Răsfoiți Sursa

IPoIB: Close race in ipoib_flush_paths()

ib_sa_cancel_query() must be called with priv->lock held since
a completion might arrive and set path->query to NULL.

Signed-off-by: Eli Cohen <eli@mellanox.co.il>
Signed-off-by: Roland Dreier <rolandd@cisco.com>
Eli Cohen 19 ani în urmă
părinte
comite
a30bb96c6f
1 a modificat fișierele cu 3 adăugiri și 2 ștergeri
  1. 3 2
      drivers/infiniband/ulp/ipoib/ipoib_main.c

+ 3 - 2
drivers/infiniband/ulp/ipoib/ipoib_main.c

@@ -346,14 +346,15 @@ void ipoib_flush_paths(struct net_device *dev)
 	list_for_each_entry(path, &remove_list, list)
 	list_for_each_entry(path, &remove_list, list)
 		rb_erase(&path->rb_node, &priv->path_tree);
 		rb_erase(&path->rb_node, &priv->path_tree);
 
 
-	spin_unlock_irqrestore(&priv->lock, flags);
-
 	list_for_each_entry_safe(path, tp, &remove_list, list) {
 	list_for_each_entry_safe(path, tp, &remove_list, list) {
 		if (path->query)
 		if (path->query)
 			ib_sa_cancel_query(path->query_id, path->query);
 			ib_sa_cancel_query(path->query_id, path->query);
+		spin_unlock_irqrestore(&priv->lock, flags);
 		wait_for_completion(&path->done);
 		wait_for_completion(&path->done);
 		path_free(dev, path);
 		path_free(dev, path);
+		spin_lock_irqsave(&priv->lock, flags);
 	}
 	}
+	spin_unlock_irqrestore(&priv->lock, flags);
 }
 }
 
 
 static void path_rec_completion(int status,
 static void path_rec_completion(int status,