Re: sound: use-after-free in snd_timer_interrupt

From: Takashi Iwai
Date: Fri Jan 15 2016 - 10:44:54 EST


On Fri, 15 Jan 2016 16:28:33 +0100,
Dmitry Vyukov wrote:
>
> On Fri, Jan 15, 2016 at 4:21 PM, Takashi Iwai <tiwai@xxxxxxx> wrote:
> > So you're running this in parallel? Or a tight sequential loop?
> > I did the latter, and I tried even this on a bare metal, but couldn't
> > trigger the Oops, so far.
>
> Yes, I run it in parallel using:
>
> $ go get golang.org/x/tools/cmd/stress
> $ ./stress -p 8 ./a.out
>
> But it just keeps 8 parallel processes running.

OK, then a bit different than I tested. Will check.

> > Meanwhile, I pushed the tree including all fixes at for-linus branch:
> > git://git.kernel.org/pub/scm/linux/kernel/git/tiwai/sound.git for-linus
> >
> > It'd be appreciated if you can test this one.
>
> Is it different from the patches you mailed?

No, they should be basically same, but just to make sure that we're
on the same ground.

> I keep several dozens
> fixes for bugs that are not yet merged into Linus tree + own kcov
> patch. It is not easy to rebase...

The branch should be pullable onto 4.4-final cleanly.

> Here is what I now have for sound/
> https://gist.githubusercontent.com/dvyukov/dc29dbfd320126285fd8/raw/e2ca7b59c0dc118045f9fb4e3d052cbc751e787e/gistfile1.txt
>

Takashi