kernel/time/timer_migration.c | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-)
When tmigr_setup_groups() failed level 0 group allocation,
wrong reference happens on local stack array while intializing timer hierarchy.
To prevent this, Check loop condition first before initializing timer hierarchy.
Fixes: 7ee988770326 ("timers: Implement the hierarchical pull model")
Signed-off-by: Levi Yun <ppbuk5246@gmail.com>
---
v3:
- Fix typo.
v2:
- Modify commit message.
kernel/time/timer_migration.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/kernel/time/timer_migration.c b/kernel/time/timer_migration.c
index ccba875d2234..84413114db5c 100644
--- a/kernel/time/timer_migration.c
+++ b/kernel/time/timer_migration.c
@@ -1596,7 +1596,7 @@ static int tmigr_setup_groups(unsigned int cpu, unsigned int node)
} while (i < tmigr_hierarchy_levels);
- do {
+ while (i > 0) {
group = stack[--i];
if (err < 0) {
@@ -1645,7 +1645,7 @@ static int tmigr_setup_groups(unsigned int cpu, unsigned int node)
tmigr_connect_child_parent(child, group);
}
}
- } while (i > 0);
+ }
kfree(stack);
--
2.41.0
Le Mon, May 06, 2024 at 05:10:59AM +0100, Levi Yun a écrit : > When tmigr_setup_groups() failed level 0 group allocation, > wrong reference happens on local stack array while intializing timer hierarchy. > > To prevent this, Check loop condition first before initializing timer hierarchy. > > Fixes: 7ee988770326 ("timers: Implement the hierarchical pull model") > Signed-off-by: Levi Yun <ppbuk5246@gmail.com> > --- > v3: > - Fix typo. > > v2: > - Modify commit message. > > kernel/time/timer_migration.c | 4 ++-- > 1 file changed, 2 insertions(+), 2 deletions(-) > > diff --git a/kernel/time/timer_migration.c b/kernel/time/timer_migration.c > index ccba875d2234..84413114db5c 100644 > --- a/kernel/time/timer_migration.c > +++ b/kernel/time/timer_migration.c > @@ -1596,7 +1596,7 @@ static int tmigr_setup_groups(unsigned int cpu, unsigned int node) > > } while (i < tmigr_hierarchy_levels); > > - do { > + while (i > 0) { > group = stack[--i]; > > if (err < 0) { > @@ -1645,7 +1645,7 @@ static int tmigr_setup_groups(unsigned int cpu, unsigned int node) > tmigr_connect_child_parent(child, group); > } > } > - } while (i > 0); > + } Looks good to me. But let's wait for Anna-Maria's second look. The group setup is not my favourite area... Thanks. > > kfree(stack); > > -- > 2.41.0
Frederic Weisbecker <frederic@kernel.org> writes: > Le Mon, May 06, 2024 at 05:10:59AM +0100, Levi Yun a écrit : >> When tmigr_setup_groups() failed level 0 group allocation, >> wrong reference happens on local stack array while intializing timer hierarchy. >> >> To prevent this, Check loop condition first before initializing timer hierarchy. >> >> Fixes: 7ee988770326 ("timers: Implement the hierarchical pull model") >> Signed-off-by: Levi Yun <ppbuk5246@gmail.com> >> --- >> v3: >> - Fix typo. >> >> v2: >> - Modify commit message. >> >> kernel/time/timer_migration.c | 4 ++-- >> 1 file changed, 2 insertions(+), 2 deletions(-) >> >> diff --git a/kernel/time/timer_migration.c b/kernel/time/timer_migration.c >> index ccba875d2234..84413114db5c 100644 >> --- a/kernel/time/timer_migration.c >> +++ b/kernel/time/timer_migration.c >> @@ -1596,7 +1596,7 @@ static int tmigr_setup_groups(unsigned int cpu, unsigned int node) >> >> } while (i < tmigr_hierarchy_levels); >> >> - do { >> + while (i > 0) { >> group = stack[--i]; >> >> if (err < 0) { >> @@ -1645,7 +1645,7 @@ static int tmigr_setup_groups(unsigned int cpu, unsigned int node) >> tmigr_connect_child_parent(child, group); >> } >> } >> - } while (i > 0); >> + } > > Looks good to me. But let's wait for Anna-Maria's second look. The group setup > is not my favourite area... > Thanks for the fix! Reviewed-by: Anna-Maria Behnsen <anna-maria@linutronix.de>
… >>> To prevent this, Check loop condition first before initializing timer hierarchy. … >>> --- >>> v3: >>> - Fix typo. >>> >>> v2: >>> - Modify commit message. >>> >>> kernel/time/timer_migration.c | 4 ++-- … > Reviewed-by: Anna-Maria Behnsen <anna-maria@linutronix.de> Do you find any remaining wording concerns less relevant fur such a changelog? Regards, Markus
The following commit has been merged into the timers/urgent branch of tip:
Commit-ID: d7ad05c86e2191bd66e5b62fca8da53c4a53484f
Gitweb: https://git.kernel.org/tip/d7ad05c86e2191bd66e5b62fca8da53c4a53484f
Author: Levi Yun <ppbuk5246@gmail.com>
AuthorDate: Mon, 06 May 2024 05:10:59 +01:00
Committer: Thomas Gleixner <tglx@linutronix.de>
CommitterDate: Wed, 08 May 2024 11:19:43 +02:00
timers/migration: Prevent out of bounds access on failure
When tmigr_setup_groups() fails the level 0 group allocation, then the
cleanup derefences index -1 of the local stack array.
Prevent this by checking the loop condition first.
Fixes: 7ee988770326 ("timers: Implement the hierarchical pull model")
Signed-off-by: Levi Yun <ppbuk5246@gmail.com>
Signed-off-by: Thomas Gleixner <tglx@linutronix.de>
Reviewed-by: Anna-Maria Behnsen <anna-maria@linutronix.de>
Link: https://lore.kernel.org/r/20240506041059.86877-1-ppbuk5246@gmail.com
---
kernel/time/timer_migration.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/kernel/time/timer_migration.c b/kernel/time/timer_migration.c
index ccba875..8441311 100644
--- a/kernel/time/timer_migration.c
+++ b/kernel/time/timer_migration.c
@@ -1596,7 +1596,7 @@ static int tmigr_setup_groups(unsigned int cpu, unsigned int node)
} while (i < tmigr_hierarchy_levels);
- do {
+ while (i > 0) {
group = stack[--i];
if (err < 0) {
@@ -1645,7 +1645,7 @@ static int tmigr_setup_groups(unsigned int cpu, unsigned int node)
tmigr_connect_child_parent(child, group);
}
}
- } while (i > 0);
+ }
kfree(stack);
On Wed, May 08, 2024 at 09:45:41AM -0000, tip-bot2 for Levi Yun wrote: > The following commit has been merged into the timers/urgent branch of tip: (Yes, I noted above) ... > - do { > + while (i > 0) { > group = stack[--i]; Looking at this and most used patterns for cleanup loops, I would amend this to while (i--) { group = stack[i]; which seems to me an equivalent. > if (err < 0) { > @@ -1645,7 +1645,7 @@ static int tmigr_setup_groups(unsigned int cpu, unsigned int node) > tmigr_connect_child_parent(child, group); > } > } > - } while (i > 0); > + } -- With Best Regards, Andy Shevchenko
© 2016 - 2024 Red Hat, Inc.