Commit ebeeb1ad9b8a ("rds: tcp: use rds_destroy_pending() to synchronize
netns/module teardown and rds connection/workq management") adds an
rcu read critical section to __rds_conn_create. The memory allocations
in that critcal section need to use GFP_ATOMIC to avoid sleeping.
This patch was verified with syzkaller reproducer.
Reported-by: syzbot+a0564419941aaae3fe3c@syzkaller.appspotmail.com
Signed-off-by: Sowmini Varadhan <redacted>
Fixes: ebeeb1ad9b8a ("rds: tcp: use rds_destroy_pending() to synchronize
netns/module teardown and rds connection/workq management")
---
net/rds/connection.c | 2 ++
1 files changed, 2 insertions(+), 0 deletions(-)
I'd never seen this kind of gfp masking before, so I did a grep around
and the only cases I saw of this kind of usage were for things like
GFP_DMA and such.
I could not find one case that did it to convert a sleeping into a non-
sleeping GFP mask.
Let's not over-engineer this. For one thing, whatever allocation bits
came down from the callers, we are going to lose here.
So just pass straight GFP_ATOMIC into the routines below here instead
of the 'gfp' variable.
Thanks.
Let's not over-engineer this. For one thing, whatever allocation bits
came down from the callers, we are going to lose here.
Ok, I was wondering how much of the sk_allocation we want to keep in
the future, so I did this admittedly weird thing. I'll change it
to the obvious and submit v3.
--Sowmini