ` [17/74] ath9k_hw: revert chainmask to user configuration after calibration Ben Hutchings
2013-04-07 22:45 ` [51/74] loop: prevent bdev freeing while device in use Ben Hutchings
2013-04-07 22:45 ` [38/74] usb: ftdi_sio: Add support for Mitsubishi FX-USB-AW/-BD Ben Hutchings
2013-04-07 22:45 ` [52/74] sky2: Receive Overflows not counted Ben Hutchings
2013-04-07 22:45 ` [28/74] usb: xhci: Fix TRB transfer length macro used for Event TRB Ben Hutchings
2013-04-07 22:45 ` [23/74] pnfs-block: removing DM device maybe cause oops when call dev_remove Ben Hutchings
2013-04-07 22:45 ` [22/74] sysfs: handle failure path correctly for readdir() Ben Hutchings
2013-04-07 22:45 ` [42/74] virtio: console: add locking around c_ovq operations Ben Hutchings
2013-04-07 22:45 ` [08/74] Bluetooth device 04ca:3008 should use ath3k Ben Hutchings
2013-04-07 22:45 ` [16/74] Bluetooth: Add support for Dell[QCA 0cf3:817a] Ben Hutchings
2013-04-07 22:45 ` [11/74] Bluetooth: Add support for Dell[QCA 0cf3:0036] Ben Hutchings
2013-04-07 22:45 ` [46/74] ixgbe: fix registration order of driver and DCA nofitication Ben Hutchings
2013-04-07 22:45 ` [50/74] NFS: nfs_getaclargs.acl_len is a size_t Ben Hutchings
2013-04-07 22:45 ` [30/74] nfsd4: reject "negative" acl lengths Ben Hutchings
2013-04-07 22:45 ` [21/74] sysfs: fix race between readdir and lseek Ben Hutchings
2013-04-07 22:45 ` [13/74] HID: usbhid: quirk for Realtek Multi-card reader Ben Hutchings
2013-04-07 22:45 ` [02/74] ASoC: imx-ssi: Fix occasional AC97 reset failure Ben Hutchings
2013-04-07 22:45 ` [12/74] tty: atmel_serial_probe(): index of atmel_ports[] fix Ben Hutchings
2013-04-07 22:45 ` [05/74] Bluetooth: Add support for GC-WB300D PCIe [04ca:3006] to ath3k Ben Hutchings
2013-04-07 22:45 ` [18/74] rtlwifi: usb: add missing freeing of skbuff Ben Hutchings
2013-04-07 22:45 ` [36/74] tg3: fix length overflow in VPD firmware parsing Ben Hutchings
2013-04-07 22:45 ` [15/74] HID: usbhid: fix build problem Ben Hutchings
2013-04-07 22:45 ` [37/74] Btrfs: limit the global reserve to 512mb Ben Hutchings
2013-04-07 22:45 ` [19/74] xen-blkback: fix dispatch_rw_block_io() error path Ben Hutchings
2013-04-07 22:45 ` [33/74] iommu/amd: Make sure dma_ops are set for hotplug devices Ben Hutchings
2013-04-07 22:45 ` [39/74] reiserfs: Fix warning and inode leak when deleting inode with xattrs Ben Hutchings
2013-04-07 22:45 ` [01/74] clockevents: Don't allow dummy broadcast timers Ben Hutchings
2013-04-07 22:45 ` [06/74] Bluetooth: Add support for Foxconn / Hon Hai [0489:e04e] Ben Hutchings
2013-04-07 22:45 ` [10/74] Bluetooth: Device 0cf3:3008 should map AR 3012 Ben Hutchings
2013-04-07 22:45 ` [20/74] net/irda: add missing error path release_sock call Ben Hutchings
2013-04-07 22:45 ` [48/74] key: Fix resource leak Ben Hutchings
2013-04-07 22:45 ` [41/74] virtio: console: rename cvq_lock to c_ivq_lock Ben Hutchings
2013-04-07 22:45 ` [03/74] UBIFS: make space fixup work in the remount case Ben Hutchings
2013-04-07 22:45 ` [35/74] b43: A fix for DMA transmission sequence errors Ben Hutchings
2013-04-07 22:45 ` [55/74] tcp: undo spurious timeout after SACK reneging Ben Hutchings
2013-04-07 22:45 ` Ben Hutchings [this message]
2013-04-07 22:45 ` [32/74] vt: synchronize_rcu() under spinlock is not nice Ben Hutchings
2013-04-07 22:45 ` [53/74] sky2: Threshold for Pause Packet is set wrong Ben Hutchings
2013-04-07 22:45 ` [45/74] mm: prevent mmap_cache race in find_vma() Ben Hutchings
2013-04-07 22:45 ` [25/74] ASoC: dma-sh7760: Fix compile error Ben Hutchings
2013-04-07 22:45 ` [54/74] tcp: preserve ACK clocking in TSO Ben Hutchings
2013-04-07 22:45 ` [09/74] Bluetooth: Add support for atheros 04ca:3004 device to ath3k Ben Hutchings
2013-04-07 22:45 ` [56/74] 8021q: fix a potential use-after-free Ben Hutchings
2013-04-07 22:45 ` [27/74] SUNRPC: Add barriers to ensure read ordering in rpc_wake_up_task_queue_locked Ben Hutchings
2013-04-07 22:45 ` [49/74] udf: Fix bitmap overflow on large filesystems with small block size Ben Hutchings
2013-04-07 22:45 ` [40/74] tile: expect new initramfs name from hypervisor file system Ben Hutchings
2013-04-07 22:45 ` [29/74] staging: comedi: s626: fix continuous acquisition Ben Hutchings
2013-04-07 22:45 ` [34/74] can: sja1000: fix define conflict on SH Ben Hutchings
2013-04-07 22:45 ` [04/74] Bluetooth: Add support for IMC Networks [13d3:3393] Ben Hutchings
2013-04-07 22:45 ` [07/74] Bluetooth: Add support for Foxconn / Hon Hai [0489:e056] Ben Hutchings
2013-04-07 22:45 ` [43/74] spi/mpc512x-psc: optionally keep PSC SS asserted across xfer segmensts Ben Hutchings
2013-04-07 22:45 ` [14/74] HID: usbhid: quirk for MSI GX680R led panel Ben Hutchings
2013-04-07 22:45 ` [47/74] rt2x00: error in configurations with mesh support disabled Ben Hutchings
2013-04-07 22:45 ` [26/74] IPoIB: Fix send lockup due to missed TX completion Ben Hutchings
2013-04-07 22:45 ` [24/74] NFSv4.1: Fix a race in pNFS layoutcommit Ben Hutchings
2013-04-07 22:45 ` [44/74] EISA/PCI: Init EISA early, before PNP Ben Hutchings
2013-04-07 22:45 ` [71/74] pch_gbe: fix ip_summed checksum reporting on rx Ben Hutchings
2013-04-07 22:45 ` [65/74] DM9000B: driver initialization upgrade Ben Hutchings
2013-04-07 22:45 ` [59/74] unix: fix a race condition in unix_release() Ben Hutchings
2013-04-07 22:45 ` [68/74] ipv6: don't accept node local multicast traffic from the wire Ben Hutchings
2013-04-07 22:45 ` [70/74] net: add a synchronize_net() in netdev_rx_handler_unregister() Ben Hutchings
2013-04-07 22:45 ` [69/74] ks8851: Fix interpretation of rxlen field Ben Hutchings
2013-04-07 22:45 ` [60/74] bonding: remove already created master sysfs link on failure Ben Hutchings
2013-04-07 22:45 ` [66/74] ipv6: don't accept multicast traffic with scope 0 Ben Hutchings
2013-04-07 22:45 ` [63/74] aoe: reserve enough headroom on skbs Ben Hutchings
2013-04-07 22:45 ` [61/74] bonding: fix disabling of arp_interval and miimon Ben Hutchings
2013-04-07 22:45 ` [72/74] smsc75xx: fix jumbo frame support Ben Hutchings
2013-04-07 22:45 ` [73/74] bonding: get netdev_rx_handler_unregister out of locks Ben Hutchings
2013-04-07 22:45 ` [64/74] atl1e: drop pci-msi support because of packet corruption Ben Hutchings
2013-04-07 22:45 ` [57/74] thermal: shorten too long mcast group name Ben Hutchings
2013-04-07 22:45 ` [62/74] drivers: net: ethernet: davinci_emac: use netif_wake_queue() while restarting tx queue Ben Hutchings
2013-04-07 22:45 ` [67/74] ipv6: fix bad free of addrconf_init_net Ben Hutchings
2013-04-07 22:45 ` [74/74] HID: microsoft: do not use compound literal - fix build Ben Hutchings
2013-04-07 22:45 ` [58/74] bonding: fix miimon and arp_interval delayed work race conditions Ben Hutchings

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=lsq.1365374742.832741758@decadent.org.uk \
    --to=ben@decadent.org.uk \
    --cc=akpm@linux-foundation.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=stable@vger.kernel.org \
    --cc=viro@zeniv.linux.org.uk \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®