Linux kernel mirror (for testing) git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git
kernel os linux

RDS: Fix the atomicity for congestion map update

Two different threads with different rds sockets may be in
rds_recv_rcvbuf_delta() via receive path. If their ports
both map to the same word in the congestion map, then
using non-atomic ops to update it could cause the map to
be incorrect. Lets use atomics to avoid such an issue.

Full credit to Wengang <wen.gang.wang@oracle.com> for
finding the issue, analysing it and also pointing out
to offending code with spin lock based fix.

Reviewed-by: Leon Romanovsky <leon@leon.nu>
Signed-off-by: Wengang Wang <wen.gang.wang@oracle.com>
Signed-off-by: Santosh Shilimkar <santosh.shilimkar@oracle.com>
Signed-off-by: David S. Miller <davem@davemloft.net>

authored by

santosh.shilimkar@oracle.com and committed by
David S. Miller
e47db94e a7c55654

+2 -2
+2 -2
net/rds/cong.c
··· 299 299 i = be16_to_cpu(port) / RDS_CONG_MAP_PAGE_BITS; 300 300 off = be16_to_cpu(port) % RDS_CONG_MAP_PAGE_BITS; 301 301 302 - __set_bit_le(off, (void *)map->m_page_addrs[i]); 302 + set_bit_le(off, (void *)map->m_page_addrs[i]); 303 303 } 304 304 305 305 void rds_cong_clear_bit(struct rds_cong_map *map, __be16 port) ··· 313 313 i = be16_to_cpu(port) / RDS_CONG_MAP_PAGE_BITS; 314 314 off = be16_to_cpu(port) % RDS_CONG_MAP_PAGE_BITS; 315 315 316 - __clear_bit_le(off, (void *)map->m_page_addrs[i]); 316 + clear_bit_le(off, (void *)map->m_page_addrs[i]); 317 317 } 318 318 319 319 static int rds_cong_test_bit(struct rds_cong_map *map, __be16 port)