# git rev-parse -q --verify a5b9b743fdb653c37d347b303fb60dff0c743f7e^{commit} a5b9b743fdb653c37d347b303fb60dff0c743f7e already have revision, skipping fetch # git checkout -q -f -B kisskb a5b9b743fdb653c37d347b303fb60dff0c743f7e # git clean -qxdf # < git log -1 # commit a5b9b743fdb653c37d347b303fb60dff0c743f7e # Author: Frederic Barrat # Date: Mon Jun 24 16:41:48 2019 +0200 # # ocxl: Fix concurrent AFU open and device removal # # If an ocxl device is unbound through sysfs at the same time its AFU is # being opened by a user process, the open code may dereference freed # stuctures, which can lead to kernel oops messages. You'd have to hit a # tiny time window, but it's possible. It's fairly easy to test by # making the time window bigger artificially. # # Fix it with a combination of 2 changes: # - when an AFU device is found in the IDR by looking for the device # minor number, we should hold a reference on the device until after # the context is allocated. A reference on the AFU structure is kept # when the context is allocated, so we can release the reference on # the device after the context allocation. # - with the fix above, there's still another even tinier window, # between the time the AFU device is found in the IDR and the # reference on the device is taken. We can fix this one by removing # the IDR entry earlier, when the device setup is removed, instead # of waiting for the 'release' device callback. With proper locking # around the IDR. # # Fixes: 75ca758adbaf ("ocxl: Create a clear delineation between ocxl backend & frontend") # Cc: stable@vger.kernel.org # v5.2+ # Signed-off-by: Frederic Barrat # Reviewed-by: Greg Kurz # Signed-off-by: Michael Ellerman # Link: https://lore.kernel.org/r/20190624144148.32022-1-fbarrat@linux.ibm.com # < /opt/cross/kisskb/gcc-4.6.3-nolibc/powerpc-linux/bin/powerpc-linux-gcc --version # < /opt/cross/kisskb/gcc-4.6.3-nolibc/powerpc-linux/bin/powerpc-linux-ld --version # < git log --format=%s --max-count=1 a5b9b743fdb653c37d347b303fb60dff0c743f7e # < make -s -j 24 ARCH=powerpc O=/kisskb/build/powerpc-fixes_mpc885_ads_defconfig+HUGETLB_powerpc-gcc4.6 CROSS_COMPILE=/opt/cross/kisskb/gcc-4.6.3-nolibc/powerpc-linux/bin/powerpc-linux- mpc885_ads_defconfig # Added to kconfig CONFIG_HUGETLBFS=y # yes \n | make -s -j 24 ARCH=powerpc O=/kisskb/build/powerpc-fixes_mpc885_ads_defconfig+HUGETLB_powerpc-gcc4.6 CROSS_COMPILE=/opt/cross/kisskb/gcc-4.6.3-nolibc/powerpc-linux/bin/powerpc-linux- oldconfig yes: standard output: Broken pipe # make -s -j 24 ARCH=powerpc O=/kisskb/build/powerpc-fixes_mpc885_ads_defconfig+HUGETLB_powerpc-gcc4.6 CROSS_COMPILE=/opt/cross/kisskb/gcc-4.6.3-nolibc/powerpc-linux/bin/powerpc-linux- /kisskb/src/kernel/printk/printk.c: In function 'devkmsg_sysctl_set_loglvl': /kisskb/src/kernel/printk/printk.c:204:16: warning: 'old' may be used uninitialized in this function [-Wuninitialized] /kisskb/src/fs/proc/inode.c: In function 'proc_reg_open': /kisskb/src/include/linux/list.h:65:12: warning: 'pdeo' may be used uninitialized in this function [-Wuninitialized] /kisskb/src/fs/proc/inode.c:338:21: note: 'pdeo' was declared here /kisskb/src/mm/hugetlb.c: In function 'alloc_pool_huge_page': /kisskb/src/mm/hugetlb.c:1377:5: warning: 'page' may be used uninitialized in this function [-Wuninitialized] WARNING: vmlinux.o(.text+0xbca8): Section mismatch in reference from the function mmu_mark_initmem_nx() to the function .init.text:mmu_mapin_ram_chunk() The function mmu_mark_initmem_nx() references the function __init mmu_mapin_ram_chunk(). This is often because mmu_mark_initmem_nx lacks a __init annotation or the annotation of mmu_mapin_ram_chunk is wrong. WARNING: vmlinux.o(.text+0xbcc0): Section mismatch in reference from the function mmu_mark_initmem_nx() to the function .init.text:mmu_mapin_ram_chunk() The function mmu_mark_initmem_nx() references the function __init mmu_mapin_ram_chunk(). This is often because mmu_mark_initmem_nx lacks a __init annotation or the annotation of mmu_mapin_ram_chunk is wrong. WARNING: vmlinux.o(.text+0xbcd8): Section mismatch in reference from the function mmu_mark_initmem_nx() to the function .init.text:mmu_mapin_ram_chunk() The function mmu_mark_initmem_nx() references the function __init mmu_mapin_ram_chunk(). This is often because mmu_mark_initmem_nx lacks a __init annotation or the annotation of mmu_mapin_ram_chunk is wrong. Image Name: Linux-5.4.0-ga5b9b743fdb6 Created: Sat Dec 7 16:42:06 2019 Image Type: PowerPC Linux Kernel Image (gzip compressed) Data Size: 1781107 Bytes = 1739.36 KiB = 1.70 MiB Load Address: 00400000 Entry Point: 004001dc Completed OK # rm -rf /kisskb/build/powerpc-fixes_mpc885_ads_defconfig+HUGETLB_powerpc-gcc4.6 # Build took: 0:00:47.124380