diff options
| author | Wen Yang <wen.yang99@zte.com.cn> | 2018-12-05 10:35:50 +0800 | 
|---|---|---|
| committer | Boris Ostrovsky <boris.ostrovsky@oracle.com> | 2019-01-10 09:19:36 -0500 | 
| commit | 9f51c05dc41a6d69423e3d03d18eb7ab22f9ec19 (patch) | |
| tree | 8590b589970b80cbb53d2e0a8370f5c0d346b36d /lib/memory-notifier-error-inject.c | |
| parent | 1f8ce09b36c41a026a37a24b20efa32000892a64 (diff) | |
pvcalls-front: Avoid get_free_pages(GFP_KERNEL) under spinlock
The problem is that we call this with a spin lock held.
The call tree is:
pvcalls_front_accept() holds bedata->socket_lock.
    -> create_active()
        -> __get_free_pages() uses GFP_KERNEL
The create_active() function is only called from pvcalls_front_accept()
with a spin_lock held, The allocation is not allowed to sleep and
GFP_KERNEL is not sufficient.
This issue was detected by using the Coccinelle software.
v2: Add a function doing the allocations which is called
    outside the lock and passing the allocated data to
    create_active().
v3: Use the matching deallocators i.e., free_page()
    and free_pages(), respectively.
v4: It would be better to pre-populate map (struct sock_mapping),
    rather than introducing one more new struct.
v5: Since allocating the data outside of this call it should also
    be freed outside, when create_active() fails.
    Move kzalloc(sizeof(*map2), GFP_ATOMIC) outside spinlock and
    use GFP_KERNEL instead.
v6: Drop the superfluous calls.
Suggested-by: Juergen Gross <jgross@suse.com>
Suggested-by: Boris Ostrovsky <boris.ostrovsky@oracle.com>
Suggested-by: Stefano Stabellini <sstabellini@kernel.org>
Signed-off-by: Wen Yang <wen.yang99@zte.com.cn>
Acked-by: Stefano Stabellini <sstabellini@kernel.org>
CC: Julia Lawall <julia.lawall@lip6.fr>
CC: Boris Ostrovsky <boris.ostrovsky@oracle.com>
CC: Juergen Gross <jgross@suse.com>
CC: Stefano Stabellini <sstabellini@kernel.org>
CC: xen-devel@lists.xenproject.org
CC: linux-kernel@vger.kernel.org
Signed-off-by: Boris Ostrovsky <boris.ostrovsky@oracle.com>
Diffstat (limited to 'lib/memory-notifier-error-inject.c')
0 files changed, 0 insertions, 0 deletions
