Received: by 2002:a05:6358:d09b:b0:dc:cd0c:909e with SMTP id jc27csp398861rwb; Tue, 13 Dec 2022 19:42:30 -0800 (PST) X-Google-Smtp-Source: AA0mqf5wBctsNMZc7a0JoSPJ17a4LRKNxS9r3ZPnqHWRhWHRe0qB1WUBrswddRTZ3AIgaSFwrd6M X-Received: by 2002:a17:906:b289:b0:7c0:dac7:36dc with SMTP id q9-20020a170906b28900b007c0dac736dcmr178006ejz.46.1670989350442; Tue, 13 Dec 2022 19:42:30 -0800 (PST) ARC-Seal: i=1; a=rsa-sha256; t=1670989350; cv=none; d=google.com; s=arc-20160816; b=wfTmSIC7z/zPCerSbERHaWR+J7Jb4YEMlh6HQ/G/6QMPNnvX+Z+NWmzJ7Yd3vfQOhP SWPiGbwukoyMk/snr5RtzZiQzarBq5v1Z9iEyRv2uQrUl4cvJsxAO8UJTFuQWcBtDdan dxxvNZs8TMBfHZMgciSEBOTiHlTK8Gc8gAjXQ2TjylGRIJl1Wa8z8crHIefF9IcLvB7l FXgLxhVQkrbP6a20G0TQhvviOh5IhTpFoEkPY/Q+PcAHzo7iOpudZz1nejk0//PAQdkK 0YNX8C4IseRAX67Q6QW1PenqJZp5jGzvNyv34CFBh4RzKKgTiCLLCKFRxY6I704qUqCm m0nQ== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:mime-version:message-id:in-reply-to:date:subject :cc:to:from:user-agent:references:dkim-signature; bh=zjoUL1OFj4FUNqJzzW9IevB/AH024BCp8wmz9LscwDA=; b=nQ98dIKAbsXSIQu9L2M8/gzgnkCjL2Vw7cD2uVhy856zWLY7UCNQ8MGcW+EwN716tX jVEeLRv4ZiN4eMhTtgJdqnvRJ3ry08IqVp4Li5odljvXnrtrjgD9b0nv5zDErOT6o/Ud /aEBIAwvt1YMW/IZL6qdcVHSEqmq+PZa+z+QRsslA/LU9V2KNmeRBqH2pTjYHBms4+Td uB31bNup4TmgJlch8nuyn70a6hkQMtcujPgV0sd6rBnnkqTntsB0g6IfE2ZCB1jVpEVR cVYvw0f+yXyV20TZF/CokiYqDz0H4wx2guOXuTi8+9v7Dz825w6wE9wB/UDGgEEUSA1W S7oQ== ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@gmail.com header.s=20210112 header.b=Bg2FP3HI; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=NONE sp=QUARANTINE dis=NONE) header.from=gmail.com Return-Path: Received: from out1.vger.email (out1.vger.email. [2620:137:e000::1:20]) by mx.google.com with ESMTP id js14-20020a17090797ce00b0078d805901b1si11006233ejc.489.2022.12.13.19.42.13; Tue, 13 Dec 2022 19:42:30 -0800 (PST) Received-SPF: pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) client-ip=2620:137:e000::1:20; Authentication-Results: mx.google.com; dkim=pass header.i=@gmail.com header.s=20210112 header.b=Bg2FP3HI; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=NONE sp=QUARANTINE dis=NONE) header.from=gmail.com Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S236745AbiLNDRO (ORCPT + 71 others); Tue, 13 Dec 2022 22:17:14 -0500 Received: from lindbergh.monkeyblade.net ([23.128.96.19]:60112 "EHLO lindbergh.monkeyblade.net" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S237285AbiLNDRC (ORCPT ); Tue, 13 Dec 2022 22:17:02 -0500 Received: from mail-pl1-x62b.google.com (mail-pl1-x62b.google.com [IPv6:2607:f8b0:4864:20::62b]) by lindbergh.monkeyblade.net (Postfix) with ESMTPS id 531C027B16 for ; Tue, 13 Dec 2022 19:17:00 -0800 (PST) Received: by mail-pl1-x62b.google.com with SMTP id g10so1966798plo.11 for ; Tue, 13 Dec 2022 19:17:00 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20210112; h=mime-version:message-id:in-reply-to:date:subject:cc:to:from :user-agent:references:from:to:cc:subject:date:message-id:reply-to; bh=zjoUL1OFj4FUNqJzzW9IevB/AH024BCp8wmz9LscwDA=; b=Bg2FP3HI+WEXQvFSI0TqRDR4m1oL6bTW0FrDv+c06vvkLtYqiPJUmZJOJY2IMmpDYc yXF9WSsfJFZ4TmnRaKa9iPxJs+F9fa8zvzoMt56jjv5GEo8FeuedhMqnveEOPS0H45xF h6gy3Jvx/IX4vtLEw5bgy8x7gV8C6DNdcLW63QrZTuifecsh8DcXZNEXxNpWT3ubHbg3 zhbz/ILvgzd4clijyw47zUgkuPYbpjd0sTL275TrBb1IkI5D5Cn+h6MElaLkd1JK4qOi JliqwHIwsfx819pNkqf0AGpV50Ph7FIdWiBi2XPnhyrD0D4BqVz8Qzp7RHtsIhxM+he/ AEZg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20210112; h=mime-version:message-id:in-reply-to:date:subject:cc:to:from :user-agent:references:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to; bh=zjoUL1OFj4FUNqJzzW9IevB/AH024BCp8wmz9LscwDA=; b=0MWsc/QcLuyfgo/Exbw7t23CjGw4csjcFRTvyKRi5UndH/0r4c2pO75KTYkaHv7a5R HMgJ51e3HcC9dj/7HHPTzVsOZbdfxANHQqDvi/2+VzM2+zBL9+GWTzHl+4JSxNHLQnP+ HGmrqPlQoXpxY+8b8TZlsRORHI3ur2bxxkrpRF4FB9L/pyfDCUYl8x9K/MYXO1Y692Jo 5O1CQfuZaiYYo8ZAOP6SOiw9b0iqxduHkHaLYXHTgfn3wT0i5XU4T8+6XfrJeKoxCwv5 QPZ0JVu4j7bIJ29ORPt7lw3XfFMwLvGIzCYKDmIzM7tWkHjs1Q4L+J5cNMjSJDu7CjwM 2x/g== X-Gm-Message-State: ANoB5pk+D8tvfRpEzitKkGYVpR+6PB8SPMF+81SLgefvXXh5YoeKpXJt iOKeKWzCWY/61zCqQYmBnPHYi9cKFm6+VA== X-Received: by 2002:a05:6a20:13a3:b0:a5:df86:f0e1 with SMTP id w35-20020a056a2013a300b000a5df86f0e1mr34252993pzh.16.1670987819802; Tue, 13 Dec 2022 19:16:59 -0800 (PST) Received: from MBP ([39.170.101.209]) by smtp.gmail.com with ESMTPSA id n6-20020a63ee46000000b0047681fa88d1sm7472285pgk.53.2022.12.13.19.16.55 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 13 Dec 2022 19:16:58 -0800 (PST) References: <20221115140233.21981-1-schspa@gmail.com> User-agent: mu4e 1.8.10; emacs 29.0.60 From: Schspa Shi To: Luis Chamberlain Cc: mingo@redhat.com, peterz@infradead.org, juri.lelli@redhat.com, vincent.guittot@linaro.org, dietmar.eggemann@arm.com, rostedt@goodmis.org, bsegall@google.com, mgorman@suse.de, bristot@redhat.com, vschneid@redhat.com, linux-kernel@vger.kernel.org, syzbot+10d19d528d9755d9af22@syzkaller.appspotmail.com, syzbot+70d5d5d83d03db2c813d@syzkaller.appspotmail.com, syzbot+83cb0411d0fcf0a30fc1@syzkaller.appspotmail.com Subject: Re: [PATCH] umh: fix UAF when the process is being killed Date: Wed, 14 Dec 2022 10:28:11 +0800 In-reply-to: Message-ID: MIME-Version: 1.0 Content-Type: text/plain X-Spam-Status: No, score=-2.1 required=5.0 tests=BAYES_00,DKIM_SIGNED, DKIM_VALID,DKIM_VALID_AU,DKIM_VALID_EF,FREEMAIL_FROM, RCVD_IN_DNSWL_NONE,SPF_HELO_NONE,SPF_PASS autolearn=ham autolearn_force=no version=3.4.6 X-Spam-Checker-Version: SpamAssassin 3.4.6 (2021-04-09) on lindbergh.monkeyblade.net Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org Luis Chamberlain writes: > On Mon, Dec 12, 2022 at 09:38:31PM +0800, Schspa Shi wrote: >> I'd like to upload a V2 patch with the new solution if you prefer the >> following way. >> >> diff --git a/kernel/umh.c b/kernel/umh.c >> index 850631518665..8023f11fcfc0 100644 >> --- a/kernel/umh.c >> +++ b/kernel/umh.c >> @@ -452,6 +452,11 @@ int call_usermodehelper_exec(struct subprocess_info *sub_info, int wait) >> /* umh_complete() will see NULL and free sub_info */ >> if (xchg(&sub_info->complete, NULL)) >> goto unlock; >> + /* >> + * kthreadd (or new kernel thread) will call complete() >> + * shortly. >> + */ >> + wait_for_completion(&done); >> } > > Yes much better. Did you verify it fixes the splat found by the bots? > Yes, it will fix it. > Luis -- BRs Schspa Shi