From patchwork Thu Dec 30 14:54:11 2021 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Padmanabha Srinivasaiah X-Patchwork-Id: 12701489 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from bombadil.infradead.org (bombadil.infradead.org [198.137.202.133]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.lore.kernel.org (Postfix) with ESMTPS id 5FEA4C433F5 for ; Thu, 30 Dec 2021 14:59:04 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=lists.infradead.org; s=bombadil.20210309; h=Sender: Content-Transfer-Encoding:Content-Type:MIME-Version:List-Subscribe:List-Help: List-Post:List-Archive:List-Unsubscribe:List-Id:References:In-Reply-To: Message-Id:Date:Subject:Cc:To:From:Reply-To:Content-ID:Content-Description: Resent-Date:Resent-From:Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID: List-Owner; bh=/Drep2E7vkM0Wn2F8D7DbP0Ft7VnQLM4forrchcxJDg=; b=Yc0GluNv9nPETe m8U4iD1eEQtEA5MSCYiMn8SiA/+RwDd+ZCIvyd8u7Itl3cchXHbBY87NJKaMPprnJpNgJQx4hFvl6 4BVgda4pzJmTRbxnC3JcLvaK1xdOzxAOQJPW6zcFlpXfQ6ZZVFrmOg5DOcNoWBZkxFE40wqbYTLm1 bJXqBHl0vRo/NRpHqabGmuaCCEsAZr/5RWAEbkiMsUcsezC2d3ADE78MGpvX85uE3O/MCyxB0fxdH BMvdS2b0hlPXVuE02ixL1xZlsR6H10ZkFKethpCsTidMCOXlJsDPiGYgURa4nUw5sBlbToFWoTjJA wih4fI2tzLB4xTIX2sWQ==; Received: from localhost ([::1] helo=bombadil.infradead.org) by bombadil.infradead.org with esmtp (Exim 4.94.2 #2 (Red Hat Linux)) id 1n2wrA-004XeC-M2; Thu, 30 Dec 2021 14:56:40 +0000 Received: from mail-wm1-x332.google.com ([2a00:1450:4864:20::332]) by bombadil.infradead.org with esmtps (Exim 4.94.2 #2 (Red Hat Linux)) id 1n2wr7-004XcB-3y; Thu, 30 Dec 2021 14:56:38 +0000 Received: by mail-wm1-x332.google.com with SMTP id g132so15774975wmg.2; Thu, 30 Dec 2021 06:56:33 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20210112; h=from:to:cc:subject:date:message-id:in-reply-to:references; bh=JDmpSF45YcS1E3Eg1OsibbyFEleKy63whnxqUOdxM+E=; b=khdGs1JnrOKUM15e4EVNN3MlK1bDfnUDA7mIWNeLiouDoIIdNOhLuw0/BbYAmL7QL6 0nexo1aKPyo2juNavxS2QGdrR/ckNrDr4Vc1gYSGtyvSplaWjRuUZXPejg/vDECyn/V8 vCerTclSAa7dteafS93aZs7jdMudfGrbp8Jj4XQRLaffq9O7/IQEmjkcCQ9ckLZyijJf Bg64Ifxk+Q89kJIKZQOGAhHixYIsaN0jPJXLfbpkw9JNHbphA7X99OgL6ELL8bgXCeom ZdjgARvgY1ohY3E8sbyaIDyU7vqlB5G2wBp+u4W1yx6YOmhMp0qq2lASOpuI7XG0DdbE Scog== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20210112; h=x-gm-message-state:from:to:cc:subject:date:message-id:in-reply-to :references; bh=JDmpSF45YcS1E3Eg1OsibbyFEleKy63whnxqUOdxM+E=; b=d/YlRZ3cSyHrI0mhVZ0mAm0iwFcaSj8FN/x++zcPlLN+9MyDe7+LQfXflosSXKu4bE 8yHjUR4klEk8GcxMADdj4gr832co7ARgL3mi48JgEyvZoQ1N7Q38KjKgWfmfmEPhffXt FKr8ywJYlT+jYe1GZi1tl2YAnL5Dy0dfiioohFSuOhJgg88oJCV6wQ1Fx7+7ir3k8X5b c3N9xjscy4c8YRexCRyCfgNpSY3TmLqRjrQpKRsiA9dgH+CK/ePhZXsVaRMN7jqqPgBb gup5YmHbUIGtwqoQAJpSjA87pAk/Ll/EXRu+0vS0SGKUPEQ9ujk2+FY1dMhaix6pbCc0 O4hA== X-Gm-Message-State: AOAM533x/yaqm2yJHKa74gq0u7LqO9ukv9LlGa0K1ENru6TRS1bUrH70 f8NJAMRmzorUGzmukRFEUMdc3bsjswJrM+6Q X-Google-Smtp-Source: ABdhPJy5RxDepYYn0RG6O4bcZK03BLBuezi5xdz/C202ZMRpjK4y1jXrCU3Y048l4Dre1/Gu1p3NJw== X-Received: by 2002:a05:600c:4153:: with SMTP id h19mr26107175wmm.142.1640876191790; Thu, 30 Dec 2021 06:56:31 -0800 (PST) Received: from pswork.fritz.box (mue-88-130-61-102.dsl.tropolys.de. [88.130.61.102]) by smtp.gmail.com with ESMTPSA id d10sm26572238wri.57.2021.12.30.06.56.30 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 30 Dec 2021 06:56:31 -0800 (PST) From: Padmanabha Srinivasaiah To: linux-rpi-kernel@lists.infradead.org, linux-arm-kernel@lists.infradead.org, linux-staging@lists.linux.dev, linux-kernel@vger.kernel.org, stefan.wahren@i2se.com Cc: gregkh@linuxfoundation.org, nsaenz@kernel.org, treasure4paddy@gmail.com, Gaston Gonzalez , Ojaswin Mujoo , Arnd Bergmann , Phil Elwell , bcm-kernel-feedback-list@broadcom.com Subject: [PATCH v2] staging: vc04_services: Fix RCU dereference check Date: Thu, 30 Dec 2021 15:54:11 +0100 Message-Id: <20211230145415.11962-1-treasure4paddy@gmail.com> X-Mailer: git-send-email 2.17.1 In-Reply-To: <20211230133430.GA10256@pswork> References: <20211230133430.GA10256@pswork> X-CRM114-Version: 20100106-BlameMichelson ( TRE 0.8.0 (BSD) ) MR-646709E3 X-CRM114-CacheID: sfid-20211230_065637_185949_F867EB90 X-CRM114-Status: GOOD ( 10.43 ) X-BeenThere: linux-arm-kernel@lists.infradead.org X-Mailman-Version: 2.1.34 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , MIME-Version: 1.0 Sender: "linux-arm-kernel" Errors-To: linux-arm-kernel-bounces+linux-arm-kernel=archiver.kernel.org@lists.infradead.org In service_callback path RCU dereferenced pointer struct vchiq_service need to be accessed inside rcu read-critical section. Accessing same with rcu_read_[lock/unlock] fixes the issue. [ 32.201659] ============================= [ 32.201664] WARNING: suspicious RCU usage [ 32.201670] 5.15.11-rt24-v8+ #3 Not tainted [ 32.201680] ----------------------------- [ 32.201685] drivers/staging/vc04_services/interface/vchiq_arm/vchiq_core.h:529 suspicious rcu_dereference_check() usage! [ 32.201695] [ 32.201695] other info that might help us debug this: [ 32.201695] [ 32.201700] [ 32.201700] rcu_scheduler_active = 2, debug_locks = 1 [ 32.201708] no locks held by vchiq-slot/0/98. [ 32.201715] [ 32.201715] stack backtrace: [ 32.201723] CPU: 1 PID: 98 Comm: vchiq-slot/0 Not tainted 5.15.11-rt24-v8+ #3 [ 32.201733] Hardware name: Raspberry Pi 4 Model B Rev 1.4 (DT) [ 32.201739] Call trace: [ 32.201742] dump_backtrace+0x0/0x1b8 [ 32.201772] show_stack+0x20/0x30 [ 32.201784] dump_stack_lvl+0x8c/0xb8 [ 32.201799] dump_stack+0x18/0x34 [ 32.201808] lockdep_rcu_suspicious+0xe4/0xf8 [ 32.201817] service_callback+0x124/0x400 [ 32.201830] slot_handler_func+0xf60/0x1e20 [ 32.201839] kthread+0x19c/0x1a8 [ 32.201849] ret_from_fork+0x10/0x20 Signed-off-by: Padmanabha Srinivasaiah --- Changes in v2: RCU dereferenced pointer need to be accessed inside rcu read-side critical section. .../vc04_services/interface/vchiq_arm/vchiq_arm.c | 10 ++++++++-- 1 file changed, 8 insertions(+), 2 deletions(-) diff --git a/drivers/staging/vc04_services/interface/vchiq_arm/vchiq_arm.c b/drivers/staging/vc04_services/interface/vchiq_arm/vchiq_arm.c index 6759a6261500..8ddd400ab2c3 100644 --- a/drivers/staging/vc04_services/interface/vchiq_arm/vchiq_arm.c +++ b/drivers/staging/vc04_services/interface/vchiq_arm/vchiq_arm.c @@ -1053,24 +1053,30 @@ service_callback(enum vchiq_reason reason, struct vchiq_header *header, struct vchiq_service *service; struct vchiq_instance *instance; bool skip_completion = false; + unsigned int localport; DEBUG_INITIALISE(g_state.local); DEBUG_TRACE(SERVICE_CALLBACK_LINE); + rcu_read_lock(); service = handle_to_service(handle); - if (WARN_ON(!service)) + if (WARN_ON(!service)) { + rcu_read_unlock(); return VCHIQ_SUCCESS; + } user_service = (struct user_service *)service->base.userdata; instance = user_service->instance; + localport = service->localport; + rcu_read_unlock(); if (!instance || instance->closing) return VCHIQ_SUCCESS; vchiq_log_trace(vchiq_arm_log_level, "%s - service %lx(%d,%p), reason %d, header %lx, instance %lx, bulk_userdata %lx", - __func__, (unsigned long)user_service, service->localport, + __func__, (unsigned long)user_service, (int)localport, user_service->userdata, reason, (unsigned long)header, (unsigned long)instance, (unsigned long)bulk_userdata);