mirror of
https://github.com/torvalds/linux.git
synced 2026-07-27 09:36:22 +02:00
netconsole: take target_cleanup_list_lock in drop_netconsole_target()
drop_netconsole_target() unlinks the target while only holding target_list_lock. However, when the underlying interface has been unregistered, netconsole_netdev_event() moves the target from target_list to target_cleanup_list, and netconsole_process_cleanups_core() walks that list under target_cleanup_list_lock only. If a user removes the configfs target at the same time the cleanup worker is iterating target_cleanup_list, list_del() can corrupt the list because the two paths take disjoint locks while operating on the same list node. Acquire target_cleanup_list_lock around the list_del() so the unlink is serialised against netconsole_process_cleanups_core() regardless of which list the target currently belongs to. The state transition that downgrades STATE_DEACTIVATED to STATE_DISABLED is left intact and is performed under the same combined locking, preserving the existing ordering with resume_target(). Signed-off-by: Breno Leitao <leitao@debian.org> Link: https://patch.msgid.link/20260604-netcons_fix_before_move-v3-3-ab055b3a6aa5@debian.org Signed-off-by: Paolo Abeni <pabeni@redhat.com>
This commit is contained in:
parent
6c537b845c
commit
91aeb87f05
|
|
@ -1452,6 +1452,7 @@ static void drop_netconsole_target(struct config_group *group,
|
|||
|
||||
dynamic_netconsole_mutex_lock();
|
||||
|
||||
mutex_lock(&target_cleanup_list_lock);
|
||||
spin_lock_irqsave(&target_list_lock, flags);
|
||||
/* Disable deactivated target to prevent races between resume attempt
|
||||
* and target removal.
|
||||
|
|
@ -1460,6 +1461,7 @@ static void drop_netconsole_target(struct config_group *group,
|
|||
nt->state = STATE_DISABLED;
|
||||
list_del(&nt->list);
|
||||
spin_unlock_irqrestore(&target_list_lock, flags);
|
||||
mutex_unlock(&target_cleanup_list_lock);
|
||||
|
||||
dynamic_netconsole_mutex_unlock();
|
||||
|
||||
|
|
|
|||
Loading…
Reference in New Issue
Block a user