]> git.ipfire.org Git - thirdparty/kernel/stable.git/commitdiff
lib/generic-radix-tree.c: Fix rare race in __genradix_ptr_alloc()
authorKent Overstreet <kent.overstreet@linux.dev>
Sun, 11 Aug 2024 01:04:35 +0000 (21:04 -0400)
committerGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Thu, 12 Sep 2024 09:11:39 +0000 (11:11 +0200)
[ Upstream commit b2f11c6f3e1fc60742673b8675c95b78447f3dae ]

If we need to increase the tree depth, allocate a new node, and then
race with another thread that increased the tree depth before us, we'll
still have a preallocated node that might be used later.

If we then use that node for a new non-root node, it'll still have a
pointer to the old root instead of being zeroed - fix this by zeroing it
in the cmpxchg failure path.

Signed-off-by: Kent Overstreet <kent.overstreet@linux.dev>
Signed-off-by: Sasha Levin <sashal@kernel.org>
lib/generic-radix-tree.c

index 7dfa88282b006a408c7a6e77f69c17353b333301..78f081d695d0b79a52a1a49e46f851f3a3686754 100644 (file)
@@ -131,6 +131,8 @@ void *__genradix_ptr_alloc(struct __genradix *radix, size_t offset,
                if ((v = cmpxchg_release(&radix->root, r, new_root)) == r) {
                        v = new_root;
                        new_node = NULL;
+               } else {
+                       new_node->children[0] = NULL;
                }
        }