Re: [linux-usb-devel] [PATCH] back out sysfs reference count change

From: Greg KH
Date: Wed Mar 31 2004 - 17:22:08 EST


On Wed, Mar 31, 2004 at 12:11:30PM +1000, Benjamin Herrenschmidt wrote:
> On Wed, 2004-03-31 at 09:55, Greg KH wrote:
> > Hi,
> >
> > The patch below backs out Maneesh's sysfs patch that was recently added
> > to the kernel. In its defense, the original patch did solve some fixes
> > that could be duplicated on SMP machines, but the side affect of the
> > patch caused lots of problems. Basically it caused kobjects to get
> > their references incremented when files that are not present in the
> > kobject are asked for (udev can easily trigger this when it looks for
> > files call "dev" in directories that do not have that file). This can
> > cause easy oopses when the VFS later ages out those old dentries and the
> > kobject has its reference finally released (usually after the module
> > that the kobject lived in was removed.)
>
> I think that the bug in the first place is to have an existing
> kobject that didn't bump the module ref count.
>
> If a kobject exists that have a pointer to the module code (the
> release function), it _MUST_ have bumped the module ref count,
> that's the whole point of the module reference count.

But that is impossible as has already been pointed out by Alan Stern.
If a module creates a kobject, how can the module_exit() function ever
be called if that kobject incremented the module reference count?

So what we do is any reference to the kobject grabbed by userspace
causes the module reference count to go up. That fixes the issue for
the most part (with the exception of the race that Maneesh has
documented.)

thanks,

greg k-h
-
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at http://vger.kernel.org/majordomo-info.html
Please read the FAQ at http://www.tux.org/lkml/