]> git.ipfire.org Git - thirdparty/kernel/stable-queue.git/commitdiff
4.9-stable patches
authorGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Mon, 1 Mar 2021 14:22:37 +0000 (15:22 +0100)
committerGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Mon, 1 Mar 2021 14:22:37 +0000 (15:22 +0100)
added patches:
futex-fix-dead-code-in-attach_to_pi_owner.patch
futex-fix-owner_dead-fixup.patch

queue-4.9/futex-fix-dead-code-in-attach_to_pi_owner.patch [new file with mode: 0644]
queue-4.9/futex-fix-owner_dead-fixup.patch [new file with mode: 0644]
queue-4.9/series

diff --git a/queue-4.9/futex-fix-dead-code-in-attach_to_pi_owner.patch b/queue-4.9/futex-fix-dead-code-in-attach_to_pi_owner.patch
new file mode 100644 (file)
index 0000000..dc89159
--- /dev/null
@@ -0,0 +1,65 @@
+From nixiaoming@huawei.com  Mon Mar  1 15:17:04 2021
+From: Xiaoming Ni <nixiaoming@huawei.com>
+Date: Wed, 24 Feb 2021 18:09:23 +0800
+Subject: futex: fix dead code in attach_to_pi_owner()
+To: <linux-kernel@vger.kernel.org>, <stable@vger.kernel.org>, <gregkh@linuxfoundation.org>, <sashal@kernel.org>, <tglx@linutronix.de>, <lee.jones@linaro.org>
+Cc: <nixiaoming@huawei.com>, <wangle6@huawei.com>, <zhengyejian1@huawei.com>
+Message-ID: <20210224100923.51315-1-nixiaoming@huawei.com>
+
+From: Thomas Gleixner <tglx@linutronix.de>
+
+The handle_exit_race() function is defined in commit 9c3f39860367
+ ("futex: Cure exit race"), which never returns -EBUSY. This results
+in a small piece of dead code in the attach_to_pi_owner() function:
+
+       int ret = handle_exit_race(uaddr, uval, p); /* Never return -EBUSY */
+       ...
+       if (ret == -EBUSY)
+               *exiting = p; /* dead code */
+
+The return value -EBUSY is added to handle_exit_race() in upsteam
+commit ac31c7ff8624409 ("futex: Provide distinct return value when
+owner is exiting"). This commit was incorporated into v4.9.255, before
+the function handle_exit_race() was introduced, whitout Modify
+handle_exit_race().
+
+To fix dead code, extract the change of handle_exit_race() from
+commit ac31c7ff8624409 ("futex: Provide distinct return value when owner
+ is exiting"), re-incorporated.
+
+Lee writes:
+
+This commit takes the remaining functional snippet of:
+
+ ac31c7ff8624409 ("futex: Provide distinct return value when owner is exiting")
+
+... and is the correct fix for this issue.
+
+
+Fixes: 9c3f39860367 ("futex: Cure exit race")
+Cc: stable@vger.kernel.org # v4.9.258
+Signed-off-by: Xiaoming Ni <nixiaoming@huawei.com>
+Reviewed-by: Lee Jones <lee.jones@linaro.org>
+Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
+
+---
+ kernel/futex.c |    6 +++---
+ 1 file changed, 3 insertions(+), 3 deletions(-)
+
+--- a/kernel/futex.c
++++ b/kernel/futex.c
+@@ -1207,11 +1207,11 @@ static int handle_exit_race(u32 __user *
+       u32 uval2;
+       /*
+-       * If the futex exit state is not yet FUTEX_STATE_DEAD, wait
+-       * for it to finish.
++       * If the futex exit state is not yet FUTEX_STATE_DEAD, tell the
++       * caller that the alleged owner is busy.
+        */
+       if (tsk && tsk->futex_state != FUTEX_STATE_DEAD)
+-              return -EAGAIN;
++              return -EBUSY;
+       /*
+        * Reread the user space value to handle the following situation:
diff --git a/queue-4.9/futex-fix-owner_dead-fixup.patch b/queue-4.9/futex-fix-owner_dead-fixup.patch
new file mode 100644 (file)
index 0000000..7795b57
--- /dev/null
@@ -0,0 +1,59 @@
+From a97cb0e7b3f4c6297fd857055ae8e895f402f501 Mon Sep 17 00:00:00 2001
+From: Peter Zijlstra <peterz@infradead.org>
+Date: Mon, 22 Jan 2018 11:39:47 +0100
+Subject: futex: Fix OWNER_DEAD fixup
+
+From: Peter Zijlstra <peterz@infradead.org>
+
+commit a97cb0e7b3f4c6297fd857055ae8e895f402f501 upstream.
+
+Both Geert and DaveJ reported that the recent futex commit:
+
+  c1e2f0eaf015 ("futex: Avoid violating the 10th rule of futex")
+
+introduced a problem with setting OWNER_DEAD. We set the bit on an
+uninitialized variable and then entirely optimize it away as a
+dead-store.
+
+Move the setting of the bit to where it is more useful.
+
+Reported-by: Geert Uytterhoeven <geert@linux-m68k.org>
+Reported-by: Dave Jones <davej@codemonkey.org.uk>
+Signed-off-by: Peter Zijlstra (Intel) <peterz@infradead.org>
+Cc: Andrew Morton <akpm@linux-foundation.org>
+Cc: Linus Torvalds <torvalds@linux-foundation.org>
+Cc: Paul E. McKenney <paulmck@us.ibm.com>
+Cc: Peter Zijlstra <peterz@infradead.org>
+Cc: Thomas Gleixner <tglx@linutronix.de>
+Fixes: c1e2f0eaf015 ("futex: Avoid violating the 10th rule of futex")
+Link: http://lkml.kernel.org/r/20180122103947.GD2228@hirez.programming.kicks-ass.net
+Signed-off-by: Ingo Molnar <mingo@kernel.org>
+Reviewed-by: Lee Jones <lee.jones@linaro.org>
+Signed-off-by: Zheng Yejian <zhengyejian1@huawei.com>
+Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
+---
+ kernel/futex.c |    6 +++---
+ 1 file changed, 3 insertions(+), 3 deletions(-)
+
+--- a/kernel/futex.c
++++ b/kernel/futex.c
+@@ -2424,9 +2424,6 @@ static int __fixup_pi_state_owner(u32 __
+       int err = 0;
+       oldowner = pi_state->owner;
+-      /* Owner died? */
+-      if (!pi_state->owner)
+-              newtid |= FUTEX_OWNER_DIED;
+       /*
+        * We are here because either:
+@@ -2484,6 +2481,9 @@ retry:
+       }
+       newtid = task_pid_vnr(newowner) | FUTEX_WAITERS;
++      /* Owner died? */
++      if (!pi_state->owner)
++              newtid |= FUTEX_OWNER_DIED;
+       if (get_futex_value_locked(&uval, uaddr))
+               goto handle_fault;
index a460bd3388c8e24fe72bb7d13075a384d309605d..51153af48edde87d6f0f4b9de6c1c3636524c456 100644 (file)
@@ -123,3 +123,5 @@ dm-era-fix-bitset-memory-leaks.patch
 dm-era-use-correct-value-size-in-equality-function-of-writeset-tree.patch
 dm-era-reinitialize-bitset-cache-before-digesting-a-new-writeset.patch
 dm-era-only-resize-metadata-in-preresume.patch
+futex-fix-owner_dead-fixup.patch
+futex-fix-dead-code-in-attach_to_pi_owner.patch