]> git.baikalelectronics.ru Git - kernel.git/commit
tracepoint: Fix use of tracepoint funcs after rcu free
authorMathieu Desnoyers <mathieu.desnoyers@efficios.com>
Thu, 8 May 2014 11:47:49 +0000 (07:47 -0400)
committerSteven Rostedt <rostedt@goodmis.org>
Thu, 8 May 2014 13:10:56 +0000 (09:10 -0400)
commit028f39aa4e1d1a20b99580c6f9bdf87c31c22c44
tree71172e9ae00c358e23e93c451f0b7dc45d98f436
parentf31aa5d808efb06e9c31bdf363927cd16e19df3e
tracepoint: Fix use of tracepoint funcs after rcu free

Commit 8943e93b926b "tracepoint: Use struct pointer instead of name hash
for reg/unreg tracepoints" introduces a use after free by calling
release_probes on the old struct tracepoint array before the newly
allocated array is published with rcu_assign_pointer. There is a race
window where tracepoints (RCU readers) can perform a
"use-after-grace-period-after-free", which shows up as a GPF in
stress-tests.

Link: http://lkml.kernel.org/r/53698021.5020108@oracle.com
Link: http://lkml.kernel.org/p/1399549669-25465-1-git-send-email-mathieu.desnoyers@efficios.com
Reported-by: Sasha Levin <sasha.levin@oracle.com>
CC: Oleg Nesterov <oleg@redhat.com>
CC: Dave Jones <davej@redhat.com>
Fixes: 8943e93b926b "tracepoint: Use struct pointer instead of name hash for reg/unreg tracepoints"
Signed-off-by: Mathieu Desnoyers <mathieu.desnoyers@efficios.com>
Signed-off-by: Steven Rostedt <rostedt@goodmis.org>
kernel/tracepoint.c