Commit 49bef5ac authored by Kirill Tkhai's avatar Kirill Tkhai Committed by Luis Henriques

sched: Use dl_bw_of() under RCU read lock

commit 66339c31 upstream.

dl_bw_of() dereferences rq->rd which has to have RCU read lock held.
Probability of use-after-free isn't zero here.

Also add lockdep assert into dl_bw_cpus().
Signed-off-by: default avatarKirill Tkhai <ktkhai@parallels.com>
Signed-off-by: default avatarPeter Zijlstra (Intel) <peterz@infradead.org>
Cc: Paul E. McKenney <paulmck@linux.vnet.ibm.com>
Cc: Linus Torvalds <torvalds@linux-foundation.org>
Link: http://lkml.kernel.org/r/20140922183624.11015.71558.stgit@localhostSigned-off-by: default avatarIngo Molnar <mingo@kernel.org>
Signed-off-by: default avatarLuis Henriques <luis.henriques@canonical.com>
parent 427ee2fa
......@@ -1969,6 +1969,8 @@ unsigned long to_ratio(u64 period, u64 runtime)
#ifdef CONFIG_SMP
inline struct dl_bw *dl_bw_of(int i)
{
rcu_lockdep_assert(rcu_read_lock_sched_held(),
"sched RCU must be held");
return &cpu_rq(i)->rd->dl_bw;
}
......@@ -1977,6 +1979,8 @@ static inline int dl_bw_cpus(int i)
struct root_domain *rd = cpu_rq(i)->rd;
int cpus = 0;
rcu_lockdep_assert(rcu_read_lock_sched_held(),
"sched RCU must be held");
for_each_cpu_and(i, rd->span, cpu_active_mask)
cpus++;
......@@ -7541,6 +7545,8 @@ static int sched_dl_global_constraints(void)
int cpu, ret = 0;
unsigned long flags;
rcu_read_lock();
/*
* Here we want to check the bandwidth not being set to some
* value smaller than the currently allocated bandwidth in
......@@ -7562,6 +7568,8 @@ static int sched_dl_global_constraints(void)
break;
}
rcu_read_unlock();
return ret;
}
......@@ -7577,6 +7585,7 @@ static void sched_dl_do_global(void)
if (global_rt_runtime() != RUNTIME_INF)
new_bw = to_ratio(global_rt_period(), global_rt_runtime());
rcu_read_lock();
/*
* FIXME: As above...
*/
......@@ -7587,6 +7596,7 @@ static void sched_dl_do_global(void)
dl_b->bw = new_bw;
raw_spin_unlock_irqrestore(&dl_b->lock, flags);
}
rcu_read_unlock();
}
static int sched_rt_global_validate(void)
......
Markdown is supported
0%
or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment