Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.kernel > #1386232
| From | Suzuki K Poulose <Suzuki.Poulose@arm.com> |
|---|---|
| Newsgroups | linux.kernel |
| Subject | Re: [PATCH V3 10/18] coresight: tmc: getting the right read_count on tmc_open() |
| Date | 2016-04-25 12:50 +0200 |
| Message-ID | <rrMfw-4fB-11@gated-at.bofh.it> (permalink) |
| References | <rqMUh-5Du-3@gated-at.bofh.it> <rqMUi-5Du-11@gated-at.bofh.it> |
| Organization | linux.* mail to news gateway |
On 22/04/16 18:14, Mathieu Poirier wrote: > In function tmc_open(), if tmc_read_prepare() fails variable > drvdata->read_count is not decremented, causing unwanted > access to drvdata->buf and very likely, a crash dump. > > By moving the incrementation to a place where we know things > are stable this kind of situation is avoided. > > Signed-off-by: Mathieu Poirier <mathieu.poirier@linaro.org> > Reviewed-by: Suzuki K Poulose <Suzuki.Poulose@arm.com> > --- > drivers/hwtracing/coresight/coresight-tmc.c | 3 ++- > 1 file changed, 2 insertions(+), 1 deletion(-) > > diff --git a/drivers/hwtracing/coresight/coresight-tmc.c b/drivers/hwtracing/coresight/coresight-tmc.c > index e8e12a9b917a..55806352b1f1 100644 > --- a/drivers/hwtracing/coresight/coresight-tmc.c > +++ b/drivers/hwtracing/coresight/coresight-tmc.c > @@ -121,13 +121,14 @@ static int tmc_open(struct inode *inode, struct file *file) > struct tmc_drvdata, miscdev); > int ret = 0; > On a second thought, I think there could be a race here. > - if (drvdata->read_count++) > + if (drvdata->read_count) > goto out; > > ret = tmc_read_prepare(drvdata); > if (ret) > return ret; > out: What prevents someone else doing a release() on the file when we get here, without incrementing the read_count ? Also, read_count accesses are not protected. Either should be covered by the drvdata->spinlock or convert it to atomic. > + drvdata->read_count++; > nonseekable_open(inode, file); Cheers Suzuki
Back to linux.kernel | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread
[PATCH V3 10/18] coresight: tmc: getting the right read_count on tmc_open() Mathieu Poirier <mathieu.poirier@linaro.org> - 2016-04-22 19:20 +0200
Re: [PATCH V3 10/18] coresight: tmc: getting the right read_count on tmc_open() Suzuki K Poulose <Suzuki.Poulose@arm.com> - 2016-04-25 12:50 +0200
Re: [PATCH V3 10/18] coresight: tmc: getting the right read_count on tmc_open() Mathieu Poirier <mathieu.poirier@linaro.org> - 2016-04-25 16:30 +0200
csiph-web