diff options
author | Linus Torvalds <torvalds@linux-foundation.org> | 2014-06-21 16:40:30 -1000 |
---|---|---|
committer | Linus Torvalds <torvalds@linux-foundation.org> | 2014-06-21 16:40:30 -1000 |
commit | 2dfded821097be62dc7ba20d53a9c96d0de13134 (patch) | |
tree | c686cdb704fe91337e8e7ea5253c9582b407e51c | |
parent | 532f51388b0432f41f4a178a98207ba1d81149f7 (diff) | |
parent | 0c27362998a8357f199501aa401e99c51c2eb46e (diff) | |
download | op-kernel-dev-2dfded821097be62dc7ba20d53a9c96d0de13134.zip op-kernel-dev-2dfded821097be62dc7ba20d53a9c96d0de13134.tar.gz |
Merge tag 'locks-v3.16-2' of git://git.samba.org/jlayton/linux
Pull file locking fixes from Jeff Layton:
"File locking related bugfixes
Nothing too earth-shattering here. A fix for a potential regression
due to a patch in pile #1, and the addition of a memory barrier to
prevent a race condition between break_deleg and generic_add_lease"
* tag 'locks-v3.16-2' of git://git.samba.org/jlayton/linux:
locks: set fl_owner for leases back to current->files
locks: add missing memory barrier in break_deleg
-rw-r--r-- | fs/locks.c | 2 | ||||
-rw-r--r-- | include/linux/fs.h | 6 |
2 files changed, 7 insertions, 1 deletions
@@ -431,7 +431,7 @@ static int lease_init(struct file *filp, long type, struct file_lock *fl) if (assign_type(fl, type) != 0) return -EINVAL; - fl->fl_owner = (fl_owner_t)filp; + fl->fl_owner = (fl_owner_t)current->files; fl->fl_pid = current->tgid; fl->fl_file = filp; diff --git a/include/linux/fs.h b/include/linux/fs.h index 338e6f7..e11d60c 100644 --- a/include/linux/fs.h +++ b/include/linux/fs.h @@ -1921,6 +1921,12 @@ static inline int break_lease(struct inode *inode, unsigned int mode) static inline int break_deleg(struct inode *inode, unsigned int mode) { + /* + * Since this check is lockless, we must ensure that any refcounts + * taken are done before checking inode->i_flock. Otherwise, we could + * end up racing with tasks trying to set a new lease on this file. + */ + smp_mb(); if (inode->i_flock) return __break_lease(inode, mode, FL_DELEG); return 0; |