Go to file
Andrew Deason 9d7b94493c rx: Use atomics for rx_securityClass refcounts
Currently, the refCount in struct rx_securityClass is not protected by
any locks. Thus, if two threads create or destroy a connection using
the same rx_securityClass at the same time (or call rxs_Release), the
refCount can become inaccurate. If the refCount is undercounted, we
can prematurely free it while it's still referenced by other
connections or services, leading to segfaults, data corruption, etc.

For client connections, this can happen between any threads that
create and destroy a connection using the same security class struct.
For server connections, only two threads can race in this way: the rx
listener thread (which creates connections), and the rx event thread
(which destroys idle connections in rxi_ReapConnections).

To fix this, ideally we would change the refCount field to be an
rx_atomic_t. However, struct rx_securityClass is declared in the
public installed rx.h header, which cannot include rx_atomic.h. So
instead, change refCount users to go through a few new functions:
rxs_Ref(), rxs_DecRef(), and rxs_SetRefs(). These functions interpret
the refCount as an rx_atomic_t, and so allows callers to use safe
refcounting without needing to call rx_atomic_* functions directly.

Rename the existing refCount field to refCount_data, and declare it as
a char[8]. This gives us enough space to use it as an rx_atomic_t, but
avoids using rx_atomic_t in a public header, and discourages callers
from manipulating the refCount directly.

Thanks to mvitale@sinenomine.net for helping investigate the relevant
issue.

Change-Id: I55094218c79e8bc5498a6d2c1daa5620b1fceaff
Reviewed-on: https://gerrit.openafs.org/15158
Reviewed-by: Cheyenne Wills <cwills@sinenomine.net>
Reviewed-by: Mark Vitale <mvitale@sinenomine.net>
Tested-by: BuildBot <buildbot@rampaginggeek.com>
Reviewed-by: Michael Meffie <mmeffie@sinenomine.net>
2024-07-03 14:25:04 -04:00
build-tools make-release: create SHA256 checksums too 2024-04-25 12:22:19 -04:00
doc doc: Fix grammar in fileserver -admin-write 2024-07-02 19:39:21 -04:00
src rx: Use atomics for rx_securityClass refcounts 2024-07-03 14:25:04 -04:00
tests tests: Add make shell target 2024-06-27 09:10:18 -04:00
.gitignore Remove alpha_dux/alpha_osf references 2018-09-22 17:05:26 -04:00
.gitreview Add .gitreview 2018-02-04 15:34:55 -05:00
.mailmap git: add a mailmap file 2016-09-25 21:05:23 -04:00
.splintrc start-splint-support-20030528 2003-05-28 19:18:08 +00:00
acinclude.m4 cf: Set CC before calling AC_PROG_CC 2024-07-02 13:13:45 -04:00
CODING rxkad: Cleanup and build src/rxkad/test 2024-06-27 22:02:23 -04:00
configure-libafs.ac cf: Set CC before calling AC_PROG_CC 2024-07-02 13:13:45 -04:00
configure.ac cf: Set CC before calling AC_PROG_CC 2024-07-02 13:13:45 -04:00
CONTRIBUTING Correct our contributor's code of conduct 2020-09-04 10:01:28 -04:00
INSTALL INSTALL: Update AIX notes 2024-07-02 14:52:10 -04:00
libafsdep Move build support files into build-tools 2010-07-14 20:40:36 -07:00
LICENSE cf: Make local copy of ax_gcc_func_attribute.m4 2020-07-24 08:35:59 -04:00
Makefile-libafs.in Fix libafs_tree's cross-architecture support 2010-05-24 20:28:41 -07:00
Makefile.in tsm41: Fix various errors in aix_aklog.c 2024-07-01 14:51:10 -04:00
NEWS Update NEWS for OpenAFS 1.9.1 2021-03-18 21:48:27 -04:00
NTMakefile Remove rpctestlib 2021-06-10 12:59:53 -04:00
README Tweak grammar in README 2015-12-28 19:32:17 -05:00
README-WINDOWS Update windows build documentation 2013-07-02 15:14:09 -07:00
regen.sh Use autoconf-archive m4 from src/external 2020-05-08 11:30:36 -04:00

AFS is a distributed file system that enables users to share and
access all of the files stored in a network of computers as easily as
they access the files stored on their local machines. The file system is
called distributed for this exact reason: files can reside on many
different machines, but are available to users on every machine.

OpenAFS 1.0 was originally released by IBM under the terms of the
IBM Public License 1.0 (IPL10).  For details on IPL10 see the LICENSE
file in this directory.  The current OpenAFS distribution is licensed
under a combination of the IPL10 and many other licenses as granted by
the relevant copyright holders.  The LICENSE file in this directory
contains more details, thought it is not a comprehensive statement.

See INSTALL for information about building and installing OpenAFS
on various platforms.

See CODING for developer information and guidelines.

See NEWS for recent changes to OpenAFS.