Commit 6afc8591 authored by Zheng Yejian's avatar Zheng Yejian Committed by Jialin Zhang
Browse files

ftrace: Fix issue that 'direct->addr' not restored in modify_ftrace_direct()

mainline inclusion
from mainline-v6.3-rc6
commit 2a2d8c51
category: bugfix
bugzilla: https://gitee.com/openeuler/kernel/issues/I6TQ89
CVE: NA

Reference: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=2a2d8c51defb446e8d89a83f42f8e5cd529111e9

--------------------------------

Syzkaller report a WARNING: "WARN_ON(!direct)" in modify_ftrace_direct().

Root cause is 'direct->addr' was changed from 'old_addr' to 'new_addr' but
not restored if error happened on calling ftrace_modify_direct_caller().
Then it can no longer find 'direct' by that 'old_addr'.

To fix it, restore 'direct->addr' to 'old_addr' explicitly in error path.

Link: https://lore.kernel.org/linux-trace-kernel/20230330025223.1046087-1-zhengyejian1@huawei.com



Cc: stable@vger.kernel.org
Cc: <mhiramat@kernel.org>
Cc: <mark.rutland@arm.com>
Cc: <ast@kernel.org>
Cc: <daniel@iogearbox.net>
Fixes: 77ab7785 ("ftrace: Fix modify_ftrace_direct.")
Signed-off-by: default avatarZheng Yejian <zhengyejian1@huawei.com>
Signed-off-by: default avatarSteven Rostedt (Google) <rostedt@goodmis.org>
Signed-off-by: default avatarZheng Yejian <zhengyejian1@huawei.com>
Reviewed-by: default avatarXu Kuohai <xukuohai@huawei.com>
Signed-off-by: default avatarJialin Zhang <zhangjialin11@huawei.com>
parent 0eb9f75b
Loading
Loading
Loading
Loading
+9 −6
Original line number Diff line number Diff line
@@ -5390,13 +5390,16 @@ int modify_ftrace_direct(unsigned long ip,
		ret = 0;
	}

	if (unlikely(ret && new_direct)) {
	if (ret) {
		direct->addr = old_addr;
		if (unlikely(new_direct)) {
			direct->count++;
			list_del_rcu(&new_direct->next);
			synchronize_rcu_tasks();
			kfree(new_direct);
			ftrace_direct_func_count--;
		}
	}

 out_unlock:
	mutex_unlock(&ftrace_lock);