提交 f2edf457 编写于 作者: Z Zhizhou Zhang 提交者: Xie XiuQi

tee: optee: avoid possible double list_del()

[ Upstream commit b2d102bd0146d9eb1fa630ca0cd19a15ef2f74c8 ]

This bug occurs when:

- a new request arrives, one thread(let's call it A) is pending in
  optee_supp_req() with req->busy is initial value false.

- tee-supplicant is killed, then optee_supp_release() is called, this
  function calls list_del(&req->link), and set supp->ctx to NULL. And
  it also wake up process A.

- process A continues, it firstly checks supp->ctx which is NULL,
  then checks req->busy which is false, at last run list_del(&req->link).
  This triggers double list_del() and results kernel panic.

For solve this problem, we rename req->busy to req->in_queue, and
associate it with state of whether req is linked to supp->reqs. So we
can just only check req->in_queue to make decision calling list_del()
or not.
Signed-off-by: NZhizhou Zhang <zhizhouzhang@asrmicro.com>
Signed-off-by: NJens Wiklander <jens.wiklander@linaro.org>
Signed-off-by: NSasha Levin <sashal@kernel.org>
Signed-off-by: NYang Yingliang <yangyingliang@huawei.com>
上级 cb3d768a
...@@ -19,7 +19,7 @@ ...@@ -19,7 +19,7 @@
struct optee_supp_req { struct optee_supp_req {
struct list_head link; struct list_head link;
bool busy; bool in_queue;
u32 func; u32 func;
u32 ret; u32 ret;
size_t num_params; size_t num_params;
...@@ -54,7 +54,6 @@ void optee_supp_release(struct optee_supp *supp) ...@@ -54,7 +54,6 @@ void optee_supp_release(struct optee_supp *supp)
/* Abort all request retrieved by supplicant */ /* Abort all request retrieved by supplicant */
idr_for_each_entry(&supp->idr, req, id) { idr_for_each_entry(&supp->idr, req, id) {
req->busy = false;
idr_remove(&supp->idr, id); idr_remove(&supp->idr, id);
req->ret = TEEC_ERROR_COMMUNICATION; req->ret = TEEC_ERROR_COMMUNICATION;
complete(&req->c); complete(&req->c);
...@@ -63,6 +62,7 @@ void optee_supp_release(struct optee_supp *supp) ...@@ -63,6 +62,7 @@ void optee_supp_release(struct optee_supp *supp)
/* Abort all queued requests */ /* Abort all queued requests */
list_for_each_entry_safe(req, req_tmp, &supp->reqs, link) { list_for_each_entry_safe(req, req_tmp, &supp->reqs, link) {
list_del(&req->link); list_del(&req->link);
req->in_queue = false;
req->ret = TEEC_ERROR_COMMUNICATION; req->ret = TEEC_ERROR_COMMUNICATION;
complete(&req->c); complete(&req->c);
} }
...@@ -103,6 +103,7 @@ u32 optee_supp_thrd_req(struct tee_context *ctx, u32 func, size_t num_params, ...@@ -103,6 +103,7 @@ u32 optee_supp_thrd_req(struct tee_context *ctx, u32 func, size_t num_params,
/* Insert the request in the request list */ /* Insert the request in the request list */
mutex_lock(&supp->mutex); mutex_lock(&supp->mutex);
list_add_tail(&req->link, &supp->reqs); list_add_tail(&req->link, &supp->reqs);
req->in_queue = true;
mutex_unlock(&supp->mutex); mutex_unlock(&supp->mutex);
/* Tell an eventual waiter there's a new request */ /* Tell an eventual waiter there's a new request */
...@@ -130,9 +131,10 @@ u32 optee_supp_thrd_req(struct tee_context *ctx, u32 func, size_t num_params, ...@@ -130,9 +131,10 @@ u32 optee_supp_thrd_req(struct tee_context *ctx, u32 func, size_t num_params,
* will serve all requests in a timely manner and * will serve all requests in a timely manner and
* interrupting then wouldn't make sense. * interrupting then wouldn't make sense.
*/ */
interruptable = !req->busy; if (req->in_queue) {
if (!req->busy)
list_del(&req->link); list_del(&req->link);
req->in_queue = false;
}
} }
mutex_unlock(&supp->mutex); mutex_unlock(&supp->mutex);
...@@ -176,7 +178,7 @@ static struct optee_supp_req *supp_pop_entry(struct optee_supp *supp, ...@@ -176,7 +178,7 @@ static struct optee_supp_req *supp_pop_entry(struct optee_supp *supp,
return ERR_PTR(-ENOMEM); return ERR_PTR(-ENOMEM);
list_del(&req->link); list_del(&req->link);
req->busy = true; req->in_queue = false;
return req; return req;
} }
...@@ -318,7 +320,6 @@ static struct optee_supp_req *supp_pop_req(struct optee_supp *supp, ...@@ -318,7 +320,6 @@ static struct optee_supp_req *supp_pop_req(struct optee_supp *supp,
if ((num_params - nm) != req->num_params) if ((num_params - nm) != req->num_params)
return ERR_PTR(-EINVAL); return ERR_PTR(-EINVAL);
req->busy = false;
idr_remove(&supp->idr, id); idr_remove(&supp->idr, id);
supp->req_id = -1; supp->req_id = -1;
*num_meta = nm; *num_meta = nm;
......
Markdown is supported
0% .
You are about to add 0 people to the discussion. Proceed with caution.
先完成此消息的编辑!
想要评论请 注册