Commit ca846a7a authored by Steven Rostedt (Red Hat)'s avatar Steven Rostedt (Red Hat) Committed by Jiri Slaby

ring-buffer: Check if buffer exists before polling

commit 8b8b3683 upstream.

The per_cpu buffers are created one per possible CPU. But these do
not mean that those CPUs are online, nor do they even exist.

With the addition of the ring buffer polling, it assumes that the
caller polls on an existing buffer. But this is not the case if
the user reads trace_pipe from a CPU that does not exist, and this
causes the kernel to crash.

Simple fix is to check the cpu against buffer bitmask against to see
if the buffer was allocated or not and return -ENODEV if it is
not.

More updates were done to pass the -ENODEV back up to userspace.

Link: http://lkml.kernel.org/r/5393DB61.6060707@oracle.comReported-by: default avatarSasha Levin <sasha.levin@oracle.com>
Signed-off-by: default avatarSteven Rostedt <rostedt@goodmis.org>
Signed-off-by: default avatarJiri Slaby <jslaby@suse.cz>
parent 378005bb
...@@ -97,7 +97,7 @@ __ring_buffer_alloc(unsigned long size, unsigned flags, struct lock_class_key *k ...@@ -97,7 +97,7 @@ __ring_buffer_alloc(unsigned long size, unsigned flags, struct lock_class_key *k
__ring_buffer_alloc((size), (flags), &__key); \ __ring_buffer_alloc((size), (flags), &__key); \
}) })
void ring_buffer_wait(struct ring_buffer *buffer, int cpu); int ring_buffer_wait(struct ring_buffer *buffer, int cpu);
int ring_buffer_poll_wait(struct ring_buffer *buffer, int cpu, int ring_buffer_poll_wait(struct ring_buffer *buffer, int cpu,
struct file *filp, poll_table *poll_table); struct file *filp, poll_table *poll_table);
......
...@@ -543,7 +543,7 @@ static void rb_wake_up_waiters(struct irq_work *work) ...@@ -543,7 +543,7 @@ static void rb_wake_up_waiters(struct irq_work *work)
* as data is added to any of the @buffer's cpu buffers. Otherwise * as data is added to any of the @buffer's cpu buffers. Otherwise
* it will wait for data to be added to a specific cpu buffer. * it will wait for data to be added to a specific cpu buffer.
*/ */
void ring_buffer_wait(struct ring_buffer *buffer, int cpu) int ring_buffer_wait(struct ring_buffer *buffer, int cpu)
{ {
struct ring_buffer_per_cpu *cpu_buffer; struct ring_buffer_per_cpu *cpu_buffer;
DEFINE_WAIT(wait); DEFINE_WAIT(wait);
...@@ -557,6 +557,8 @@ void ring_buffer_wait(struct ring_buffer *buffer, int cpu) ...@@ -557,6 +557,8 @@ void ring_buffer_wait(struct ring_buffer *buffer, int cpu)
if (cpu == RING_BUFFER_ALL_CPUS) if (cpu == RING_BUFFER_ALL_CPUS)
work = &buffer->irq_work; work = &buffer->irq_work;
else { else {
if (!cpumask_test_cpu(cpu, buffer->cpumask))
return -ENODEV;
cpu_buffer = buffer->buffers[cpu]; cpu_buffer = buffer->buffers[cpu];
work = &cpu_buffer->irq_work; work = &cpu_buffer->irq_work;
} }
...@@ -591,6 +593,7 @@ void ring_buffer_wait(struct ring_buffer *buffer, int cpu) ...@@ -591,6 +593,7 @@ void ring_buffer_wait(struct ring_buffer *buffer, int cpu)
schedule(); schedule();
finish_wait(&work->waiters, &wait); finish_wait(&work->waiters, &wait);
return 0;
} }
/** /**
......
...@@ -1044,13 +1044,13 @@ update_max_tr_single(struct trace_array *tr, struct task_struct *tsk, int cpu) ...@@ -1044,13 +1044,13 @@ update_max_tr_single(struct trace_array *tr, struct task_struct *tsk, int cpu)
} }
#endif /* CONFIG_TRACER_MAX_TRACE */ #endif /* CONFIG_TRACER_MAX_TRACE */
static void default_wait_pipe(struct trace_iterator *iter) static int default_wait_pipe(struct trace_iterator *iter)
{ {
/* Iterators are static, they should be filled or empty */ /* Iterators are static, they should be filled or empty */
if (trace_buffer_iter(iter, iter->cpu_file)) if (trace_buffer_iter(iter, iter->cpu_file))
return; return 0;
ring_buffer_wait(iter->trace_buffer->buffer, iter->cpu_file); return ring_buffer_wait(iter->trace_buffer->buffer, iter->cpu_file);
} }
#ifdef CONFIG_FTRACE_STARTUP_TEST #ifdef CONFIG_FTRACE_STARTUP_TEST
...@@ -4059,17 +4059,19 @@ tracing_poll_pipe(struct file *filp, poll_table *poll_table) ...@@ -4059,17 +4059,19 @@ tracing_poll_pipe(struct file *filp, poll_table *poll_table)
* *
* Anyway, this is really very primitive wakeup. * Anyway, this is really very primitive wakeup.
*/ */
void poll_wait_pipe(struct trace_iterator *iter) int poll_wait_pipe(struct trace_iterator *iter)
{ {
set_current_state(TASK_INTERRUPTIBLE); set_current_state(TASK_INTERRUPTIBLE);
/* sleep for 100 msecs, and try again. */ /* sleep for 100 msecs, and try again. */
schedule_timeout(HZ / 10); schedule_timeout(HZ / 10);
return 0;
} }
/* Must be called with trace_types_lock mutex held. */ /* Must be called with trace_types_lock mutex held. */
static int tracing_wait_pipe(struct file *filp) static int tracing_wait_pipe(struct file *filp)
{ {
struct trace_iterator *iter = filp->private_data; struct trace_iterator *iter = filp->private_data;
int ret;
while (trace_empty(iter)) { while (trace_empty(iter)) {
...@@ -4079,10 +4081,13 @@ static int tracing_wait_pipe(struct file *filp) ...@@ -4079,10 +4081,13 @@ static int tracing_wait_pipe(struct file *filp)
mutex_unlock(&iter->mutex); mutex_unlock(&iter->mutex);
iter->trace->wait_pipe(iter); ret = iter->trace->wait_pipe(iter);
mutex_lock(&iter->mutex); mutex_lock(&iter->mutex);
if (ret)
return ret;
if (signal_pending(current)) if (signal_pending(current))
return -EINTR; return -EINTR;
...@@ -5016,8 +5021,12 @@ tracing_buffers_read(struct file *filp, char __user *ubuf, ...@@ -5016,8 +5021,12 @@ tracing_buffers_read(struct file *filp, char __user *ubuf,
goto out_unlock; goto out_unlock;
} }
mutex_unlock(&trace_types_lock); mutex_unlock(&trace_types_lock);
iter->trace->wait_pipe(iter); ret = iter->trace->wait_pipe(iter);
mutex_lock(&trace_types_lock); mutex_lock(&trace_types_lock);
if (ret) {
size = ret;
goto out_unlock;
}
if (signal_pending(current)) { if (signal_pending(current)) {
size = -EINTR; size = -EINTR;
goto out_unlock; goto out_unlock;
...@@ -5229,8 +5238,10 @@ tracing_buffers_splice_read(struct file *file, loff_t *ppos, ...@@ -5229,8 +5238,10 @@ tracing_buffers_splice_read(struct file *file, loff_t *ppos,
goto out; goto out;
} }
mutex_unlock(&trace_types_lock); mutex_unlock(&trace_types_lock);
iter->trace->wait_pipe(iter); ret = iter->trace->wait_pipe(iter);
mutex_lock(&trace_types_lock); mutex_lock(&trace_types_lock);
if (ret)
goto out;
if (signal_pending(current)) { if (signal_pending(current)) {
ret = -EINTR; ret = -EINTR;
goto out; goto out;
......
...@@ -334,7 +334,7 @@ struct tracer { ...@@ -334,7 +334,7 @@ struct tracer {
void (*stop)(struct trace_array *tr); void (*stop)(struct trace_array *tr);
void (*open)(struct trace_iterator *iter); void (*open)(struct trace_iterator *iter);
void (*pipe_open)(struct trace_iterator *iter); void (*pipe_open)(struct trace_iterator *iter);
void (*wait_pipe)(struct trace_iterator *iter); int (*wait_pipe)(struct trace_iterator *iter);
void (*close)(struct trace_iterator *iter); void (*close)(struct trace_iterator *iter);
void (*pipe_close)(struct trace_iterator *iter); void (*pipe_close)(struct trace_iterator *iter);
ssize_t (*read)(struct trace_iterator *iter, ssize_t (*read)(struct trace_iterator *iter,
...@@ -549,7 +549,7 @@ void trace_init_global_iter(struct trace_iterator *iter); ...@@ -549,7 +549,7 @@ void trace_init_global_iter(struct trace_iterator *iter);
void tracing_iter_reset(struct trace_iterator *iter, int cpu); void tracing_iter_reset(struct trace_iterator *iter, int cpu);
void poll_wait_pipe(struct trace_iterator *iter); int poll_wait_pipe(struct trace_iterator *iter);
void tracing_sched_switch_trace(struct trace_array *tr, void tracing_sched_switch_trace(struct trace_array *tr,
struct task_struct *prev, struct task_struct *prev,
......
Markdown is supported
0%
or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment