Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1328005

[PATCH] tty: Drop krefs for interrupted tty lock

From Peter Hurley <peter@hurleysoftware.com>
Newsgroups linux.kernel
Subject [PATCH] tty: Drop krefs for interrupted tty lock
Date 2016-02-05 20:00 +0100
Message-ID <qYTLQ-3XC-9@gated-at.bofh.it> (permalink)
References <qY8jU-4ft-17@gated-at.bofh.it>
Organization linux.* mail to news gateway

Show all headers | View raw


When the tty lock is interrupted on attempted re-open, 2 tty krefs
are still held. Drop extra kref before returning failure from
tty_lock_interruptible(), and drop lookup kref before returning
failure from tty_open().

Fixes: 0bfd464d3fdd ("tty: Wait interruptibly for tty lock on reopen")
Reported-by: Dmitry Vyukov <dvyukov@google.com>
Signed-off-by: Peter Hurley <peter@hurleysoftware.com>
---

Greg,

This patch applies to tty-linus. For tty-next, the first blob has
been refactored into tty_open_by_driver(). Please let me know if
the merge isn't as straightforward as I believe it should be.


 drivers/tty/tty_io.c    | 3 +--
 drivers/tty/tty_mutex.c | 7 ++++++-
 2 files changed, 7 insertions(+), 3 deletions(-)

diff --git a/drivers/tty/tty_io.c b/drivers/tty/tty_io.c
index 5cec01c..a7eacef 100644
--- a/drivers/tty/tty_io.c
+++ b/drivers/tty/tty_io.c
@@ -2066,13 +2066,12 @@ retry_open:
 		if (tty) {
 			mutex_unlock(&tty_mutex);
 			retval = tty_lock_interruptible(tty);
+			tty_kref_put(tty);  /* drop kref from tty_driver_lookup_tty() */
 			if (retval) {
 				if (retval == -EINTR)
 					retval = -ERESTARTSYS;
 				goto err_unref;
 			}
-			/* safe to drop the kref from tty_driver_lookup_tty() */
-			tty_kref_put(tty);
 			retval = tty_reopen(tty);
 			if (retval < 0) {
 				tty_unlock(tty);
diff --git a/drivers/tty/tty_mutex.c b/drivers/tty/tty_mutex.c
index d2f3c4c..dfa9ec0 100644
--- a/drivers/tty/tty_mutex.c
+++ b/drivers/tty/tty_mutex.c
@@ -21,10 +21,15 @@ EXPORT_SYMBOL(tty_lock);
 
 int tty_lock_interruptible(struct tty_struct *tty)
 {
+	int ret;
+
 	if (WARN(tty->magic != TTY_MAGIC, "L Bad %p\n", tty))
 		return -EIO;
 	tty_kref_get(tty);
-	return mutex_lock_interruptible(&tty->legacy_mutex);
+	ret = mutex_lock_interruptible(&tty->legacy_mutex);
+	if (ret)
+		tty_kref_put(tty);
+	return ret;
 }
 
 void __lockfunc tty_unlock(struct tty_struct *tty)
-- 
2.7.0

Back to linux.kernel | Previous | Next — Previous in thread | Find similar | Unroll thread


Thread

tty: tty_struct memory leak Dmitry Vyukov <dvyukov@google.com> - 2016-02-03 17:20 +0100
  Re: tty: tty_struct memory leak Dmitry Vyukov <dvyukov@google.com> - 2016-02-03 17:30 +0100
    Re: tty: tty_struct memory leak Peter Hurley <peter@hurleysoftware.com> - 2016-02-04 00:30 +0100
      Re: tty: tty_struct memory leak Dmitry Vyukov <dvyukov@google.com> - 2016-02-04 11:50 +0100
        Re: tty: tty_struct memory leak Peter Hurley <peter@hurleysoftware.com> - 2016-02-04 22:50 +0100
  [PATCH] tty: Drop krefs for interrupted tty lock Peter Hurley <peter@hurleysoftware.com> - 2016-02-05 20:00 +0100

csiph-web