1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34#include <linux/compat.h>
35#include <linux/slab.h>
36#include <linux/poll.h>
37#include <linux/fs.h>
38#include <linux/file.h>
39#include <linux/jhash.h>
40#include <linux/init.h>
41#include <linux/futex.h>
42#include <linux/mount.h>
43#include <linux/pagemap.h>
44#include <linux/syscalls.h>
45#include <linux/signal.h>
46#include <linux/export.h>
47#include <linux/magic.h>
48#include <linux/pid.h>
49#include <linux/nsproxy.h>
50#include <linux/ptrace.h>
51#include <linux/sched/rt.h>
52#include <linux/sched/wake_q.h>
53#include <linux/sched/mm.h>
54#include <linux/hugetlb.h>
55#include <linux/freezer.h>
56#include <linux/memblock.h>
57#include <linux/fault-inject.h>
58#include <linux/refcount.h>
59
60#include <asm/futex.h>
61
62#include "locking/rtmutex_common.h"
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165#ifdef CONFIG_HAVE_FUTEX_CMPXCHG
166#define futex_cmpxchg_enabled 1
167#else
168static int __read_mostly futex_cmpxchg_enabled;
169#endif
170
171
172
173
174
175#ifdef CONFIG_MMU
176# define FLAGS_SHARED 0x01
177#else
178
179
180
181
182# define FLAGS_SHARED 0x00
183#endif
184#define FLAGS_CLOCKRT 0x02
185#define FLAGS_HAS_TIMEOUT 0x04
186
187
188
189
190struct futex_pi_state {
191
192
193
194
195 struct list_head list;
196
197
198
199
200 struct rt_mutex pi_mutex;
201
202 struct task_struct *owner;
203 refcount_t refcount;
204
205 union futex_key key;
206} __randomize_layout;
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230struct futex_q {
231 struct plist_node list;
232
233 struct task_struct *task;
234 spinlock_t *lock_ptr;
235 union futex_key key;
236 struct futex_pi_state *pi_state;
237 struct rt_mutex_waiter *rt_waiter;
238 union futex_key *requeue_pi_key;
239 u32 bitset;
240} __randomize_layout;
241
242static const struct futex_q futex_q_init = {
243
244 .key = FUTEX_KEY_INIT,
245 .bitset = FUTEX_BITSET_MATCH_ANY
246};
247
248
249
250
251
252
253struct futex_hash_bucket {
254 atomic_t waiters;
255 spinlock_t lock;
256 struct plist_head chain;
257} ____cacheline_aligned_in_smp;
258
259
260
261
262
263
264static struct {
265 struct futex_hash_bucket *queues;
266 unsigned long hashsize;
267} __futex_data __read_mostly __aligned(2*sizeof(long));
268#define futex_queues (__futex_data.queues)
269#define futex_hashsize (__futex_data.hashsize)
270
271
272
273
274
275#ifdef CONFIG_FAIL_FUTEX
276
277static struct {
278 struct fault_attr attr;
279
280 bool ignore_private;
281} fail_futex = {
282 .attr = FAULT_ATTR_INITIALIZER,
283 .ignore_private = false,
284};
285
286static int __init setup_fail_futex(char *str)
287{
288 return setup_fault_attr(&fail_futex.attr, str);
289}
290__setup("fail_futex=", setup_fail_futex);
291
292static bool should_fail_futex(bool fshared)
293{
294 if (fail_futex.ignore_private && !fshared)
295 return false;
296
297 return should_fail(&fail_futex.attr, 1);
298}
299
300#ifdef CONFIG_FAULT_INJECTION_DEBUG_FS
301
302static int __init fail_futex_debugfs(void)
303{
304 umode_t mode = S_IFREG | S_IRUSR | S_IWUSR;
305 struct dentry *dir;
306
307 dir = fault_create_debugfs_attr("fail_futex", NULL,
308 &fail_futex.attr);
309 if (IS_ERR(dir))
310 return PTR_ERR(dir);
311
312 debugfs_create_bool("ignore-private", mode, dir,
313 &fail_futex.ignore_private);
314 return 0;
315}
316
317late_initcall(fail_futex_debugfs);
318
319#endif
320
321#else
322static inline bool should_fail_futex(bool fshared)
323{
324 return false;
325}
326#endif
327
328#ifdef CONFIG_COMPAT
329static void compat_exit_robust_list(struct task_struct *curr);
330#else
331static inline void compat_exit_robust_list(struct task_struct *curr) { }
332#endif
333
334static inline void futex_get_mm(union futex_key *key)
335{
336 mmgrab(key->private.mm);
337
338
339
340
341
342 smp_mb__after_atomic();
343}
344
345
346
347
348static inline void hb_waiters_inc(struct futex_hash_bucket *hb)
349{
350#ifdef CONFIG_SMP
351 atomic_inc(&hb->waiters);
352
353
354
355 smp_mb__after_atomic();
356#endif
357}
358
359
360
361
362
363static inline void hb_waiters_dec(struct futex_hash_bucket *hb)
364{
365#ifdef CONFIG_SMP
366 atomic_dec(&hb->waiters);
367#endif
368}
369
370static inline int hb_waiters_pending(struct futex_hash_bucket *hb)
371{
372#ifdef CONFIG_SMP
373 return atomic_read(&hb->waiters);
374#else
375 return 1;
376#endif
377}
378
379
380
381
382
383
384
385
386static struct futex_hash_bucket *hash_futex(union futex_key *key)
387{
388 u32 hash = jhash2((u32*)&key->both.word,
389 (sizeof(key->both.word)+sizeof(key->both.ptr))/4,
390 key->both.offset);
391 return &futex_queues[hash & (futex_hashsize - 1)];
392}
393
394
395
396
397
398
399
400
401
402static inline int match_futex(union futex_key *key1, union futex_key *key2)
403{
404 return (key1 && key2
405 && key1->both.word == key2->both.word
406 && key1->both.ptr == key2->both.ptr
407 && key1->both.offset == key2->both.offset);
408}
409
410
411
412
413
414
415static void get_futex_key_refs(union futex_key *key)
416{
417 if (!key->both.ptr)
418 return;
419
420
421
422
423
424
425 if (!IS_ENABLED(CONFIG_MMU)) {
426 smp_mb();
427 return;
428 }
429
430 switch (key->both.offset & (FUT_OFF_INODE|FUT_OFF_MMSHARED)) {
431 case FUT_OFF_INODE:
432 ihold(key->shared.inode);
433 break;
434 case FUT_OFF_MMSHARED:
435 futex_get_mm(key);
436 break;
437 default:
438
439
440
441
442
443 smp_mb();
444 }
445}
446
447
448
449
450
451
452
453static void drop_futex_key_refs(union futex_key *key)
454{
455 if (!key->both.ptr) {
456
457 WARN_ON_ONCE(1);
458 return;
459 }
460
461 if (!IS_ENABLED(CONFIG_MMU))
462 return;
463
464 switch (key->both.offset & (FUT_OFF_INODE|FUT_OFF_MMSHARED)) {
465 case FUT_OFF_INODE:
466 iput(key->shared.inode);
467 break;
468 case FUT_OFF_MMSHARED:
469 mmdrop(key->private.mm);
470 break;
471 }
472}
473
474enum futex_access {
475 FUTEX_READ,
476 FUTEX_WRITE
477};
478
479
480
481
482
483
484
485
486
487
488
489static inline struct hrtimer_sleeper *
490futex_setup_timer(ktime_t *time, struct hrtimer_sleeper *timeout,
491 int flags, u64 range_ns)
492{
493 if (!time)
494 return NULL;
495
496 hrtimer_init_sleeper_on_stack(timeout, (flags & FLAGS_CLOCKRT) ?
497 CLOCK_REALTIME : CLOCK_MONOTONIC,
498 HRTIMER_MODE_ABS);
499
500
501
502
503 hrtimer_set_expires_range_ns(&timeout->timer, *time, range_ns);
504
505 return timeout;
506}
507
508
509
510
511
512
513
514
515
516
517
518
519
520
521
522
523
524
525
526static int
527get_futex_key(u32 __user *uaddr, int fshared, union futex_key *key, enum futex_access rw)
528{
529 unsigned long address = (unsigned long)uaddr;
530 struct mm_struct *mm = current->mm;
531 struct page *page, *tail;
532 struct address_space *mapping;
533 int err, ro = 0;
534
535
536
537
538 key->both.offset = address % PAGE_SIZE;
539 if (unlikely((address % sizeof(u32)) != 0))
540 return -EINVAL;
541 address -= key->both.offset;
542
543 if (unlikely(!access_ok(uaddr, sizeof(u32))))
544 return -EFAULT;
545
546 if (unlikely(should_fail_futex(fshared)))
547 return -EFAULT;
548
549
550
551
552
553
554
555
556 if (!fshared) {
557 key->private.mm = mm;
558 key->private.address = address;
559 get_futex_key_refs(key);
560 return 0;
561 }
562
563again:
564
565 if (unlikely(should_fail_futex(fshared)))
566 return -EFAULT;
567
568 err = get_user_pages_fast(address, 1, FOLL_WRITE, &page);
569
570
571
572
573 if (err == -EFAULT && rw == FUTEX_READ) {
574 err = get_user_pages_fast(address, 1, 0, &page);
575 ro = 1;
576 }
577 if (err < 0)
578 return err;
579 else
580 err = 0;
581
582
583
584
585
586
587
588
589
590
591
592
593
594
595
596
597
598
599
600 tail = page;
601 page = compound_head(page);
602 mapping = READ_ONCE(page->mapping);
603
604
605
606
607
608
609
610
611
612
613
614
615
616
617
618
619 if (unlikely(!mapping)) {
620 int shmem_swizzled;
621
622
623
624
625
626
627 lock_page(page);
628 shmem_swizzled = PageSwapCache(page) || page->mapping;
629 unlock_page(page);
630 put_page(page);
631
632 if (shmem_swizzled)
633 goto again;
634
635 return -EFAULT;
636 }
637
638
639
640
641
642
643
644
645
646
647
648 if (PageAnon(page)) {
649
650
651
652
653 if (unlikely(should_fail_futex(fshared)) || ro) {
654 err = -EFAULT;
655 goto out;
656 }
657
658 key->both.offset |= FUT_OFF_MMSHARED;
659 key->private.mm = mm;
660 key->private.address = address;
661
662 get_futex_key_refs(key);
663
664 } else {
665 struct inode *inode;
666
667
668
669
670
671
672
673
674
675
676
677
678 rcu_read_lock();
679
680 if (READ_ONCE(page->mapping) != mapping) {
681 rcu_read_unlock();
682 put_page(page);
683
684 goto again;
685 }
686
687 inode = READ_ONCE(mapping->host);
688 if (!inode) {
689 rcu_read_unlock();
690 put_page(page);
691
692 goto again;
693 }
694
695
696
697
698
699
700
701
702
703
704
705
706
707 if (!atomic_inc_not_zero(&inode->i_count)) {
708 rcu_read_unlock();
709 put_page(page);
710
711 goto again;
712 }
713
714
715 if (WARN_ON_ONCE(inode->i_mapping != mapping)) {
716 err = -EFAULT;
717 rcu_read_unlock();
718 iput(inode);
719
720 goto out;
721 }
722
723 key->both.offset |= FUT_OFF_INODE;
724 key->shared.inode = inode;
725 key->shared.pgoff = basepage_index(tail);
726 rcu_read_unlock();
727 }
728
729out:
730 put_page(page);
731 return err;
732}
733
734static inline void put_futex_key(union futex_key *key)
735{
736 drop_futex_key_refs(key);
737}
738
739
740
741
742
743
744
745
746
747
748
749
750
751static int fault_in_user_writeable(u32 __user *uaddr)
752{
753 struct mm_struct *mm = current->mm;
754 int ret;
755
756 down_read(&mm->mmap_sem);
757 ret = fixup_user_fault(current, mm, (unsigned long)uaddr,
758 FAULT_FLAG_WRITE, NULL);
759 up_read(&mm->mmap_sem);
760
761 return ret < 0 ? ret : 0;
762}
763
764
765
766
767
768
769
770
771static struct futex_q *futex_top_waiter(struct futex_hash_bucket *hb,
772 union futex_key *key)
773{
774 struct futex_q *this;
775
776 plist_for_each_entry(this, &hb->chain, list) {
777 if (match_futex(&this->key, key))
778 return this;
779 }
780 return NULL;
781}
782
783static int cmpxchg_futex_value_locked(u32 *curval, u32 __user *uaddr,
784 u32 uval, u32 newval)
785{
786 int ret;
787
788 pagefault_disable();
789 ret = futex_atomic_cmpxchg_inatomic(curval, uaddr, uval, newval);
790 pagefault_enable();
791
792 return ret;
793}
794
795static int get_futex_value_locked(u32 *dest, u32 __user *from)
796{
797 int ret;
798
799 pagefault_disable();
800 ret = __get_user(*dest, from);
801 pagefault_enable();
802
803 return ret ? -EFAULT : 0;
804}
805
806
807
808
809
810static int refill_pi_state_cache(void)
811{
812 struct futex_pi_state *pi_state;
813
814 if (likely(current->pi_state_cache))
815 return 0;
816
817 pi_state = kzalloc(sizeof(*pi_state), GFP_KERNEL);
818
819 if (!pi_state)
820 return -ENOMEM;
821
822 INIT_LIST_HEAD(&pi_state->list);
823
824 pi_state->owner = NULL;
825 refcount_set(&pi_state->refcount, 1);
826 pi_state->key = FUTEX_KEY_INIT;
827
828 current->pi_state_cache = pi_state;
829
830 return 0;
831}
832
833static struct futex_pi_state *alloc_pi_state(void)
834{
835 struct futex_pi_state *pi_state = current->pi_state_cache;
836
837 WARN_ON(!pi_state);
838 current->pi_state_cache = NULL;
839
840 return pi_state;
841}
842
843static void get_pi_state(struct futex_pi_state *pi_state)
844{
845 WARN_ON_ONCE(!refcount_inc_not_zero(&pi_state->refcount));
846}
847
848
849
850
851
852static void put_pi_state(struct futex_pi_state *pi_state)
853{
854 if (!pi_state)
855 return;
856
857 if (!refcount_dec_and_test(&pi_state->refcount))
858 return;
859
860
861
862
863
864 if (pi_state->owner) {
865 struct task_struct *owner;
866
867 raw_spin_lock_irq(&pi_state->pi_mutex.wait_lock);
868 owner = pi_state->owner;
869 if (owner) {
870 raw_spin_lock(&owner->pi_lock);
871 list_del_init(&pi_state->list);
872 raw_spin_unlock(&owner->pi_lock);
873 }
874 rt_mutex_proxy_unlock(&pi_state->pi_mutex, owner);
875 raw_spin_unlock_irq(&pi_state->pi_mutex.wait_lock);
876 }
877
878 if (current->pi_state_cache) {
879 kfree(pi_state);
880 } else {
881
882
883
884
885
886 pi_state->owner = NULL;
887 refcount_set(&pi_state->refcount, 1);
888 current->pi_state_cache = pi_state;
889 }
890}
891
892#ifdef CONFIG_FUTEX_PI
893
894
895
896
897
898
899static void exit_pi_state_list(struct task_struct *curr)
900{
901 struct list_head *next, *head = &curr->pi_state_list;
902 struct futex_pi_state *pi_state;
903 struct futex_hash_bucket *hb;
904 union futex_key key = FUTEX_KEY_INIT;
905
906 if (!futex_cmpxchg_enabled)
907 return;
908
909
910
911
912
913 raw_spin_lock_irq(&curr->pi_lock);
914 while (!list_empty(head)) {
915 next = head->next;
916 pi_state = list_entry(next, struct futex_pi_state, list);
917 key = pi_state->key;
918 hb = hash_futex(&key);
919
920
921
922
923
924
925
926
927
928
929
930 if (!refcount_inc_not_zero(&pi_state->refcount)) {
931 raw_spin_unlock_irq(&curr->pi_lock);
932 cpu_relax();
933 raw_spin_lock_irq(&curr->pi_lock);
934 continue;
935 }
936 raw_spin_unlock_irq(&curr->pi_lock);
937
938 spin_lock(&hb->lock);
939 raw_spin_lock_irq(&pi_state->pi_mutex.wait_lock);
940 raw_spin_lock(&curr->pi_lock);
941
942
943
944
945 if (head->next != next) {
946
947 raw_spin_unlock(&pi_state->pi_mutex.wait_lock);
948 spin_unlock(&hb->lock);
949 put_pi_state(pi_state);
950 continue;
951 }
952
953 WARN_ON(pi_state->owner != curr);
954 WARN_ON(list_empty(&pi_state->list));
955 list_del_init(&pi_state->list);
956 pi_state->owner = NULL;
957
958 raw_spin_unlock(&curr->pi_lock);
959 raw_spin_unlock_irq(&pi_state->pi_mutex.wait_lock);
960 spin_unlock(&hb->lock);
961
962 rt_mutex_futex_unlock(&pi_state->pi_mutex);
963 put_pi_state(pi_state);
964
965 raw_spin_lock_irq(&curr->pi_lock);
966 }
967 raw_spin_unlock_irq(&curr->pi_lock);
968}
969#else
970static inline void exit_pi_state_list(struct task_struct *curr) { }
971#endif
972
973
974
975
976
977
978
979
980
981
982
983
984
985
986
987
988
989
990
991
992
993
994
995
996
997
998
999
1000
1001
1002
1003
1004
1005
1006
1007
1008
1009
1010
1011
1012
1013
1014
1015
1016
1017
1018
1019
1020
1021
1022
1023
1024
1025
1026
1027
1028
1029
1030
1031
1032
1033
1034
1035
1036
1037
1038
1039
1040
1041
1042
1043
1044
1045
1046
1047
1048
1049
1050
1051
1052
1053
1054
1055
1056
1057
1058
1059
1060
1061static int attach_to_pi_state(u32 __user *uaddr, u32 uval,
1062 struct futex_pi_state *pi_state,
1063 struct futex_pi_state **ps)
1064{
1065 pid_t pid = uval & FUTEX_TID_MASK;
1066 u32 uval2;
1067 int ret;
1068
1069
1070
1071
1072 if (unlikely(!pi_state))
1073 return -EINVAL;
1074
1075
1076
1077
1078
1079
1080
1081
1082
1083
1084
1085
1086
1087 WARN_ON(!refcount_read(&pi_state->refcount));
1088
1089
1090
1091
1092
1093 raw_spin_lock_irq(&pi_state->pi_mutex.wait_lock);
1094
1095
1096
1097
1098
1099
1100
1101 if (get_futex_value_locked(&uval2, uaddr))
1102 goto out_efault;
1103
1104 if (uval != uval2)
1105 goto out_eagain;
1106
1107
1108
1109
1110 if (uval & FUTEX_OWNER_DIED) {
1111
1112
1113
1114
1115
1116 if (!pi_state->owner) {
1117
1118
1119
1120
1121 if (pid)
1122 goto out_einval;
1123
1124
1125
1126 goto out_attach;
1127 }
1128
1129
1130
1131
1132
1133
1134
1135
1136
1137 if (!pid)
1138 goto out_attach;
1139 } else {
1140
1141
1142
1143
1144 if (!pi_state->owner)
1145 goto out_einval;
1146 }
1147
1148
1149
1150
1151
1152
1153 if (pid != task_pid_vnr(pi_state->owner))
1154 goto out_einval;
1155
1156out_attach:
1157 get_pi_state(pi_state);
1158 raw_spin_unlock_irq(&pi_state->pi_mutex.wait_lock);
1159 *ps = pi_state;
1160 return 0;
1161
1162out_einval:
1163 ret = -EINVAL;
1164 goto out_error;
1165
1166out_eagain:
1167 ret = -EAGAIN;
1168 goto out_error;
1169
1170out_efault:
1171 ret = -EFAULT;
1172 goto out_error;
1173
1174out_error:
1175 raw_spin_unlock_irq(&pi_state->pi_mutex.wait_lock);
1176 return ret;
1177}
1178
1179
1180
1181
1182
1183
1184
1185
1186static void wait_for_owner_exiting(int ret, struct task_struct *exiting)
1187{
1188 if (ret != -EBUSY) {
1189 WARN_ON_ONCE(exiting);
1190 return;
1191 }
1192
1193 if (WARN_ON_ONCE(ret == -EBUSY && !exiting))
1194 return;
1195
1196 mutex_lock(&exiting->futex_exit_mutex);
1197
1198
1199
1200
1201
1202
1203
1204
1205 mutex_unlock(&exiting->futex_exit_mutex);
1206
1207 put_task_struct(exiting);
1208}
1209
1210static int handle_exit_race(u32 __user *uaddr, u32 uval,
1211 struct task_struct *tsk)
1212{
1213 u32 uval2;
1214
1215
1216
1217
1218
1219 if (tsk && tsk->futex_state != FUTEX_STATE_DEAD)
1220 return -EBUSY;
1221
1222
1223
1224
1225
1226
1227
1228
1229
1230
1231
1232
1233
1234
1235
1236
1237
1238
1239
1240
1241
1242
1243
1244
1245
1246
1247
1248
1249
1250
1251 if (get_futex_value_locked(&uval2, uaddr))
1252 return -EFAULT;
1253
1254
1255 if (uval2 != uval)
1256 return -EAGAIN;
1257
1258
1259
1260
1261
1262
1263 return -ESRCH;
1264}
1265
1266
1267
1268
1269
1270static int attach_to_pi_owner(u32 __user *uaddr, u32 uval, union futex_key *key,
1271 struct futex_pi_state **ps,
1272 struct task_struct **exiting)
1273{
1274 pid_t pid = uval & FUTEX_TID_MASK;
1275 struct futex_pi_state *pi_state;
1276 struct task_struct *p;
1277
1278
1279
1280
1281
1282
1283
1284
1285 if (!pid)
1286 return -EAGAIN;
1287 p = find_get_task_by_vpid(pid);
1288 if (!p)
1289 return handle_exit_race(uaddr, uval, NULL);
1290
1291 if (unlikely(p->flags & PF_KTHREAD)) {
1292 put_task_struct(p);
1293 return -EPERM;
1294 }
1295
1296
1297
1298
1299
1300
1301 raw_spin_lock_irq(&p->pi_lock);
1302 if (unlikely(p->futex_state != FUTEX_STATE_OK)) {
1303
1304
1305
1306
1307
1308 int ret = handle_exit_race(uaddr, uval, p);
1309
1310 raw_spin_unlock_irq(&p->pi_lock);
1311
1312
1313
1314
1315
1316
1317
1318
1319
1320 if (ret == -EBUSY)
1321 *exiting = p;
1322 else
1323 put_task_struct(p);
1324 return ret;
1325 }
1326
1327
1328
1329
1330
1331
1332
1333 pi_state = alloc_pi_state();
1334
1335
1336
1337
1338
1339 rt_mutex_init_proxy_locked(&pi_state->pi_mutex, p);
1340
1341
1342 pi_state->key = *key;
1343
1344 WARN_ON(!list_empty(&pi_state->list));
1345 list_add(&pi_state->list, &p->pi_state_list);
1346
1347
1348
1349
1350 pi_state->owner = p;
1351 raw_spin_unlock_irq(&p->pi_lock);
1352
1353 put_task_struct(p);
1354
1355 *ps = pi_state;
1356
1357 return 0;
1358}
1359
1360static int lookup_pi_state(u32 __user *uaddr, u32 uval,
1361 struct futex_hash_bucket *hb,
1362 union futex_key *key, struct futex_pi_state **ps,
1363 struct task_struct **exiting)
1364{
1365 struct futex_q *top_waiter = futex_top_waiter(hb, key);
1366
1367
1368
1369
1370
1371 if (top_waiter)
1372 return attach_to_pi_state(uaddr, uval, top_waiter->pi_state, ps);
1373
1374
1375
1376
1377
1378 return attach_to_pi_owner(uaddr, uval, key, ps, exiting);
1379}
1380
1381static int lock_pi_update_atomic(u32 __user *uaddr, u32 uval, u32 newval)
1382{
1383 int err;
1384 u32 uninitialized_var(curval);
1385
1386 if (unlikely(should_fail_futex(true)))
1387 return -EFAULT;
1388
1389 err = cmpxchg_futex_value_locked(&curval, uaddr, uval, newval);
1390 if (unlikely(err))
1391 return err;
1392
1393
1394 return curval != uval ? -EAGAIN : 0;
1395}
1396
1397
1398
1399
1400
1401
1402
1403
1404
1405
1406
1407
1408
1409
1410
1411
1412
1413
1414
1415
1416
1417
1418
1419
1420
1421static int futex_lock_pi_atomic(u32 __user *uaddr, struct futex_hash_bucket *hb,
1422 union futex_key *key,
1423 struct futex_pi_state **ps,
1424 struct task_struct *task,
1425 struct task_struct **exiting,
1426 int set_waiters)
1427{
1428 u32 uval, newval, vpid = task_pid_vnr(task);
1429 struct futex_q *top_waiter;
1430 int ret;
1431
1432
1433
1434
1435
1436 if (get_futex_value_locked(&uval, uaddr))
1437 return -EFAULT;
1438
1439 if (unlikely(should_fail_futex(true)))
1440 return -EFAULT;
1441
1442
1443
1444
1445 if ((unlikely((uval & FUTEX_TID_MASK) == vpid)))
1446 return -EDEADLK;
1447
1448 if ((unlikely(should_fail_futex(true))))
1449 return -EDEADLK;
1450
1451
1452
1453
1454
1455 top_waiter = futex_top_waiter(hb, key);
1456 if (top_waiter)
1457 return attach_to_pi_state(uaddr, uval, top_waiter->pi_state, ps);
1458
1459
1460
1461
1462
1463
1464
1465 if (!(uval & FUTEX_TID_MASK)) {
1466
1467
1468
1469
1470 newval = uval & FUTEX_OWNER_DIED;
1471 newval |= vpid;
1472
1473
1474 if (set_waiters)
1475 newval |= FUTEX_WAITERS;
1476
1477 ret = lock_pi_update_atomic(uaddr, uval, newval);
1478
1479 return ret < 0 ? ret : 1;
1480 }
1481
1482
1483
1484
1485
1486
1487 newval = uval | FUTEX_WAITERS;
1488 ret = lock_pi_update_atomic(uaddr, uval, newval);
1489 if (ret)
1490 return ret;
1491
1492
1493
1494
1495
1496 return attach_to_pi_owner(uaddr, newval, key, ps, exiting);
1497}
1498
1499
1500
1501
1502
1503
1504
1505static void __unqueue_futex(struct futex_q *q)
1506{
1507 struct futex_hash_bucket *hb;
1508
1509 if (WARN_ON_SMP(!q->lock_ptr) || WARN_ON(plist_node_empty(&q->list)))
1510 return;
1511 lockdep_assert_held(q->lock_ptr);
1512
1513 hb = container_of(q->lock_ptr, struct futex_hash_bucket, lock);
1514 plist_del(&q->list, &hb->chain);
1515 hb_waiters_dec(hb);
1516}
1517
1518
1519
1520
1521
1522
1523
1524static void mark_wake_futex(struct wake_q_head *wake_q, struct futex_q *q)
1525{
1526 struct task_struct *p = q->task;
1527
1528 if (WARN(q->pi_state || q->rt_waiter, "refusing to wake PI futex\n"))
1529 return;
1530
1531 get_task_struct(p);
1532 __unqueue_futex(q);
1533
1534
1535
1536
1537
1538
1539
1540 smp_store_release(&q->lock_ptr, NULL);
1541
1542
1543
1544
1545
1546 wake_q_add_safe(wake_q, p);
1547}
1548
1549
1550
1551
1552static int wake_futex_pi(u32 __user *uaddr, u32 uval, struct futex_pi_state *pi_state)
1553{
1554 u32 uninitialized_var(curval), newval;
1555 struct task_struct *new_owner;
1556 bool postunlock = false;
1557 DEFINE_WAKE_Q(wake_q);
1558 int ret = 0;
1559
1560 new_owner = rt_mutex_next_owner(&pi_state->pi_mutex);
1561 if (WARN_ON_ONCE(!new_owner)) {
1562
1563
1564
1565
1566
1567
1568
1569
1570 ret = -EAGAIN;
1571 goto out_unlock;
1572 }
1573
1574
1575
1576
1577
1578
1579 newval = FUTEX_WAITERS | task_pid_vnr(new_owner);
1580
1581 if (unlikely(should_fail_futex(true)))
1582 ret = -EFAULT;
1583
1584 ret = cmpxchg_futex_value_locked(&curval, uaddr, uval, newval);
1585 if (!ret && (curval != uval)) {
1586
1587
1588
1589
1590
1591
1592 if ((FUTEX_TID_MASK & curval) == uval)
1593 ret = -EAGAIN;
1594 else
1595 ret = -EINVAL;
1596 }
1597
1598 if (ret)
1599 goto out_unlock;
1600
1601
1602
1603
1604
1605
1606 raw_spin_lock(&pi_state->owner->pi_lock);
1607 WARN_ON(list_empty(&pi_state->list));
1608 list_del_init(&pi_state->list);
1609 raw_spin_unlock(&pi_state->owner->pi_lock);
1610
1611 raw_spin_lock(&new_owner->pi_lock);
1612 WARN_ON(!list_empty(&pi_state->list));
1613 list_add(&pi_state->list, &new_owner->pi_state_list);
1614 pi_state->owner = new_owner;
1615 raw_spin_unlock(&new_owner->pi_lock);
1616
1617 postunlock = __rt_mutex_futex_unlock(&pi_state->pi_mutex, &wake_q);
1618
1619out_unlock:
1620 raw_spin_unlock_irq(&pi_state->pi_mutex.wait_lock);
1621
1622 if (postunlock)
1623 rt_mutex_postunlock(&wake_q);
1624
1625 return ret;
1626}
1627
1628
1629
1630
1631static inline void
1632double_lock_hb(struct futex_hash_bucket *hb1, struct futex_hash_bucket *hb2)
1633{
1634 if (hb1 <= hb2) {
1635 spin_lock(&hb1->lock);
1636 if (hb1 < hb2)
1637 spin_lock_nested(&hb2->lock, SINGLE_DEPTH_NESTING);
1638 } else {
1639 spin_lock(&hb2->lock);
1640 spin_lock_nested(&hb1->lock, SINGLE_DEPTH_NESTING);
1641 }
1642}
1643
1644static inline void
1645double_unlock_hb(struct futex_hash_bucket *hb1, struct futex_hash_bucket *hb2)
1646{
1647 spin_unlock(&hb1->lock);
1648 if (hb1 != hb2)
1649 spin_unlock(&hb2->lock);
1650}
1651
1652
1653
1654
1655static int
1656futex_wake(u32 __user *uaddr, unsigned int flags, int nr_wake, u32 bitset)
1657{
1658 struct futex_hash_bucket *hb;
1659 struct futex_q *this, *next;
1660 union futex_key key = FUTEX_KEY_INIT;
1661 int ret;
1662 DEFINE_WAKE_Q(wake_q);
1663
1664 if (!bitset)
1665 return -EINVAL;
1666
1667 ret = get_futex_key(uaddr, flags & FLAGS_SHARED, &key, FUTEX_READ);
1668 if (unlikely(ret != 0))
1669 goto out;
1670
1671 hb = hash_futex(&key);
1672
1673
1674 if (!hb_waiters_pending(hb))
1675 goto out_put_key;
1676
1677 spin_lock(&hb->lock);
1678
1679 plist_for_each_entry_safe(this, next, &hb->chain, list) {
1680 if (match_futex (&this->key, &key)) {
1681 if (this->pi_state || this->rt_waiter) {
1682 ret = -EINVAL;
1683 break;
1684 }
1685
1686
1687 if (!(this->bitset & bitset))
1688 continue;
1689
1690 mark_wake_futex(&wake_q, this);
1691 if (++ret >= nr_wake)
1692 break;
1693 }
1694 }
1695
1696 spin_unlock(&hb->lock);
1697 wake_up_q(&wake_q);
1698out_put_key:
1699 put_futex_key(&key);
1700out:
1701 return ret;
1702}
1703
1704static int futex_atomic_op_inuser(unsigned int encoded_op, u32 __user *uaddr)
1705{
1706 unsigned int op = (encoded_op & 0x70000000) >> 28;
1707 unsigned int cmp = (encoded_op & 0x0f000000) >> 24;
1708 int oparg = sign_extend32((encoded_op & 0x00fff000) >> 12, 11);
1709 int cmparg = sign_extend32(encoded_op & 0x00000fff, 11);
1710 int oldval, ret;
1711
1712 if (encoded_op & (FUTEX_OP_OPARG_SHIFT << 28)) {
1713 if (oparg < 0 || oparg > 31) {
1714 char comm[sizeof(current->comm)];
1715
1716
1717
1718
1719 pr_info_ratelimited("futex_wake_op: %s tries to shift op by %d; fix this program\n",
1720 get_task_comm(comm, current), oparg);
1721 oparg &= 31;
1722 }
1723 oparg = 1 << oparg;
1724 }
1725
1726 if (!access_ok(uaddr, sizeof(u32)))
1727 return -EFAULT;
1728
1729 ret = arch_futex_atomic_op_inuser(op, oparg, &oldval, uaddr);
1730 if (ret)
1731 return ret;
1732
1733 switch (cmp) {
1734 case FUTEX_OP_CMP_EQ:
1735 return oldval == cmparg;
1736 case FUTEX_OP_CMP_NE:
1737 return oldval != cmparg;
1738 case FUTEX_OP_CMP_LT:
1739 return oldval < cmparg;
1740 case FUTEX_OP_CMP_GE:
1741 return oldval >= cmparg;
1742 case FUTEX_OP_CMP_LE:
1743 return oldval <= cmparg;
1744 case FUTEX_OP_CMP_GT:
1745 return oldval > cmparg;
1746 default:
1747 return -ENOSYS;
1748 }
1749}
1750
1751
1752
1753
1754
1755static int
1756futex_wake_op(u32 __user *uaddr1, unsigned int flags, u32 __user *uaddr2,
1757 int nr_wake, int nr_wake2, int op)
1758{
1759 union futex_key key1 = FUTEX_KEY_INIT, key2 = FUTEX_KEY_INIT;
1760 struct futex_hash_bucket *hb1, *hb2;
1761 struct futex_q *this, *next;
1762 int ret, op_ret;
1763 DEFINE_WAKE_Q(wake_q);
1764
1765retry:
1766 ret = get_futex_key(uaddr1, flags & FLAGS_SHARED, &key1, FUTEX_READ);
1767 if (unlikely(ret != 0))
1768 goto out;
1769 ret = get_futex_key(uaddr2, flags & FLAGS_SHARED, &key2, FUTEX_WRITE);
1770 if (unlikely(ret != 0))
1771 goto out_put_key1;
1772
1773 hb1 = hash_futex(&key1);
1774 hb2 = hash_futex(&key2);
1775
1776retry_private:
1777 double_lock_hb(hb1, hb2);
1778 op_ret = futex_atomic_op_inuser(op, uaddr2);
1779 if (unlikely(op_ret < 0)) {
1780 double_unlock_hb(hb1, hb2);
1781
1782 if (!IS_ENABLED(CONFIG_MMU) ||
1783 unlikely(op_ret != -EFAULT && op_ret != -EAGAIN)) {
1784
1785
1786
1787
1788 ret = op_ret;
1789 goto out_put_keys;
1790 }
1791
1792 if (op_ret == -EFAULT) {
1793 ret = fault_in_user_writeable(uaddr2);
1794 if (ret)
1795 goto out_put_keys;
1796 }
1797
1798 if (!(flags & FLAGS_SHARED)) {
1799 cond_resched();
1800 goto retry_private;
1801 }
1802
1803 put_futex_key(&key2);
1804 put_futex_key(&key1);
1805 cond_resched();
1806 goto retry;
1807 }
1808
1809 plist_for_each_entry_safe(this, next, &hb1->chain, list) {
1810 if (match_futex (&this->key, &key1)) {
1811 if (this->pi_state || this->rt_waiter) {
1812 ret = -EINVAL;
1813 goto out_unlock;
1814 }
1815 mark_wake_futex(&wake_q, this);
1816 if (++ret >= nr_wake)
1817 break;
1818 }
1819 }
1820
1821 if (op_ret > 0) {
1822 op_ret = 0;
1823 plist_for_each_entry_safe(this, next, &hb2->chain, list) {
1824 if (match_futex (&this->key, &key2)) {
1825 if (this->pi_state || this->rt_waiter) {
1826 ret = -EINVAL;
1827 goto out_unlock;
1828 }
1829 mark_wake_futex(&wake_q, this);
1830 if (++op_ret >= nr_wake2)
1831 break;
1832 }
1833 }
1834 ret += op_ret;
1835 }
1836
1837out_unlock:
1838 double_unlock_hb(hb1, hb2);
1839 wake_up_q(&wake_q);
1840out_put_keys:
1841 put_futex_key(&key2);
1842out_put_key1:
1843 put_futex_key(&key1);
1844out:
1845 return ret;
1846}
1847
1848
1849
1850
1851
1852
1853
1854
1855static inline
1856void requeue_futex(struct futex_q *q, struct futex_hash_bucket *hb1,
1857 struct futex_hash_bucket *hb2, union futex_key *key2)
1858{
1859
1860
1861
1862
1863
1864 if (likely(&hb1->chain != &hb2->chain)) {
1865 plist_del(&q->list, &hb1->chain);
1866 hb_waiters_dec(hb1);
1867 hb_waiters_inc(hb2);
1868 plist_add(&q->list, &hb2->chain);
1869 q->lock_ptr = &hb2->lock;
1870 }
1871 get_futex_key_refs(key2);
1872 q->key = *key2;
1873}
1874
1875
1876
1877
1878
1879
1880
1881
1882
1883
1884
1885
1886
1887
1888
1889static inline
1890void requeue_pi_wake_futex(struct futex_q *q, union futex_key *key,
1891 struct futex_hash_bucket *hb)
1892{
1893 get_futex_key_refs(key);
1894 q->key = *key;
1895
1896 __unqueue_futex(q);
1897
1898 WARN_ON(!q->rt_waiter);
1899 q->rt_waiter = NULL;
1900
1901 q->lock_ptr = &hb->lock;
1902
1903 wake_up_state(q->task, TASK_NORMAL);
1904}
1905
1906
1907
1908
1909
1910
1911
1912
1913
1914
1915
1916
1917
1918
1919
1920
1921
1922
1923
1924
1925
1926
1927
1928
1929
1930
1931
1932static int
1933futex_proxy_trylock_atomic(u32 __user *pifutex, struct futex_hash_bucket *hb1,
1934 struct futex_hash_bucket *hb2, union futex_key *key1,
1935 union futex_key *key2, struct futex_pi_state **ps,
1936 struct task_struct **exiting, int set_waiters)
1937{
1938 struct futex_q *top_waiter = NULL;
1939 u32 curval;
1940 int ret, vpid;
1941
1942 if (get_futex_value_locked(&curval, pifutex))
1943 return -EFAULT;
1944
1945 if (unlikely(should_fail_futex(true)))
1946 return -EFAULT;
1947
1948
1949
1950
1951
1952
1953
1954
1955
1956 top_waiter = futex_top_waiter(hb1, key1);
1957
1958
1959 if (!top_waiter)
1960 return 0;
1961
1962
1963 if (!match_futex(top_waiter->requeue_pi_key, key2))
1964 return -EINVAL;
1965
1966
1967
1968
1969
1970
1971 vpid = task_pid_vnr(top_waiter->task);
1972 ret = futex_lock_pi_atomic(pifutex, hb2, key2, ps, top_waiter->task,
1973 exiting, set_waiters);
1974 if (ret == 1) {
1975 requeue_pi_wake_futex(top_waiter, key2, hb2);
1976 return vpid;
1977 }
1978 return ret;
1979}
1980
1981
1982
1983
1984
1985
1986
1987
1988
1989
1990
1991
1992
1993
1994
1995
1996
1997
1998
1999static int futex_requeue(u32 __user *uaddr1, unsigned int flags,
2000 u32 __user *uaddr2, int nr_wake, int nr_requeue,
2001 u32 *cmpval, int requeue_pi)
2002{
2003 union futex_key key1 = FUTEX_KEY_INIT, key2 = FUTEX_KEY_INIT;
2004 int drop_count = 0, task_count = 0, ret;
2005 struct futex_pi_state *pi_state = NULL;
2006 struct futex_hash_bucket *hb1, *hb2;
2007 struct futex_q *this, *next;
2008 DEFINE_WAKE_Q(wake_q);
2009
2010 if (nr_wake < 0 || nr_requeue < 0)
2011 return -EINVAL;
2012
2013
2014
2015
2016
2017
2018
2019 if (!IS_ENABLED(CONFIG_FUTEX_PI) && requeue_pi)
2020 return -ENOSYS;
2021
2022 if (requeue_pi) {
2023
2024
2025
2026
2027 if (uaddr1 == uaddr2)
2028 return -EINVAL;
2029
2030
2031
2032
2033
2034 if (refill_pi_state_cache())
2035 return -ENOMEM;
2036
2037
2038
2039
2040
2041
2042
2043
2044
2045
2046 if (nr_wake != 1)
2047 return -EINVAL;
2048 }
2049
2050retry:
2051 ret = get_futex_key(uaddr1, flags & FLAGS_SHARED, &key1, FUTEX_READ);
2052 if (unlikely(ret != 0))
2053 goto out;
2054 ret = get_futex_key(uaddr2, flags & FLAGS_SHARED, &key2,
2055 requeue_pi ? FUTEX_WRITE : FUTEX_READ);
2056 if (unlikely(ret != 0))
2057 goto out_put_key1;
2058
2059
2060
2061
2062
2063 if (requeue_pi && match_futex(&key1, &key2)) {
2064 ret = -EINVAL;
2065 goto out_put_keys;
2066 }
2067
2068 hb1 = hash_futex(&key1);
2069 hb2 = hash_futex(&key2);
2070
2071retry_private:
2072 hb_waiters_inc(hb2);
2073 double_lock_hb(hb1, hb2);
2074
2075 if (likely(cmpval != NULL)) {
2076 u32 curval;
2077
2078 ret = get_futex_value_locked(&curval, uaddr1);
2079
2080 if (unlikely(ret)) {
2081 double_unlock_hb(hb1, hb2);
2082 hb_waiters_dec(hb2);
2083
2084 ret = get_user(curval, uaddr1);
2085 if (ret)
2086 goto out_put_keys;
2087
2088 if (!(flags & FLAGS_SHARED))
2089 goto retry_private;
2090
2091 put_futex_key(&key2);
2092 put_futex_key(&key1);
2093 goto retry;
2094 }
2095 if (curval != *cmpval) {
2096 ret = -EAGAIN;
2097 goto out_unlock;
2098 }
2099 }
2100
2101 if (requeue_pi && (task_count - nr_wake < nr_requeue)) {
2102 struct task_struct *exiting = NULL;
2103
2104
2105
2106
2107
2108
2109
2110 ret = futex_proxy_trylock_atomic(uaddr2, hb1, hb2, &key1,
2111 &key2, &pi_state,
2112 &exiting, nr_requeue);
2113
2114
2115
2116
2117
2118
2119
2120
2121
2122
2123 if (ret > 0) {
2124 WARN_ON(pi_state);
2125 drop_count++;
2126 task_count++;
2127
2128
2129
2130
2131
2132
2133
2134
2135
2136
2137
2138
2139 ret = lookup_pi_state(uaddr2, ret, hb2, &key2,
2140 &pi_state, &exiting);
2141 }
2142
2143 switch (ret) {
2144 case 0:
2145
2146 break;
2147
2148
2149 case -EFAULT:
2150 double_unlock_hb(hb1, hb2);
2151 hb_waiters_dec(hb2);
2152 put_futex_key(&key2);
2153 put_futex_key(&key1);
2154 ret = fault_in_user_writeable(uaddr2);
2155 if (!ret)
2156 goto retry;
2157 goto out;
2158 case -EBUSY:
2159 case -EAGAIN:
2160
2161
2162
2163
2164
2165
2166 double_unlock_hb(hb1, hb2);
2167 hb_waiters_dec(hb2);
2168 put_futex_key(&key2);
2169 put_futex_key(&key1);
2170
2171
2172
2173
2174
2175 wait_for_owner_exiting(ret, exiting);
2176 cond_resched();
2177 goto retry;
2178 default:
2179 goto out_unlock;
2180 }
2181 }
2182
2183 plist_for_each_entry_safe(this, next, &hb1->chain, list) {
2184 if (task_count - nr_wake >= nr_requeue)
2185 break;
2186
2187 if (!match_futex(&this->key, &key1))
2188 continue;
2189
2190
2191
2192
2193
2194
2195
2196
2197 if ((requeue_pi && !this->rt_waiter) ||
2198 (!requeue_pi && this->rt_waiter) ||
2199 this->pi_state) {
2200 ret = -EINVAL;
2201 break;
2202 }
2203
2204
2205
2206
2207
2208
2209 if (++task_count <= nr_wake && !requeue_pi) {
2210 mark_wake_futex(&wake_q, this);
2211 continue;
2212 }
2213
2214
2215 if (requeue_pi && !match_futex(this->requeue_pi_key, &key2)) {
2216 ret = -EINVAL;
2217 break;
2218 }
2219
2220
2221
2222
2223
2224 if (requeue_pi) {
2225
2226
2227
2228
2229
2230 get_pi_state(pi_state);
2231 this->pi_state = pi_state;
2232 ret = rt_mutex_start_proxy_lock(&pi_state->pi_mutex,
2233 this->rt_waiter,
2234 this->task);
2235 if (ret == 1) {
2236
2237
2238
2239
2240
2241
2242
2243
2244 requeue_pi_wake_futex(this, &key2, hb2);
2245 drop_count++;
2246 continue;
2247 } else if (ret) {
2248
2249
2250
2251
2252
2253
2254
2255
2256 this->pi_state = NULL;
2257 put_pi_state(pi_state);
2258
2259
2260
2261
2262 break;
2263 }
2264 }
2265 requeue_futex(this, hb1, hb2, &key2);
2266 drop_count++;
2267 }
2268
2269
2270
2271
2272
2273
2274 put_pi_state(pi_state);
2275
2276out_unlock:
2277 double_unlock_hb(hb1, hb2);
2278 wake_up_q(&wake_q);
2279 hb_waiters_dec(hb2);
2280
2281
2282
2283
2284
2285
2286
2287 while (--drop_count >= 0)
2288 drop_futex_key_refs(&key1);
2289
2290out_put_keys:
2291 put_futex_key(&key2);
2292out_put_key1:
2293 put_futex_key(&key1);
2294out:
2295 return ret ? ret : task_count;
2296}
2297
2298
2299static inline struct futex_hash_bucket *queue_lock(struct futex_q *q)
2300 __acquires(&hb->lock)
2301{
2302 struct futex_hash_bucket *hb;
2303
2304 hb = hash_futex(&q->key);
2305
2306
2307
2308
2309
2310
2311
2312
2313
2314 hb_waiters_inc(hb);
2315
2316 q->lock_ptr = &hb->lock;
2317
2318 spin_lock(&hb->lock);
2319 return hb;
2320}
2321
2322static inline void
2323queue_unlock(struct futex_hash_bucket *hb)
2324 __releases(&hb->lock)
2325{
2326 spin_unlock(&hb->lock);
2327 hb_waiters_dec(hb);
2328}
2329
2330static inline void __queue_me(struct futex_q *q, struct futex_hash_bucket *hb)
2331{
2332 int prio;
2333
2334
2335
2336
2337
2338
2339
2340
2341
2342 prio = min(current->normal_prio, MAX_RT_PRIO);
2343
2344 plist_node_init(&q->list, prio);
2345 plist_add(&q->list, &hb->chain);
2346 q->task = current;
2347}
2348
2349
2350
2351
2352
2353
2354
2355
2356
2357
2358
2359
2360
2361static inline void queue_me(struct futex_q *q, struct futex_hash_bucket *hb)
2362 __releases(&hb->lock)
2363{
2364 __queue_me(q, hb);
2365 spin_unlock(&hb->lock);
2366}
2367
2368
2369
2370
2371
2372
2373
2374
2375
2376
2377
2378
2379static int unqueue_me(struct futex_q *q)
2380{
2381 spinlock_t *lock_ptr;
2382 int ret = 0;
2383
2384
2385retry:
2386
2387
2388
2389
2390
2391 lock_ptr = READ_ONCE(q->lock_ptr);
2392 if (lock_ptr != NULL) {
2393 spin_lock(lock_ptr);
2394
2395
2396
2397
2398
2399
2400
2401
2402
2403
2404
2405
2406
2407 if (unlikely(lock_ptr != q->lock_ptr)) {
2408 spin_unlock(lock_ptr);
2409 goto retry;
2410 }
2411 __unqueue_futex(q);
2412
2413 BUG_ON(q->pi_state);
2414
2415 spin_unlock(lock_ptr);
2416 ret = 1;
2417 }
2418
2419 drop_futex_key_refs(&q->key);
2420 return ret;
2421}
2422
2423
2424
2425
2426
2427
2428static void unqueue_me_pi(struct futex_q *q)
2429 __releases(q->lock_ptr)
2430{
2431 __unqueue_futex(q);
2432
2433 BUG_ON(!q->pi_state);
2434 put_pi_state(q->pi_state);
2435 q->pi_state = NULL;
2436
2437 spin_unlock(q->lock_ptr);
2438}
2439
2440static int fixup_pi_state_owner(u32 __user *uaddr, struct futex_q *q,
2441 struct task_struct *argowner)
2442{
2443 struct futex_pi_state *pi_state = q->pi_state;
2444 u32 uval, uninitialized_var(curval), newval;
2445 struct task_struct *oldowner, *newowner;
2446 u32 newtid;
2447 int ret, err = 0;
2448
2449 lockdep_assert_held(q->lock_ptr);
2450
2451 raw_spin_lock_irq(&pi_state->pi_mutex.wait_lock);
2452
2453 oldowner = pi_state->owner;
2454
2455
2456
2457
2458
2459
2460
2461
2462
2463
2464
2465
2466
2467
2468
2469
2470
2471
2472
2473
2474
2475
2476
2477
2478retry:
2479 if (!argowner) {
2480 if (oldowner != current) {
2481
2482
2483
2484
2485 ret = 0;
2486 goto out_unlock;
2487 }
2488
2489 if (__rt_mutex_futex_trylock(&pi_state->pi_mutex)) {
2490
2491 ret = 0;
2492 goto out_unlock;
2493 }
2494
2495
2496
2497
2498 newowner = rt_mutex_owner(&pi_state->pi_mutex);
2499 BUG_ON(!newowner);
2500 } else {
2501 WARN_ON_ONCE(argowner != current);
2502 if (oldowner == current) {
2503
2504
2505
2506
2507 ret = 0;
2508 goto out_unlock;
2509 }
2510 newowner = argowner;
2511 }
2512
2513 newtid = task_pid_vnr(newowner) | FUTEX_WAITERS;
2514
2515 if (!pi_state->owner)
2516 newtid |= FUTEX_OWNER_DIED;
2517
2518 err = get_futex_value_locked(&uval, uaddr);
2519 if (err)
2520 goto handle_err;
2521
2522 for (;;) {
2523 newval = (uval & FUTEX_OWNER_DIED) | newtid;
2524
2525 err = cmpxchg_futex_value_locked(&curval, uaddr, uval, newval);
2526 if (err)
2527 goto handle_err;
2528
2529 if (curval == uval)
2530 break;
2531 uval = curval;
2532 }
2533
2534
2535
2536
2537
2538 if (pi_state->owner != NULL) {
2539 raw_spin_lock(&pi_state->owner->pi_lock);
2540 WARN_ON(list_empty(&pi_state->list));
2541 list_del_init(&pi_state->list);
2542 raw_spin_unlock(&pi_state->owner->pi_lock);
2543 }
2544
2545 pi_state->owner = newowner;
2546
2547 raw_spin_lock(&newowner->pi_lock);
2548 WARN_ON(!list_empty(&pi_state->list));
2549 list_add(&pi_state->list, &newowner->pi_state_list);
2550 raw_spin_unlock(&newowner->pi_lock);
2551 raw_spin_unlock_irq(&pi_state->pi_mutex.wait_lock);
2552
2553 return 0;
2554
2555
2556
2557
2558
2559
2560
2561
2562
2563
2564
2565
2566
2567
2568handle_err:
2569 raw_spin_unlock_irq(&pi_state->pi_mutex.wait_lock);
2570 spin_unlock(q->lock_ptr);
2571
2572 switch (err) {
2573 case -EFAULT:
2574 ret = fault_in_user_writeable(uaddr);
2575 break;
2576
2577 case -EAGAIN:
2578 cond_resched();
2579 ret = 0;
2580 break;
2581
2582 default:
2583 WARN_ON_ONCE(1);
2584 ret = err;
2585 break;
2586 }
2587
2588 spin_lock(q->lock_ptr);
2589 raw_spin_lock_irq(&pi_state->pi_mutex.wait_lock);
2590
2591
2592
2593
2594 if (pi_state->owner != oldowner) {
2595 ret = 0;
2596 goto out_unlock;
2597 }
2598
2599 if (ret)
2600 goto out_unlock;
2601
2602 goto retry;
2603
2604out_unlock:
2605 raw_spin_unlock_irq(&pi_state->pi_mutex.wait_lock);
2606 return ret;
2607}
2608
2609static long futex_wait_restart(struct restart_block *restart);
2610
2611
2612
2613
2614
2615
2616
2617
2618
2619
2620
2621
2622
2623
2624
2625
2626static int fixup_owner(u32 __user *uaddr, struct futex_q *q, int locked)
2627{
2628 int ret = 0;
2629
2630 if (locked) {
2631
2632
2633
2634
2635
2636
2637
2638
2639 if (q->pi_state->owner != current)
2640 ret = fixup_pi_state_owner(uaddr, q, current);
2641 goto out;
2642 }
2643
2644
2645
2646
2647
2648
2649
2650
2651
2652 if (q->pi_state->owner == current) {
2653 ret = fixup_pi_state_owner(uaddr, q, NULL);
2654 goto out;
2655 }
2656
2657
2658
2659
2660
2661 if (rt_mutex_owner(&q->pi_state->pi_mutex) == current) {
2662 printk(KERN_ERR "fixup_owner: ret = %d pi-mutex: %p "
2663 "pi-state %p\n", ret,
2664 q->pi_state->pi_mutex.owner,
2665 q->pi_state->owner);
2666 }
2667
2668out:
2669 return ret ? ret : locked;
2670}
2671
2672
2673
2674
2675
2676
2677
2678static void futex_wait_queue_me(struct futex_hash_bucket *hb, struct futex_q *q,
2679 struct hrtimer_sleeper *timeout)
2680{
2681
2682
2683
2684
2685
2686
2687 set_current_state(TASK_INTERRUPTIBLE);
2688 queue_me(q, hb);
2689
2690
2691 if (timeout)
2692 hrtimer_sleeper_start_expires(timeout, HRTIMER_MODE_ABS);
2693
2694
2695
2696
2697
2698 if (likely(!plist_node_empty(&q->list))) {
2699
2700
2701
2702
2703
2704 if (!timeout || timeout->task)
2705 freezable_schedule();
2706 }
2707 __set_current_state(TASK_RUNNING);
2708}
2709
2710
2711
2712
2713
2714
2715
2716
2717
2718
2719
2720
2721
2722
2723
2724
2725
2726
2727static int futex_wait_setup(u32 __user *uaddr, u32 val, unsigned int flags,
2728 struct futex_q *q, struct futex_hash_bucket **hb)
2729{
2730 u32 uval;
2731 int ret;
2732
2733
2734
2735
2736
2737
2738
2739
2740
2741
2742
2743
2744
2745
2746
2747
2748
2749
2750
2751retry:
2752 ret = get_futex_key(uaddr, flags & FLAGS_SHARED, &q->key, FUTEX_READ);
2753 if (unlikely(ret != 0))
2754 return ret;
2755
2756retry_private:
2757 *hb = queue_lock(q);
2758
2759 ret = get_futex_value_locked(&uval, uaddr);
2760
2761 if (ret) {
2762 queue_unlock(*hb);
2763
2764 ret = get_user(uval, uaddr);
2765 if (ret)
2766 goto out;
2767
2768 if (!(flags & FLAGS_SHARED))
2769 goto retry_private;
2770
2771 put_futex_key(&q->key);
2772 goto retry;
2773 }
2774
2775 if (uval != val) {
2776 queue_unlock(*hb);
2777 ret = -EWOULDBLOCK;
2778 }
2779
2780out:
2781 if (ret)
2782 put_futex_key(&q->key);
2783 return ret;
2784}
2785
2786static int futex_wait(u32 __user *uaddr, unsigned int flags, u32 val,
2787 ktime_t *abs_time, u32 bitset)
2788{
2789 struct hrtimer_sleeper timeout, *to;
2790 struct restart_block *restart;
2791 struct futex_hash_bucket *hb;
2792 struct futex_q q = futex_q_init;
2793 int ret;
2794
2795 if (!bitset)
2796 return -EINVAL;
2797 q.bitset = bitset;
2798
2799 to = futex_setup_timer(abs_time, &timeout, flags,
2800 current->timer_slack_ns);
2801retry:
2802
2803
2804
2805
2806 ret = futex_wait_setup(uaddr, val, flags, &q, &hb);
2807 if (ret)
2808 goto out;
2809
2810
2811 futex_wait_queue_me(hb, &q, to);
2812
2813
2814 ret = 0;
2815
2816 if (!unqueue_me(&q))
2817 goto out;
2818 ret = -ETIMEDOUT;
2819 if (to && !to->task)
2820 goto out;
2821
2822
2823
2824
2825
2826 if (!signal_pending(current))
2827 goto retry;
2828
2829 ret = -ERESTARTSYS;
2830 if (!abs_time)
2831 goto out;
2832
2833 restart = ¤t->restart_block;
2834 restart->fn = futex_wait_restart;
2835 restart->futex.uaddr = uaddr;
2836 restart->futex.val = val;
2837 restart->futex.time = *abs_time;
2838 restart->futex.bitset = bitset;
2839 restart->futex.flags = flags | FLAGS_HAS_TIMEOUT;
2840
2841 ret = -ERESTART_RESTARTBLOCK;
2842
2843out:
2844 if (to) {
2845 hrtimer_cancel(&to->timer);
2846 destroy_hrtimer_on_stack(&to->timer);
2847 }
2848 return ret;
2849}
2850
2851
2852static long futex_wait_restart(struct restart_block *restart)
2853{
2854 u32 __user *uaddr = restart->futex.uaddr;
2855 ktime_t t, *tp = NULL;
2856
2857 if (restart->futex.flags & FLAGS_HAS_TIMEOUT) {
2858 t = restart->futex.time;
2859 tp = &t;
2860 }
2861 restart->fn = do_no_restart_syscall;
2862
2863 return (long)futex_wait(uaddr, restart->futex.flags,
2864 restart->futex.val, tp, restart->futex.bitset);
2865}
2866
2867
2868
2869
2870
2871
2872
2873
2874
2875
2876
2877static int futex_lock_pi(u32 __user *uaddr, unsigned int flags,
2878 ktime_t *time, int trylock)
2879{
2880 struct hrtimer_sleeper timeout, *to;
2881 struct futex_pi_state *pi_state = NULL;
2882 struct task_struct *exiting = NULL;
2883 struct rt_mutex_waiter rt_waiter;
2884 struct futex_hash_bucket *hb;
2885 struct futex_q q = futex_q_init;
2886 int res, ret;
2887
2888 if (!IS_ENABLED(CONFIG_FUTEX_PI))
2889 return -ENOSYS;
2890
2891 if (refill_pi_state_cache())
2892 return -ENOMEM;
2893
2894 to = futex_setup_timer(time, &timeout, FLAGS_CLOCKRT, 0);
2895
2896retry:
2897 ret = get_futex_key(uaddr, flags & FLAGS_SHARED, &q.key, FUTEX_WRITE);
2898 if (unlikely(ret != 0))
2899 goto out;
2900
2901retry_private:
2902 hb = queue_lock(&q);
2903
2904 ret = futex_lock_pi_atomic(uaddr, hb, &q.key, &q.pi_state, current,
2905 &exiting, 0);
2906 if (unlikely(ret)) {
2907
2908
2909
2910
2911 switch (ret) {
2912 case 1:
2913
2914 ret = 0;
2915 goto out_unlock_put_key;
2916 case -EFAULT:
2917 goto uaddr_faulted;
2918 case -EBUSY:
2919 case -EAGAIN:
2920
2921
2922
2923
2924
2925
2926 queue_unlock(hb);
2927 put_futex_key(&q.key);
2928
2929
2930
2931
2932
2933 wait_for_owner_exiting(ret, exiting);
2934 cond_resched();
2935 goto retry;
2936 default:
2937 goto out_unlock_put_key;
2938 }
2939 }
2940
2941 WARN_ON(!q.pi_state);
2942
2943
2944
2945
2946 __queue_me(&q, hb);
2947
2948 if (trylock) {
2949 ret = rt_mutex_futex_trylock(&q.pi_state->pi_mutex);
2950
2951 ret = ret ? 0 : -EWOULDBLOCK;
2952 goto no_block;
2953 }
2954
2955 rt_mutex_init_waiter(&rt_waiter);
2956
2957
2958
2959
2960
2961
2962
2963
2964
2965
2966
2967
2968
2969
2970 raw_spin_lock_irq(&q.pi_state->pi_mutex.wait_lock);
2971 spin_unlock(q.lock_ptr);
2972
2973
2974
2975
2976
2977 ret = __rt_mutex_start_proxy_lock(&q.pi_state->pi_mutex, &rt_waiter, current);
2978 raw_spin_unlock_irq(&q.pi_state->pi_mutex.wait_lock);
2979
2980 if (ret) {
2981 if (ret == 1)
2982 ret = 0;
2983 goto cleanup;
2984 }
2985
2986 if (unlikely(to))
2987 hrtimer_sleeper_start_expires(to, HRTIMER_MODE_ABS);
2988
2989 ret = rt_mutex_wait_proxy_lock(&q.pi_state->pi_mutex, to, &rt_waiter);
2990
2991cleanup:
2992 spin_lock(q.lock_ptr);
2993
2994
2995
2996
2997
2998
2999
3000
3001
3002 if (ret && !rt_mutex_cleanup_proxy_lock(&q.pi_state->pi_mutex, &rt_waiter))
3003 ret = 0;
3004
3005no_block:
3006
3007
3008
3009
3010 res = fixup_owner(uaddr, &q, !ret);
3011
3012
3013
3014
3015 if (res)
3016 ret = (res < 0) ? res : 0;
3017
3018
3019
3020
3021
3022 if (ret && (rt_mutex_owner(&q.pi_state->pi_mutex) == current)) {
3023 pi_state = q.pi_state;
3024 get_pi_state(pi_state);
3025 }
3026
3027
3028 unqueue_me_pi(&q);
3029
3030 if (pi_state) {
3031 rt_mutex_futex_unlock(&pi_state->pi_mutex);
3032 put_pi_state(pi_state);
3033 }
3034
3035 goto out_put_key;
3036
3037out_unlock_put_key:
3038 queue_unlock(hb);
3039
3040out_put_key:
3041 put_futex_key(&q.key);
3042out:
3043 if (to) {
3044 hrtimer_cancel(&to->timer);
3045 destroy_hrtimer_on_stack(&to->timer);
3046 }
3047 return ret != -EINTR ? ret : -ERESTARTNOINTR;
3048
3049uaddr_faulted:
3050 queue_unlock(hb);
3051
3052 ret = fault_in_user_writeable(uaddr);
3053 if (ret)
3054 goto out_put_key;
3055
3056 if (!(flags & FLAGS_SHARED))
3057 goto retry_private;
3058
3059 put_futex_key(&q.key);
3060 goto retry;
3061}
3062
3063
3064
3065
3066
3067
3068static int futex_unlock_pi(u32 __user *uaddr, unsigned int flags)
3069{
3070 u32 uninitialized_var(curval), uval, vpid = task_pid_vnr(current);
3071 union futex_key key = FUTEX_KEY_INIT;
3072 struct futex_hash_bucket *hb;
3073 struct futex_q *top_waiter;
3074 int ret;
3075
3076 if (!IS_ENABLED(CONFIG_FUTEX_PI))
3077 return -ENOSYS;
3078
3079retry:
3080 if (get_user(uval, uaddr))
3081 return -EFAULT;
3082
3083
3084
3085 if ((uval & FUTEX_TID_MASK) != vpid)
3086 return -EPERM;
3087
3088 ret = get_futex_key(uaddr, flags & FLAGS_SHARED, &key, FUTEX_WRITE);
3089 if (ret)
3090 return ret;
3091
3092 hb = hash_futex(&key);
3093 spin_lock(&hb->lock);
3094
3095
3096
3097
3098
3099
3100 top_waiter = futex_top_waiter(hb, &key);
3101 if (top_waiter) {
3102 struct futex_pi_state *pi_state = top_waiter->pi_state;
3103
3104 ret = -EINVAL;
3105 if (!pi_state)
3106 goto out_unlock;
3107
3108
3109
3110
3111
3112 if (pi_state->owner != current)
3113 goto out_unlock;
3114
3115 get_pi_state(pi_state);
3116
3117
3118
3119
3120
3121
3122
3123
3124
3125
3126 raw_spin_lock_irq(&pi_state->pi_mutex.wait_lock);
3127 spin_unlock(&hb->lock);
3128
3129
3130 ret = wake_futex_pi(uaddr, uval, pi_state);
3131
3132 put_pi_state(pi_state);
3133
3134
3135
3136
3137 if (!ret)
3138 goto out_putkey;
3139
3140
3141
3142
3143 if (ret == -EFAULT)
3144 goto pi_faulted;
3145
3146
3147
3148
3149 if (ret == -EAGAIN)
3150 goto pi_retry;
3151
3152
3153
3154
3155 goto out_putkey;
3156 }
3157
3158
3159
3160
3161
3162
3163
3164
3165 if ((ret = cmpxchg_futex_value_locked(&curval, uaddr, uval, 0))) {
3166 spin_unlock(&hb->lock);
3167 switch (ret) {
3168 case -EFAULT:
3169 goto pi_faulted;
3170
3171 case -EAGAIN:
3172 goto pi_retry;
3173
3174 default:
3175 WARN_ON_ONCE(1);
3176 goto out_putkey;
3177 }
3178 }
3179
3180
3181
3182
3183 ret = (curval == uval) ? 0 : -EAGAIN;
3184
3185out_unlock:
3186 spin_unlock(&hb->lock);
3187out_putkey:
3188 put_futex_key(&key);
3189 return ret;
3190
3191pi_retry:
3192 put_futex_key(&key);
3193 cond_resched();
3194 goto retry;
3195
3196pi_faulted:
3197 put_futex_key(&key);
3198
3199 ret = fault_in_user_writeable(uaddr);
3200 if (!ret)
3201 goto retry;
3202
3203 return ret;
3204}
3205
3206
3207
3208
3209
3210
3211
3212
3213
3214
3215
3216
3217
3218
3219
3220
3221
3222static inline
3223int handle_early_requeue_pi_wakeup(struct futex_hash_bucket *hb,
3224 struct futex_q *q, union futex_key *key2,
3225 struct hrtimer_sleeper *timeout)
3226{
3227 int ret = 0;
3228
3229
3230
3231
3232
3233
3234
3235
3236 if (!match_futex(&q->key, key2)) {
3237 WARN_ON(q->lock_ptr && (&hb->lock != q->lock_ptr));
3238
3239
3240
3241
3242 plist_del(&q->list, &hb->chain);
3243 hb_waiters_dec(hb);
3244
3245
3246 ret = -EWOULDBLOCK;
3247 if (timeout && !timeout->task)
3248 ret = -ETIMEDOUT;
3249 else if (signal_pending(current))
3250 ret = -ERESTARTNOINTR;
3251 }
3252 return ret;
3253}
3254
3255
3256
3257
3258
3259
3260
3261
3262
3263
3264
3265
3266
3267
3268
3269
3270
3271
3272
3273
3274
3275
3276
3277
3278
3279
3280
3281
3282
3283
3284
3285
3286
3287
3288
3289
3290
3291
3292
3293
3294
3295static int futex_wait_requeue_pi(u32 __user *uaddr, unsigned int flags,
3296 u32 val, ktime_t *abs_time, u32 bitset,
3297 u32 __user *uaddr2)
3298{
3299 struct hrtimer_sleeper timeout, *to;
3300 struct futex_pi_state *pi_state = NULL;
3301 struct rt_mutex_waiter rt_waiter;
3302 struct futex_hash_bucket *hb;
3303 union futex_key key2 = FUTEX_KEY_INIT;
3304 struct futex_q q = futex_q_init;
3305 int res, ret;
3306
3307 if (!IS_ENABLED(CONFIG_FUTEX_PI))
3308 return -ENOSYS;
3309
3310 if (uaddr == uaddr2)
3311 return -EINVAL;
3312
3313 if (!bitset)
3314 return -EINVAL;
3315
3316 to = futex_setup_timer(abs_time, &timeout, flags,
3317 current->timer_slack_ns);
3318
3319
3320
3321
3322
3323 rt_mutex_init_waiter(&rt_waiter);
3324
3325 ret = get_futex_key(uaddr2, flags & FLAGS_SHARED, &key2, FUTEX_WRITE);
3326 if (unlikely(ret != 0))
3327 goto out;
3328
3329 q.bitset = bitset;
3330 q.rt_waiter = &rt_waiter;
3331 q.requeue_pi_key = &key2;
3332
3333
3334
3335
3336
3337 ret = futex_wait_setup(uaddr, val, flags, &q, &hb);
3338 if (ret)
3339 goto out_key2;
3340
3341
3342
3343
3344
3345 if (match_futex(&q.key, &key2)) {
3346 queue_unlock(hb);
3347 ret = -EINVAL;
3348 goto out_put_keys;
3349 }
3350
3351
3352 futex_wait_queue_me(hb, &q, to);
3353
3354 spin_lock(&hb->lock);
3355 ret = handle_early_requeue_pi_wakeup(hb, &q, &key2, to);
3356 spin_unlock(&hb->lock);
3357 if (ret)
3358 goto out_put_keys;
3359
3360
3361
3362
3363
3364
3365
3366
3367
3368
3369
3370 if (!q.rt_waiter) {
3371
3372
3373
3374
3375 if (q.pi_state && (q.pi_state->owner != current)) {
3376 spin_lock(q.lock_ptr);
3377 ret = fixup_pi_state_owner(uaddr2, &q, current);
3378 if (ret && rt_mutex_owner(&q.pi_state->pi_mutex) == current) {
3379 pi_state = q.pi_state;
3380 get_pi_state(pi_state);
3381 }
3382
3383
3384
3385
3386 put_pi_state(q.pi_state);
3387 spin_unlock(q.lock_ptr);
3388 }
3389 } else {
3390 struct rt_mutex *pi_mutex;
3391
3392
3393
3394
3395
3396
3397 WARN_ON(!q.pi_state);
3398 pi_mutex = &q.pi_state->pi_mutex;
3399 ret = rt_mutex_wait_proxy_lock(pi_mutex, to, &rt_waiter);
3400
3401 spin_lock(q.lock_ptr);
3402 if (ret && !rt_mutex_cleanup_proxy_lock(pi_mutex, &rt_waiter))
3403 ret = 0;
3404
3405 debug_rt_mutex_free_waiter(&rt_waiter);
3406
3407
3408
3409
3410 res = fixup_owner(uaddr2, &q, !ret);
3411
3412
3413
3414
3415 if (res)
3416 ret = (res < 0) ? res : 0;
3417
3418
3419
3420
3421
3422
3423 if (ret && rt_mutex_owner(&q.pi_state->pi_mutex) == current) {
3424 pi_state = q.pi_state;
3425 get_pi_state(pi_state);
3426 }
3427
3428
3429 unqueue_me_pi(&q);
3430 }
3431
3432 if (pi_state) {
3433 rt_mutex_futex_unlock(&pi_state->pi_mutex);
3434 put_pi_state(pi_state);
3435 }
3436
3437 if (ret == -EINTR) {
3438
3439
3440
3441
3442
3443
3444
3445 ret = -EWOULDBLOCK;
3446 }
3447
3448out_put_keys:
3449 put_futex_key(&q.key);
3450out_key2:
3451 put_futex_key(&key2);
3452
3453out:
3454 if (to) {
3455 hrtimer_cancel(&to->timer);
3456 destroy_hrtimer_on_stack(&to->timer);
3457 }
3458 return ret;
3459}
3460
3461
3462
3463
3464
3465
3466
3467
3468
3469
3470
3471
3472
3473
3474
3475
3476
3477
3478
3479
3480
3481SYSCALL_DEFINE2(set_robust_list, struct robust_list_head __user *, head,
3482 size_t, len)
3483{
3484 if (!futex_cmpxchg_enabled)
3485 return -ENOSYS;
3486
3487
3488
3489 if (unlikely(len != sizeof(*head)))
3490 return -EINVAL;
3491
3492 current->robust_list = head;
3493
3494 return 0;
3495}
3496
3497
3498
3499
3500
3501
3502
3503SYSCALL_DEFINE3(get_robust_list, int, pid,
3504 struct robust_list_head __user * __user *, head_ptr,
3505 size_t __user *, len_ptr)
3506{
3507 struct robust_list_head __user *head;
3508 unsigned long ret;
3509 struct task_struct *p;
3510
3511 if (!futex_cmpxchg_enabled)
3512 return -ENOSYS;
3513
3514 rcu_read_lock();
3515
3516 ret = -ESRCH;
3517 if (!pid)
3518 p = current;
3519 else {
3520 p = find_task_by_vpid(pid);
3521 if (!p)
3522 goto err_unlock;
3523 }
3524
3525 ret = -EPERM;
3526 if (!ptrace_may_access(p, PTRACE_MODE_READ_REALCREDS))
3527 goto err_unlock;
3528
3529 head = p->robust_list;
3530 rcu_read_unlock();
3531
3532 if (put_user(sizeof(*head), len_ptr))
3533 return -EFAULT;
3534 return put_user(head, head_ptr);
3535
3536err_unlock:
3537 rcu_read_unlock();
3538
3539 return ret;
3540}
3541
3542
3543#define HANDLE_DEATH_PENDING true
3544#define HANDLE_DEATH_LIST false
3545
3546
3547
3548
3549
3550static int handle_futex_death(u32 __user *uaddr, struct task_struct *curr,
3551 bool pi, bool pending_op)
3552{
3553 u32 uval, uninitialized_var(nval), mval;
3554 int err;
3555
3556
3557 if ((((unsigned long)uaddr) % sizeof(*uaddr)) != 0)
3558 return -1;
3559
3560retry:
3561 if (get_user(uval, uaddr))
3562 return -1;
3563
3564
3565
3566
3567
3568
3569
3570
3571
3572
3573
3574
3575
3576
3577
3578
3579
3580
3581
3582
3583
3584
3585
3586
3587
3588
3589
3590
3591
3592
3593
3594
3595 if (pending_op && !pi && !uval) {
3596 futex_wake(uaddr, 1, 1, FUTEX_BITSET_MATCH_ANY);
3597 return 0;
3598 }
3599
3600 if ((uval & FUTEX_TID_MASK) != task_pid_vnr(curr))
3601 return 0;
3602
3603
3604
3605
3606
3607
3608
3609
3610
3611
3612
3613 mval = (uval & FUTEX_WAITERS) | FUTEX_OWNER_DIED;
3614
3615
3616
3617
3618
3619
3620
3621
3622
3623
3624 if ((err = cmpxchg_futex_value_locked(&nval, uaddr, uval, mval))) {
3625 switch (err) {
3626 case -EFAULT:
3627 if (fault_in_user_writeable(uaddr))
3628 return -1;
3629 goto retry;
3630
3631 case -EAGAIN:
3632 cond_resched();
3633 goto retry;
3634
3635 default:
3636 WARN_ON_ONCE(1);
3637 return err;
3638 }
3639 }
3640
3641 if (nval != uval)
3642 goto retry;
3643
3644
3645
3646
3647
3648 if (!pi && (uval & FUTEX_WAITERS))
3649 futex_wake(uaddr, 1, 1, FUTEX_BITSET_MATCH_ANY);
3650
3651 return 0;
3652}
3653
3654
3655
3656
3657static inline int fetch_robust_entry(struct robust_list __user **entry,
3658 struct robust_list __user * __user *head,
3659 unsigned int *pi)
3660{
3661 unsigned long uentry;
3662
3663 if (get_user(uentry, (unsigned long __user *)head))
3664 return -EFAULT;
3665
3666 *entry = (void __user *)(uentry & ~1UL);
3667 *pi = uentry & 1;
3668
3669 return 0;
3670}
3671
3672
3673
3674
3675
3676
3677
3678static void exit_robust_list(struct task_struct *curr)
3679{
3680 struct robust_list_head __user *head = curr->robust_list;
3681 struct robust_list __user *entry, *next_entry, *pending;
3682 unsigned int limit = ROBUST_LIST_LIMIT, pi, pip;
3683 unsigned int uninitialized_var(next_pi);
3684 unsigned long futex_offset;
3685 int rc;
3686
3687 if (!futex_cmpxchg_enabled)
3688 return;
3689
3690
3691
3692
3693
3694 if (fetch_robust_entry(&entry, &head->list.next, &pi))
3695 return;
3696
3697
3698
3699 if (get_user(futex_offset, &head->futex_offset))
3700 return;
3701
3702
3703
3704
3705 if (fetch_robust_entry(&pending, &head->list_op_pending, &pip))
3706 return;
3707
3708 next_entry = NULL;
3709 while (entry != &head->list) {
3710
3711
3712
3713
3714 rc = fetch_robust_entry(&next_entry, &entry->next, &next_pi);
3715
3716
3717
3718
3719 if (entry != pending) {
3720 if (handle_futex_death((void __user *)entry + futex_offset,
3721 curr, pi, HANDLE_DEATH_LIST))
3722 return;
3723 }
3724 if (rc)
3725 return;
3726 entry = next_entry;
3727 pi = next_pi;
3728
3729
3730
3731 if (!--limit)
3732 break;
3733
3734 cond_resched();
3735 }
3736
3737 if (pending) {
3738 handle_futex_death((void __user *)pending + futex_offset,
3739 curr, pip, HANDLE_DEATH_PENDING);
3740 }
3741}
3742
3743static void futex_cleanup(struct task_struct *tsk)
3744{
3745 if (unlikely(tsk->robust_list)) {
3746 exit_robust_list(tsk);
3747 tsk->robust_list = NULL;
3748 }
3749
3750#ifdef CONFIG_COMPAT
3751 if (unlikely(tsk->compat_robust_list)) {
3752 compat_exit_robust_list(tsk);
3753 tsk->compat_robust_list = NULL;
3754 }
3755#endif
3756
3757 if (unlikely(!list_empty(&tsk->pi_state_list)))
3758 exit_pi_state_list(tsk);
3759}
3760
3761
3762
3763
3764
3765
3766
3767
3768
3769
3770
3771
3772
3773
3774
3775
3776
3777
3778void futex_exit_recursive(struct task_struct *tsk)
3779{
3780
3781 if (tsk->futex_state == FUTEX_STATE_EXITING)
3782 mutex_unlock(&tsk->futex_exit_mutex);
3783 tsk->futex_state = FUTEX_STATE_DEAD;
3784}
3785
3786static void futex_cleanup_begin(struct task_struct *tsk)
3787{
3788
3789
3790
3791
3792
3793
3794 mutex_lock(&tsk->futex_exit_mutex);
3795
3796
3797
3798
3799
3800
3801
3802
3803
3804
3805
3806
3807 raw_spin_lock_irq(&tsk->pi_lock);
3808 tsk->futex_state = FUTEX_STATE_EXITING;
3809 raw_spin_unlock_irq(&tsk->pi_lock);
3810}
3811
3812static void futex_cleanup_end(struct task_struct *tsk, int state)
3813{
3814
3815
3816
3817
3818 tsk->futex_state = state;
3819
3820
3821
3822
3823 mutex_unlock(&tsk->futex_exit_mutex);
3824}
3825
3826void futex_exec_release(struct task_struct *tsk)
3827{
3828
3829
3830
3831
3832
3833
3834
3835 futex_cleanup_begin(tsk);
3836 futex_cleanup(tsk);
3837
3838
3839
3840
3841 futex_cleanup_end(tsk, FUTEX_STATE_OK);
3842}
3843
3844void futex_exit_release(struct task_struct *tsk)
3845{
3846 futex_cleanup_begin(tsk);
3847 futex_cleanup(tsk);
3848 futex_cleanup_end(tsk, FUTEX_STATE_DEAD);
3849}
3850
3851long do_futex(u32 __user *uaddr, int op, u32 val, ktime_t *timeout,
3852 u32 __user *uaddr2, u32 val2, u32 val3)
3853{
3854 int cmd = op & FUTEX_CMD_MASK;
3855 unsigned int flags = 0;
3856
3857 if (!(op & FUTEX_PRIVATE_FLAG))
3858 flags |= FLAGS_SHARED;
3859
3860 if (op & FUTEX_CLOCK_REALTIME) {
3861 flags |= FLAGS_CLOCKRT;
3862 if (cmd != FUTEX_WAIT && cmd != FUTEX_WAIT_BITSET && \
3863 cmd != FUTEX_WAIT_REQUEUE_PI)
3864 return -ENOSYS;
3865 }
3866
3867 switch (cmd) {
3868 case FUTEX_LOCK_PI:
3869 case FUTEX_UNLOCK_PI:
3870 case FUTEX_TRYLOCK_PI:
3871 case FUTEX_WAIT_REQUEUE_PI:
3872 case FUTEX_CMP_REQUEUE_PI:
3873 if (!futex_cmpxchg_enabled)
3874 return -ENOSYS;
3875 }
3876
3877 switch (cmd) {
3878 case FUTEX_WAIT:
3879 val3 = FUTEX_BITSET_MATCH_ANY;
3880
3881 case FUTEX_WAIT_BITSET:
3882 return futex_wait(uaddr, flags, val, timeout, val3);
3883 case FUTEX_WAKE:
3884 val3 = FUTEX_BITSET_MATCH_ANY;
3885
3886 case FUTEX_WAKE_BITSET:
3887 return futex_wake(uaddr, flags, val, val3);
3888 case FUTEX_REQUEUE:
3889 return futex_requeue(uaddr, flags, uaddr2, val, val2, NULL, 0);
3890 case FUTEX_CMP_REQUEUE:
3891 return futex_requeue(uaddr, flags, uaddr2, val, val2, &val3, 0);
3892 case FUTEX_WAKE_OP:
3893 return futex_wake_op(uaddr, flags, uaddr2, val, val2, val3);
3894 case FUTEX_LOCK_PI:
3895 return futex_lock_pi(uaddr, flags, timeout, 0);
3896 case FUTEX_UNLOCK_PI:
3897 return futex_unlock_pi(uaddr, flags);
3898 case FUTEX_TRYLOCK_PI:
3899 return futex_lock_pi(uaddr, flags, NULL, 1);
3900 case FUTEX_WAIT_REQUEUE_PI:
3901 val3 = FUTEX_BITSET_MATCH_ANY;
3902 return futex_wait_requeue_pi(uaddr, flags, val, timeout, val3,
3903 uaddr2);
3904 case FUTEX_CMP_REQUEUE_PI:
3905 return futex_requeue(uaddr, flags, uaddr2, val, val2, &val3, 1);
3906 }
3907 return -ENOSYS;
3908}
3909
3910
3911SYSCALL_DEFINE6(futex, u32 __user *, uaddr, int, op, u32, val,
3912 struct __kernel_timespec __user *, utime, u32 __user *, uaddr2,
3913 u32, val3)
3914{
3915 struct timespec64 ts;
3916 ktime_t t, *tp = NULL;
3917 u32 val2 = 0;
3918 int cmd = op & FUTEX_CMD_MASK;
3919
3920 if (utime && (cmd == FUTEX_WAIT || cmd == FUTEX_LOCK_PI ||
3921 cmd == FUTEX_WAIT_BITSET ||
3922 cmd == FUTEX_WAIT_REQUEUE_PI)) {
3923 if (unlikely(should_fail_futex(!(op & FUTEX_PRIVATE_FLAG))))
3924 return -EFAULT;
3925 if (get_timespec64(&ts, utime))
3926 return -EFAULT;
3927 if (!timespec64_valid(&ts))
3928 return -EINVAL;
3929
3930 t = timespec64_to_ktime(ts);
3931 if (cmd == FUTEX_WAIT)
3932 t = ktime_add_safe(ktime_get(), t);
3933 tp = &t;
3934 }
3935
3936
3937
3938
3939 if (cmd == FUTEX_REQUEUE || cmd == FUTEX_CMP_REQUEUE ||
3940 cmd == FUTEX_CMP_REQUEUE_PI || cmd == FUTEX_WAKE_OP)
3941 val2 = (u32) (unsigned long) utime;
3942
3943 return do_futex(uaddr, op, val, tp, uaddr2, val2, val3);
3944}
3945
3946#ifdef CONFIG_COMPAT
3947
3948
3949
3950static inline int
3951compat_fetch_robust_entry(compat_uptr_t *uentry, struct robust_list __user **entry,
3952 compat_uptr_t __user *head, unsigned int *pi)
3953{
3954 if (get_user(*uentry, head))
3955 return -EFAULT;
3956
3957 *entry = compat_ptr((*uentry) & ~1);
3958 *pi = (unsigned int)(*uentry) & 1;
3959
3960 return 0;
3961}
3962
3963static void __user *futex_uaddr(struct robust_list __user *entry,
3964 compat_long_t futex_offset)
3965{
3966 compat_uptr_t base = ptr_to_compat(entry);
3967 void __user *uaddr = compat_ptr(base + futex_offset);
3968
3969 return uaddr;
3970}
3971
3972
3973
3974
3975
3976
3977
3978static void compat_exit_robust_list(struct task_struct *curr)
3979{
3980 struct compat_robust_list_head __user *head = curr->compat_robust_list;
3981 struct robust_list __user *entry, *next_entry, *pending;
3982 unsigned int limit = ROBUST_LIST_LIMIT, pi, pip;
3983 unsigned int uninitialized_var(next_pi);
3984 compat_uptr_t uentry, next_uentry, upending;
3985 compat_long_t futex_offset;
3986 int rc;
3987
3988 if (!futex_cmpxchg_enabled)
3989 return;
3990
3991
3992
3993
3994
3995 if (compat_fetch_robust_entry(&uentry, &entry, &head->list.next, &pi))
3996 return;
3997
3998
3999
4000 if (get_user(futex_offset, &head->futex_offset))
4001 return;
4002
4003
4004
4005
4006 if (compat_fetch_robust_entry(&upending, &pending,
4007 &head->list_op_pending, &pip))
4008 return;
4009
4010 next_entry = NULL;
4011 while (entry != (struct robust_list __user *) &head->list) {
4012
4013
4014
4015
4016 rc = compat_fetch_robust_entry(&next_uentry, &next_entry,
4017 (compat_uptr_t __user *)&entry->next, &next_pi);
4018
4019
4020
4021
4022 if (entry != pending) {
4023 void __user *uaddr = futex_uaddr(entry, futex_offset);
4024
4025 if (handle_futex_death(uaddr, curr, pi,
4026 HANDLE_DEATH_LIST))
4027 return;
4028 }
4029 if (rc)
4030 return;
4031 uentry = next_uentry;
4032 entry = next_entry;
4033 pi = next_pi;
4034
4035
4036
4037 if (!--limit)
4038 break;
4039
4040 cond_resched();
4041 }
4042 if (pending) {
4043 void __user *uaddr = futex_uaddr(pending, futex_offset);
4044
4045 handle_futex_death(uaddr, curr, pip, HANDLE_DEATH_PENDING);
4046 }
4047}
4048
4049COMPAT_SYSCALL_DEFINE2(set_robust_list,
4050 struct compat_robust_list_head __user *, head,
4051 compat_size_t, len)
4052{
4053 if (!futex_cmpxchg_enabled)
4054 return -ENOSYS;
4055
4056 if (unlikely(len != sizeof(*head)))
4057 return -EINVAL;
4058
4059 current->compat_robust_list = head;
4060
4061 return 0;
4062}
4063
4064COMPAT_SYSCALL_DEFINE3(get_robust_list, int, pid,
4065 compat_uptr_t __user *, head_ptr,
4066 compat_size_t __user *, len_ptr)
4067{
4068 struct compat_robust_list_head __user *head;
4069 unsigned long ret;
4070 struct task_struct *p;
4071
4072 if (!futex_cmpxchg_enabled)
4073 return -ENOSYS;
4074
4075 rcu_read_lock();
4076
4077 ret = -ESRCH;
4078 if (!pid)
4079 p = current;
4080 else {
4081 p = find_task_by_vpid(pid);
4082 if (!p)
4083 goto err_unlock;
4084 }
4085
4086 ret = -EPERM;
4087 if (!ptrace_may_access(p, PTRACE_MODE_READ_REALCREDS))
4088 goto err_unlock;
4089
4090 head = p->compat_robust_list;
4091 rcu_read_unlock();
4092
4093 if (put_user(sizeof(*head), len_ptr))
4094 return -EFAULT;
4095 return put_user(ptr_to_compat(head), head_ptr);
4096
4097err_unlock:
4098 rcu_read_unlock();
4099
4100 return ret;
4101}
4102#endif
4103
4104#ifdef CONFIG_COMPAT_32BIT_TIME
4105SYSCALL_DEFINE6(futex_time32, u32 __user *, uaddr, int, op, u32, val,
4106 struct old_timespec32 __user *, utime, u32 __user *, uaddr2,
4107 u32, val3)
4108{
4109 struct timespec64 ts;
4110 ktime_t t, *tp = NULL;
4111 int val2 = 0;
4112 int cmd = op & FUTEX_CMD_MASK;
4113
4114 if (utime && (cmd == FUTEX_WAIT || cmd == FUTEX_LOCK_PI ||
4115 cmd == FUTEX_WAIT_BITSET ||
4116 cmd == FUTEX_WAIT_REQUEUE_PI)) {
4117 if (get_old_timespec32(&ts, utime))
4118 return -EFAULT;
4119 if (!timespec64_valid(&ts))
4120 return -EINVAL;
4121
4122 t = timespec64_to_ktime(ts);
4123 if (cmd == FUTEX_WAIT)
4124 t = ktime_add_safe(ktime_get(), t);
4125 tp = &t;
4126 }
4127 if (cmd == FUTEX_REQUEUE || cmd == FUTEX_CMP_REQUEUE ||
4128 cmd == FUTEX_CMP_REQUEUE_PI || cmd == FUTEX_WAKE_OP)
4129 val2 = (int) (unsigned long) utime;
4130
4131 return do_futex(uaddr, op, val, tp, uaddr2, val2, val3);
4132}
4133#endif
4134
4135static void __init futex_detect_cmpxchg(void)
4136{
4137#ifndef CONFIG_HAVE_FUTEX_CMPXCHG
4138 u32 curval;
4139
4140
4141
4142
4143
4144
4145
4146
4147
4148
4149
4150 if (cmpxchg_futex_value_locked(&curval, NULL, 0, 0) == -EFAULT)
4151 futex_cmpxchg_enabled = 1;
4152#endif
4153}
4154
4155static int __init futex_init(void)
4156{
4157 unsigned int futex_shift;
4158 unsigned long i;
4159
4160#if CONFIG_BASE_SMALL
4161 futex_hashsize = 16;
4162#else
4163 futex_hashsize = roundup_pow_of_two(256 * num_possible_cpus());
4164#endif
4165
4166 futex_queues = alloc_large_system_hash("futex", sizeof(*futex_queues),
4167 futex_hashsize, 0,
4168 futex_hashsize < 256 ? HASH_SMALL : 0,
4169 &futex_shift, NULL,
4170 futex_hashsize, futex_hashsize);
4171 futex_hashsize = 1UL << futex_shift;
4172
4173 futex_detect_cmpxchg();
4174
4175 for (i = 0; i < futex_hashsize; i++) {
4176 atomic_set(&futex_queues[i].waiters, 0);
4177 plist_head_init(&futex_queues[i].chain);
4178 spin_lock_init(&futex_queues[i].lock);
4179 }
4180
4181 return 0;
4182}
4183core_initcall(futex_init);
4184