• Eric Dumazet's avatar
    tun: switch to u64_stats_t · 5260dd3e
    Eric Dumazet authored
    In order to fix this data-race found by KCSAN [1],
    switch to u64_stats_t helpers. They provide all
    the needed annotations, without adding extra cost.
    
    [1]
    BUG: KCSAN: data-race in tun_get_user / tun_net_get_stats64
    
    read to 0xffffe8ffffd8aca8 of 8 bytes by task 4882 on cpu 0:
     tun_net_get_stats64+0x9b/0x230 drivers/net/tun.c:1171
     dev_get_stats+0x89/0x1e0 net/core/dev.c:9103
     rtnl_fill_stats+0x56/0x370 net/core/rtnetlink.c:1177
     rtnl_fill_ifinfo+0xd3b/0x2100 net/core/rtnetlink.c:1667
     rtmsg_ifinfo_build_skb+0xb0/0x150 net/core/rtnetlink.c:3472
     rtmsg_ifinfo_event.part.0+0x4e/0xb0 net/core/rtnetlink.c:3504
     rtmsg_ifinfo_event net/core/rtnetlink.c:3515 [inline]
     rtmsg_ifinfo+0x85/0x90 net/core/rtnetlink.c:3513
     __dev_notify_flags+0x18b/0x200 net/core/dev.c:7649
     dev_change_flags+0xb8/0xe0 net/core/dev.c:7691
     dev_ifsioc+0x201/0x6a0 net/core/dev_ioctl.c:237
     dev_ioctl+0x149/0x660 net/core/dev_ioctl.c:489
     sock_do_ioctl+0xdb/0x230 net/socket.c:1061
     sock_ioctl+0x3a3/0x5e0 net/socket.c:1189
     vfs_ioctl fs/ioctl.c:46 [inline]
     file_ioctl fs/ioctl.c:509 [inline]
     do_vfs_ioctl+0x991/0xc60 fs/ioctl.c:696
    
    write to 0xffffe8ffffd8aca8 of 8 bytes by task 4883 on cpu 1:
     tun_get_user+0x1d94/0x2ba0 drivers/net/tun.c:2002
     tun_chr_write_iter+0x79/0xd0 drivers/net/tun.c:2022
     call_write_iter include/linux/fs.h:1895 [inline]
     new_sync_write+0x388/0x4a0 fs/read_write.c:483
     __vfs_write+0xb1/0xc0 fs/read_write.c:496
     __kernel_write+0xb8/0x240 fs/read_write.c:515
     write_pipe_buf+0xb6/0xf0 fs/splice.c:794
     splice_from_pipe_feed fs/splice.c:500 [inline]
     __splice_from_pipe+0x248/0x480 fs/splice.c:624
     splice_from_pipe+0xbb/0x100 fs/splice.c:659
     default_file_splice_write+0x45/0x90 fs/splice.c:806
     do_splice_from fs/splice.c:848 [inline]
     direct_splice_actor+0xa0/0xc0 fs/splice.c:1020
     splice_direct_to_actor+0x215/0x510 fs/splice.c:975
     do_splice_direct+0x161/0x1e0 fs/splice.c:1063
     do_sendfile+0x384/0x7f0 fs/read_write.c:1464
    
    Reported by Kernel Concurrency Sanitizer on:
    CPU: 1 PID: 4883 Comm: syz-executor.1 Not tainted 5.4.0-rc3+ #0
    Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 01/01/2011
    Signed-off-by: default avatarEric Dumazet <edumazet@google.com>
    Signed-off-by: default avatarDavid S. Miller <davem@davemloft.net>
    5260dd3e
tun.c 86.3 KB