Donate to e Foundation | Murena handsets with /e/OS | Own a part of Murena! Learn more

Commit 2fff78c7 authored by Peter Zijlstra's avatar Peter Zijlstra Committed by Ingo Molnar
Browse files

futex: fix reference leak



Catalin noticed that (38d47c1b: futex: rely on get_user_pages() for
shared futexes) caused an mm_struct leak.

Some tracing with the function graph tracer quickly pointed out that
futex_wait() has exit paths with unbalanced reference counts.

This regression was discovered by kmemleak.

Reported-by: default avatarCatalin Marinas <catalin.marinas@arm.com>
Signed-off-by: default avatarPeter Zijlstra <a.p.zijlstra@chello.nl>
Tested-by: default avatar"Pallipadi, Venkatesh" <venkatesh.pallipadi@intel.com>
Tested-by: default avatarCatalin Marinas <catalin.marinas@arm.com>
Signed-off-by: default avatarIngo Molnar <mingo@elte.hu>
parent 6c6f1f0f
Loading
Loading
Loading
Loading
+28 −25
Original line number Diff line number Diff line
@@ -1165,6 +1165,7 @@ static int futex_wait(u32 __user *uaddr, int fshared,
		      u32 val, ktime_t *abs_time, u32 bitset, int clockrt)
{
	struct task_struct *curr = current;
	struct restart_block *restart;
	DECLARE_WAITQUEUE(wait, curr);
	struct futex_hash_bucket *hb;
	struct futex_q q;
@@ -1216,11 +1217,13 @@ retry:

		if (!ret)
			goto retry;
		return ret;
		goto out;
	}
	ret = -EWOULDBLOCK;
	if (uval != val)
		goto out_unlock_put_key;
	if (unlikely(uval != val)) {
		queue_unlock(&q, hb);
		goto out_put_key;
	}

	/* Only actually queue if *uaddr contained val.  */
	queue_me(&q, hb);
@@ -1284,19 +1287,21 @@ retry:
	 */

	/* If we were woken (and unqueued), we succeeded, whatever. */
	ret = 0;
	if (!unqueue_me(&q))
		return 0;
		goto out_put_key;
	ret = -ETIMEDOUT;
	if (rem)
		return -ETIMEDOUT;
		goto out_put_key;

	/*
	 * We expect signal_pending(current), but another thread may
	 * have handled it for us already.
	 */
	ret = -ERESTARTSYS;
	if (!abs_time)
		return -ERESTARTSYS;
	else {
		struct restart_block *restart;
		goto out_put_key;

	restart = &current_thread_info()->restart_block;
	restart->fn = futex_wait_restart;
	restart->futex.uaddr = (u32 *)uaddr;
@@ -1309,13 +1314,11 @@ retry:
		restart->futex.flags |= FLAGS_SHARED;
	if (clockrt)
		restart->futex.flags |= FLAGS_CLOCKRT;
		return -ERESTART_RESTARTBLOCK;
	}

out_unlock_put_key:
	queue_unlock(&q, hb);
	put_futex_key(fshared, &q.key);
	ret = -ERESTART_RESTARTBLOCK;

out_put_key:
	put_futex_key(fshared, &q.key);
out:
	return ret;
}