mirror of
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git
synced 2026-08-30 11:03:07 -04:00
ftrace: Protect direct_functions in update_ftrace_direct_del
Fix accessing the __rcu pointer direct_functions with RCU protection.
Cc: stable@vger.kernel.org
Link: https://patch.msgid.link/20260730150411.88667-3-leon.hwang@linux.dev
Fixes: 8d2c1233f3 ("ftrace: Add update_ftrace_direct_del function")
Acked-by: Jiri Olsa <jolsa@kernel.org>
Signed-off-by: Leon Hwang <leon.hwang@linux.dev>
Signed-off-by: Steven Rostedt <rostedt@goodmis.org>
This commit is contained in:
committed by
Steven Rostedt
parent
63444b7617
commit
f26e5fa75f
@@ -6512,6 +6512,7 @@ int update_ftrace_direct_del(struct ftrace_ops *ops, struct ftrace_hash *hash)
|
||||
struct ftrace_hash *new_direct_functions;
|
||||
struct ftrace_hash *new_filter_hash = NULL;
|
||||
struct ftrace_hash *old_filter_hash;
|
||||
struct ftrace_hash *direct_hash;
|
||||
struct ftrace_func_entry *entry;
|
||||
struct ftrace_func_entry *del;
|
||||
unsigned long size;
|
||||
@@ -6523,11 +6524,13 @@ int update_ftrace_direct_del(struct ftrace_ops *ops, struct ftrace_hash *hash)
|
||||
return -EINVAL;
|
||||
if (!(ops->flags & FTRACE_OPS_FL_ENABLED))
|
||||
return -EINVAL;
|
||||
if (direct_functions == EMPTY_HASH)
|
||||
return -EINVAL;
|
||||
|
||||
mutex_lock(&direct_mutex);
|
||||
|
||||
direct_hash = rcu_dereference_protected(direct_functions, lockdep_is_held(&direct_mutex));
|
||||
if (direct_hash == EMPTY_HASH)
|
||||
goto out_unlock;
|
||||
|
||||
old_filter_hash = ops->func_hash ? ops->func_hash->filter_hash : NULL;
|
||||
|
||||
if (!hash_count(old_filter_hash))
|
||||
@@ -6537,7 +6540,7 @@ int update_ftrace_direct_del(struct ftrace_ops *ops, struct ftrace_hash *hash)
|
||||
size = 1 << hash->size_bits;
|
||||
for (int i = 0; i < size; i++) {
|
||||
hlist_for_each_entry(entry, &hash->buckets[i], hlist) {
|
||||
del = __ftrace_lookup_ip(direct_functions, entry->ip);
|
||||
del = __ftrace_lookup_ip(direct_hash, entry->ip);
|
||||
if (!del || del->direct != entry->direct)
|
||||
goto out_unlock;
|
||||
}
|
||||
@@ -6548,7 +6551,7 @@ int update_ftrace_direct_del(struct ftrace_ops *ops, struct ftrace_hash *hash)
|
||||
if (!new_filter_hash)
|
||||
goto out_unlock;
|
||||
|
||||
new_direct_functions = hash_sub(direct_functions, hash);
|
||||
new_direct_functions = hash_sub(direct_hash, hash);
|
||||
if (!new_direct_functions)
|
||||
goto out_unlock;
|
||||
|
||||
@@ -6575,7 +6578,7 @@ int update_ftrace_direct_del(struct ftrace_ops *ops, struct ftrace_hash *hash)
|
||||
/* free the new_direct_functions */
|
||||
old_direct_functions = new_direct_functions;
|
||||
} else {
|
||||
old_direct_functions = direct_functions;
|
||||
old_direct_functions = direct_hash;
|
||||
rcu_assign_pointer(direct_functions, new_direct_functions);
|
||||
}
|
||||
|
||||
|
||||
Reference in New Issue
Block a user