mirror of
https://git.proxmox.com/git/mirror_ubuntu-kernels.git
synced 2025-11-07 21:30:56 +00:00
Due to several bugs caused by timers being re-armed after they are
shutdown and just before they are freed, a new state of timers was added
called "shutdown". After a timer is set to this state, then it can no
longer be re-armed.
The following script was run to find all the trivial locations where
del_timer() or del_timer_sync() is called in the same function that the
object holding the timer is freed. It also ignores any locations where
the timer->function is modified between the del_timer*() and the free(),
as that is not considered a "trivial" case.
This was created by using a coccinelle script and the following
commands:
$ cat timer.cocci
@@
expression ptr, slab;
identifier timer, rfield;
@@
(
- del_timer(&ptr->timer);
+ timer_shutdown(&ptr->timer);
|
- del_timer_sync(&ptr->timer);
+ timer_shutdown_sync(&ptr->timer);
)
... when strict
when != ptr->timer
(
kfree_rcu(ptr, rfield);
|
kmem_cache_free(slab, ptr);
|
kfree(ptr);
)
$ spatch timer.cocci . > /tmp/t.patch
$ patch -p1 < /tmp/t.patch
Link: https://lore.kernel.org/lkml/20221123201306.823305113@linutronix.de/
Signed-off-by: Steven Rostedt (Google) <rostedt@goodmis.org>
Acked-by: Pavel Machek <pavel@ucw.cz> [ LED ]
Acked-by: Kalle Valo <kvalo@kernel.org> [ wireless ]
Acked-by: Paolo Abeni <pabeni@redhat.com> [ networking ]
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
|
||
|---|---|---|
| .. | ||
| clock.c | ||
| core.c | ||
| core.h | ||
| dsp_audio.c | ||
| dsp_biquad.h | ||
| dsp_blowfish.c | ||
| dsp_cmx.c | ||
| dsp_core.c | ||
| dsp_dtmf.c | ||
| dsp_ecdis.h | ||
| dsp_hwec.c | ||
| dsp_hwec.h | ||
| dsp_pipeline.c | ||
| dsp_tones.c | ||
| dsp.h | ||
| fsm.c | ||
| fsm.h | ||
| hwchannel.c | ||
| Kconfig | ||
| l1oip_codec.c | ||
| l1oip_core.c | ||
| l1oip.h | ||
| layer1.c | ||
| layer1.h | ||
| layer2.c | ||
| layer2.h | ||
| Makefile | ||
| socket.c | ||
| stack.c | ||
| tei.c | ||
| timerdev.c | ||