提交 5a60fc9d 编写于 作者: D Di Zhu 提交者: Zheng Zengkai

net: fix a data race when get vlan device

mainline inclusion
from mainline-v5.13-rc1
commit c1102e9d
category: bugfix
bugzilla: https://gitee.com/src-openeuler/kernel/issues/I4RJ4X
CVE: NA

----------------------------

We encountered a crash: in the packet receiving process, we got an
illegal VLAN device address, but the VLAN device address saved in vmcore
is correct. After checking the code, we found a possible data
competition:
CPU 0:                             CPU 1:
    (RCU read lock)                  (RTNL lock)
    vlan_do_receive()		       register_vlan_dev()
      vlan_find_dev()

        ->__vlan_group_get_device()	 ->vlan_group_prealloc_vid()

In vlan_group_prealloc_vid(), We need to make sure that memset()
in kzalloc() is executed before assigning  value to vlan devices array:
=================================
kzalloc()
    ->memset(object, 0, size)

smp_wmb()

vg->vlan_devices_arrays[pidx][vidx] = array;
==================================

Because __vlan_group_get_device() function depends on this order.
otherwise we may get a wrong address from the hardware cache on
another cpu.

So fix it by adding memory barrier instruction to ensure the order
of memory operations.
Signed-off-by: NDi Zhu <zhudi21@huawei.com>
Signed-off-by: NDavid S. Miller <davem@davemloft.net>
Reviewed-by: Nwuchangye <wuchangye@huawei.com>
Reviewed-by: NWei Yongjun <weiyongjun1@huawei.com>
Signed-off-by: NZheng Zengkai <zhengzengkai@huawei.com>
上级 b6461fe5
......@@ -71,6 +71,9 @@ static int vlan_group_prealloc_vid(struct vlan_group *vg,
if (array == NULL)
return -ENOBUFS;
/* paired with smp_rmb() in __vlan_group_get_device() */
smp_wmb();
vg->vlan_devices_arrays[pidx][vidx] = array;
return 0;
}
......
......@@ -57,6 +57,10 @@ static inline struct net_device *__vlan_group_get_device(struct vlan_group *vg,
array = vg->vlan_devices_arrays[pidx]
[vlan_id / VLAN_GROUP_ARRAY_PART_LEN];
/* paired with smp_wmb() in vlan_group_prealloc_vid() */
smp_rmb();
return array ? array[vlan_id % VLAN_GROUP_ARRAY_PART_LEN] : NULL;
}
......
Markdown is supported
0% .
You are about to add 0 people to the discussion. Proceed with caution.
先完成此消息的编辑!
想要评论请 注册