Received: by 2002:a05:6358:a55:b0:ec:fcf4:3ecf with SMTP id 21csp1324255rwb; Thu, 19 Jan 2023 09:11:46 -0800 (PST) X-Google-Smtp-Source: AMrXdXv1muHq/wRO+C9oB6U+gBo6NhZeY04XhQJO9qhLfk1ZBu/iiefLLHX0b2Z70gfUuliyxXMs X-Received: by 2002:a05:6a21:339a:b0:a7:345a:100f with SMTP id yy26-20020a056a21339a00b000a7345a100fmr14466741pzb.10.1674148305786; Thu, 19 Jan 2023 09:11:45 -0800 (PST) ARC-Seal: i=1; a=rsa-sha256; t=1674148305; cv=none; d=google.com; s=arc-20160816; b=GdnEYTfYHLAFO518CSuI7kolW4wQJxBp552DiK4ZlYjRbjbren92RIhj2QB2+knvKQ r1THOqJKqJmwZWqMxtRGHMrdqR5whKY8zVA0YETjI+VkC68GInfDGobnfw3nXvmb1GNo 0KzJj8Png+UIruoaM4eZ0jn6/w+48rCODerm80H6TeRnECy7FlsKaQWr5gjGjkr37sG1 ljYHY1fWtcooth6u71wpK6gM7Hoky1jfbSnHmztsv+bq2CQITFOWrwhXVCXpdze60ITN oZ/vq0xnQQW6PBPSAravuiJWrVJHycq9UI9fPxhX/8LoNt+U5tRowjRiR90ErkRUVY7+ iRaQ== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:in-reply-to:content-disposition:mime-version :references:message-id:subject:cc:to:from:date:sender:dkim-signature; bh=ae6CLA/wyp/IvxNOrUUr/ZjdhSOngZFFYXXmGXpC8Eo=; b=B52PfI++9X8ndfeYeNquywNxsYZE22dZijzeE+1x9wKzsgqd12pKUYZ/CsTv/5vcJY 4HwGd+nCahFUAykUjHkbVjWVbUvSo2BScxBsh0Jzbuyhe3XBbMptBzVMVDRnAtp/PrZA DkSOlbK/PlVtvn3nAwgpsTMGWRTKikDxiWfFpoQDRzJc8OTpdESpP3jsL0ZRBE/pxfLv jAfbE/uOu0z64o3/pKS8/kwSQ6wXC5MnQQ/etbJomxHdO0OA7eIJEjswKnhi6F0lgBD0 VsihkR3yLPa5hHnk8slLXKcMCuv40o+RQgRkvduStIYq7yvF3tH90gxfufS/j2Wkms6k cqTg== ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@gmail.com header.s=20210112 header.b="IHB4k/BC"; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=kernel.org Return-Path: Received: from out1.vger.email (out1.vger.email. [2620:137:e000::1:20]) by mx.google.com with ESMTP id i13-20020a63e90d000000b00480a937f894si40215133pgh.766.2023.01.19.09.11.39; Thu, 19 Jan 2023 09:11:45 -0800 (PST) Received-SPF: pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) client-ip=2620:137:e000::1:20; Authentication-Results: mx.google.com; dkim=pass header.i=@gmail.com header.s=20210112 header.b="IHB4k/BC"; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=kernel.org Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S229534AbjASQQE (ORCPT + 45 others); Thu, 19 Jan 2023 11:16:04 -0500 Received: from lindbergh.monkeyblade.net ([23.128.96.19]:41046 "EHLO lindbergh.monkeyblade.net" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S229459AbjASQP7 (ORCPT ); Thu, 19 Jan 2023 11:15:59 -0500 Received: from mail-pl1-x634.google.com (mail-pl1-x634.google.com [IPv6:2607:f8b0:4864:20::634]) by lindbergh.monkeyblade.net (Postfix) with ESMTPS id A62EC8A63; Thu, 19 Jan 2023 08:15:58 -0800 (PST) Received: by mail-pl1-x634.google.com with SMTP id z13so2749404plg.6; Thu, 19 Jan 2023 08:15:58 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20210112; h=in-reply-to:content-disposition:mime-version:references:message-id :subject:cc:to:from:date:sender:from:to:cc:subject:date:message-id :reply-to; bh=ae6CLA/wyp/IvxNOrUUr/ZjdhSOngZFFYXXmGXpC8Eo=; b=IHB4k/BCpN5sgx7Si8MmzTbFCivgZU+rJneogVjYsDfEIK9Z03JTHrf+NRUAAjBV6j le9FgFaerU+8HdJ8/cF3P4PUTaJ7NduhYrsyULClMw+M38tARHzdUegH3US59Ru9HpRi M3mmkyFOa+I6j6zZ+drM9VxU0fmrxERrcei5iEBQUkPAwEW0Ah8alPIVjPblmz9jY74S gnT22G4f13X5F0ExocvzTFlib3QcpSXseTC3YwSJMlXTJnEWM+boHGUkV4HgSkXCDi7y DcDyLOQfSr42qNBkzng4sdtwAhXb2o/2M8effxXUzeBEtd2sAdPgswgOSgEpFGPOsxaZ f1SA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20210112; h=in-reply-to:content-disposition:mime-version:references:message-id :subject:cc:to:from:date:sender:x-gm-message-state:from:to:cc :subject:date:message-id:reply-to; bh=ae6CLA/wyp/IvxNOrUUr/ZjdhSOngZFFYXXmGXpC8Eo=; b=0dZ5dKiXTvlloMF7eDmE9v8IBr+6fPn7SaejlNPRu0fuozlliQAf4SD/jjlifDex1f drgf1OBr3LMYYdIPhX1shxZyk0dAk52lRygh+gn1Ab2q1ir5dThoQsfGzfN1JxC/ZqvS qp4BGX0tfYosH5uu/6ZREdddlAlqpTQ+PI6lzzNUSeEW8mP3Tn3IJ0WAt0cUbmazW84s 0o3wiwTOlECpGFUH3XHrYfzgrpb5+1s/W3P+/xZ03uJWNK7sNNGo/uuVdLKj2zUMgGTl B+88xArj8pfktB7nbbb3k7T4L/d3Fe9AL0Jo1Zw02vtzwoPbdf629vdUnA6WidW87hpV HR2w== X-Gm-Message-State: AFqh2kou3/JoB75SXZ7odhA/9Q2AKXseurWKuevscgnjwNd74r2F/cnR SYh2lqFMVJJnE+flDR7LqP0= X-Received: by 2002:a05:6a20:2a9a:b0:a5:6e3d:107b with SMTP id v26-20020a056a202a9a00b000a56e3d107bmr16265430pzh.0.1674144957813; Thu, 19 Jan 2023 08:15:57 -0800 (PST) Received: from localhost ([2600:380:4a69:c93e:fcd6:9a91:e25c:65a6]) by smtp.gmail.com with ESMTPSA id u7-20020a17090341c700b00186e34524e3sm25324085ple.136.2023.01.19.08.15.57 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 19 Jan 2023 08:15:57 -0800 (PST) Sender: Tejun Heo Date: Thu, 19 Jan 2023 06:15:55 -1000 From: Tejun Heo To: Yu Kuai Cc: hch@lst.de, josef@toxicpanda.com, axboe@kernel.dk, cgroups@vger.kernel.org, linux-block@vger.kernel.org, linux-kernel@vger.kernel.org, yukuai3@huawei.com, yi.zhang@huawei.com, yangerkun@huawei.com Subject: Re: [PATCH -next v3 3/3] blk-cgroup: synchronize pd_free_fn() from blkg_free_workfn() and blkcg_deactivate_policy() Message-ID: References: <20230119110350.2287325-1-yukuai1@huaweicloud.com> <20230119110350.2287325-4-yukuai1@huaweicloud.com> MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <20230119110350.2287325-4-yukuai1@huaweicloud.com> X-Spam-Status: No, score=-1.5 required=5.0 tests=BAYES_00,DKIM_SIGNED, DKIM_VALID,DKIM_VALID_EF,FREEMAIL_FORGED_FROMDOMAIN,FREEMAIL_FROM, HEADER_FROM_DIFFERENT_DOMAINS,RCVD_IN_DNSWL_NONE,SPF_HELO_NONE, SPF_PASS autolearn=no autolearn_force=no version=3.4.6 X-Spam-Checker-Version: SpamAssassin 3.4.6 (2021-04-09) on lindbergh.monkeyblade.net Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org On Thu, Jan 19, 2023 at 07:03:50PM +0800, Yu Kuai wrote: > From: Yu Kuai > > Currently parent pd can be freed before child pd: > > t1: remove cgroup C1 > blkcg_destroy_blkgs > blkg_destroy > list_del_init(&blkg->q_node) > // remove blkg from queue list > percpu_ref_kill(&blkg->refcnt) > blkg_release > call_rcu > > t2: from t1 > __blkg_release > blkg_free > schedule_work > t4: deactivate policy > blkcg_deactivate_policy > pd_free_fn > // parent of C1 is freed first > t3: from t2 > blkg_free_workfn > pd_free_fn > > If policy(for example, ioc_timer_fn() from iocost) access parent pd from > child pd after pd_offline_fn(), then UAF can be triggered. > > Fix the problem by delaying 'list_del_init(&blkg->q_node)' from > blkg_destroy() to blkg_free_workfn(), and using a new disk level mutex to > synchronize blkg_free_workfn() and blkcg_deactivate_policy(). > > Signed-off-by: Yu Kuai Acked-by: Tejun Heo Thanks. -- tejun