From 39b942cb2a3b8b8aa30f93488ae2993f192eb962 Mon Sep 17 00:00:00 2001 From: Greg Kroah-Hartman Date: Mon, 1 Mar 2021 15:22:37 +0100 Subject: [PATCH] 4.9-stable patches added patches: futex-fix-dead-code-in-attach_to_pi_owner.patch futex-fix-owner_dead-fixup.patch --- ...-fix-dead-code-in-attach_to_pi_owner.patch | 65 +++++++++++++++++++ queue-4.9/futex-fix-owner_dead-fixup.patch | 59 +++++++++++++++++ queue-4.9/series | 2 + 3 files changed, 126 insertions(+) create mode 100644 queue-4.9/futex-fix-dead-code-in-attach_to_pi_owner.patch create mode 100644 queue-4.9/futex-fix-owner_dead-fixup.patch diff --git a/queue-4.9/futex-fix-dead-code-in-attach_to_pi_owner.patch b/queue-4.9/futex-fix-dead-code-in-attach_to_pi_owner.patch new file mode 100644 index 00000000000..dc891593a5c --- /dev/null +++ b/queue-4.9/futex-fix-dead-code-in-attach_to_pi_owner.patch @@ -0,0 +1,65 @@ +From nixiaoming@huawei.com Mon Mar 1 15:17:04 2021 +From: Xiaoming Ni +Date: Wed, 24 Feb 2021 18:09:23 +0800 +Subject: futex: fix dead code in attach_to_pi_owner() +To: , , , , , +Cc: , , +Message-ID: <20210224100923.51315-1-nixiaoming@huawei.com> + +From: Thomas Gleixner + +The handle_exit_race() function is defined in commit 9c3f39860367 + ("futex: Cure exit race"), which never returns -EBUSY. This results +in a small piece of dead code in the attach_to_pi_owner() function: + + int ret = handle_exit_race(uaddr, uval, p); /* Never return -EBUSY */ + ... + if (ret == -EBUSY) + *exiting = p; /* dead code */ + +The return value -EBUSY is added to handle_exit_race() in upsteam +commit ac31c7ff8624409 ("futex: Provide distinct return value when +owner is exiting"). This commit was incorporated into v4.9.255, before +the function handle_exit_race() was introduced, whitout Modify +handle_exit_race(). + +To fix dead code, extract the change of handle_exit_race() from +commit ac31c7ff8624409 ("futex: Provide distinct return value when owner + is exiting"), re-incorporated. + +Lee writes: + +This commit takes the remaining functional snippet of: + + ac31c7ff8624409 ("futex: Provide distinct return value when owner is exiting") + +... and is the correct fix for this issue. + + +Fixes: 9c3f39860367 ("futex: Cure exit race") +Cc: stable@vger.kernel.org # v4.9.258 +Signed-off-by: Xiaoming Ni +Reviewed-by: Lee Jones +Signed-off-by: Greg Kroah-Hartman + +--- + kernel/futex.c | 6 +++--- + 1 file changed, 3 insertions(+), 3 deletions(-) + +--- a/kernel/futex.c ++++ b/kernel/futex.c +@@ -1207,11 +1207,11 @@ static int handle_exit_race(u32 __user * + u32 uval2; + + /* +- * If the futex exit state is not yet FUTEX_STATE_DEAD, wait +- * for it to finish. ++ * If the futex exit state is not yet FUTEX_STATE_DEAD, tell the ++ * caller that the alleged owner is busy. + */ + if (tsk && tsk->futex_state != FUTEX_STATE_DEAD) +- return -EAGAIN; ++ return -EBUSY; + + /* + * Reread the user space value to handle the following situation: diff --git a/queue-4.9/futex-fix-owner_dead-fixup.patch b/queue-4.9/futex-fix-owner_dead-fixup.patch new file mode 100644 index 00000000000..7795b578f08 --- /dev/null +++ b/queue-4.9/futex-fix-owner_dead-fixup.patch @@ -0,0 +1,59 @@ +From a97cb0e7b3f4c6297fd857055ae8e895f402f501 Mon Sep 17 00:00:00 2001 +From: Peter Zijlstra +Date: Mon, 22 Jan 2018 11:39:47 +0100 +Subject: futex: Fix OWNER_DEAD fixup + +From: Peter Zijlstra + +commit a97cb0e7b3f4c6297fd857055ae8e895f402f501 upstream. + +Both Geert and DaveJ reported that the recent futex commit: + + c1e2f0eaf015 ("futex: Avoid violating the 10th rule of futex") + +introduced a problem with setting OWNER_DEAD. We set the bit on an +uninitialized variable and then entirely optimize it away as a +dead-store. + +Move the setting of the bit to where it is more useful. + +Reported-by: Geert Uytterhoeven +Reported-by: Dave Jones +Signed-off-by: Peter Zijlstra (Intel) +Cc: Andrew Morton +Cc: Linus Torvalds +Cc: Paul E. McKenney +Cc: Peter Zijlstra +Cc: Thomas Gleixner +Fixes: c1e2f0eaf015 ("futex: Avoid violating the 10th rule of futex") +Link: http://lkml.kernel.org/r/20180122103947.GD2228@hirez.programming.kicks-ass.net +Signed-off-by: Ingo Molnar +Reviewed-by: Lee Jones +Signed-off-by: Zheng Yejian +Signed-off-by: Greg Kroah-Hartman +--- + kernel/futex.c | 6 +++--- + 1 file changed, 3 insertions(+), 3 deletions(-) + +--- a/kernel/futex.c ++++ b/kernel/futex.c +@@ -2424,9 +2424,6 @@ static int __fixup_pi_state_owner(u32 __ + int err = 0; + + oldowner = pi_state->owner; +- /* Owner died? */ +- if (!pi_state->owner) +- newtid |= FUTEX_OWNER_DIED; + + /* + * We are here because either: +@@ -2484,6 +2481,9 @@ retry: + } + + newtid = task_pid_vnr(newowner) | FUTEX_WAITERS; ++ /* Owner died? */ ++ if (!pi_state->owner) ++ newtid |= FUTEX_OWNER_DIED; + + if (get_futex_value_locked(&uval, uaddr)) + goto handle_fault; diff --git a/queue-4.9/series b/queue-4.9/series index a460bd3388c..51153af48ed 100644 --- a/queue-4.9/series +++ b/queue-4.9/series @@ -123,3 +123,5 @@ dm-era-fix-bitset-memory-leaks.patch dm-era-use-correct-value-size-in-equality-function-of-writeset-tree.patch dm-era-reinitialize-bitset-cache-before-digesting-a-new-writeset.patch dm-era-only-resize-metadata-in-preresume.patch +futex-fix-owner_dead-fixup.patch +futex-fix-dead-code-in-attach_to_pi_owner.patch -- 2.47.3