[<prev] [next>] [thread-next>] [day] [month] [year] [list]
Message-ID: <20090118171720.GA18374@redhat.com>
Date: Sun, 18 Jan 2009 18:17:20 +0100
From: Oleg Nesterov <oleg@...hat.com>
To: arve@...roid.com, gregkh@...e.de, jrm8005@...il.com,
rlove@...gle.com, swetland@...gle.com
Cc: linux-kernel@...r.kernel.org
Subject: [PATCH] android: task_get_unused_fd_flags: fix the wrong usage of
tsk->signal
Compile tested.
task_struct->signal is not protected by RCU, the code is bogus.
Change the code to take ->siglock to pin ->signal.
Signed-off-by: Oleg Nesterov <oleg@...hat.com>
--- CUR/drivers/staging/android/binder.c~ANDROID 2009-01-12 23:07:43.000000000 +0100
+++ CUR/drivers/staging/android/binder.c 2009-01-18 18:06:12.000000000 +0100
@@ -319,6 +319,7 @@ int task_get_unused_fd_flags(struct task
int fd, error;
struct fdtable *fdt;
unsigned long rlim_cur;
+ unsigned long irqs;
if (files == NULL)
return -ESRCH;
@@ -335,12 +336,11 @@ repeat:
* N.B. For clone tasks sharing a files structure, this test
* will limit the total number of files that can be opened.
*/
- rcu_read_lock();
- if (tsk->signal)
+ rlim_cur = 0;
+ if (lock_task_sighand(tsk, &irqs)) {
rlim_cur = tsk->signal->rlim[RLIMIT_NOFILE].rlim_cur;
- else
- rlim_cur = 0;
- rcu_read_unlock();
+ unlock_task_sighand(tsk, &irqs);
+ }
if (fd >= rlim_cur)
goto out;
--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@...r.kernel.org
More majordomo info at http://vger.kernel.org/majordomo-info.html
Please read the FAQ at http://www.tux.org/lkml/
Powered by blists - more mailing lists