提交 9b4f526c 编写于 作者: A Al Viro

[PATCH] proc_readfd_common() race fix

Since we drop the rcu_read_lock inside the loop, we can't assume
that files->fdt will remain unchanged (and not freed) between
iterations.
Signed-off-by: NAl Viro <viro@zeniv.linux.org.uk>
上级 ed152437
...@@ -1626,7 +1626,6 @@ static int proc_readfd_common(struct file * filp, void * dirent, ...@@ -1626,7 +1626,6 @@ static int proc_readfd_common(struct file * filp, void * dirent,
unsigned int fd, ino; unsigned int fd, ino;
int retval; int retval;
struct files_struct * files; struct files_struct * files;
struct fdtable *fdt;
retval = -ENOENT; retval = -ENOENT;
if (!p) if (!p)
...@@ -1649,9 +1648,8 @@ static int proc_readfd_common(struct file * filp, void * dirent, ...@@ -1649,9 +1648,8 @@ static int proc_readfd_common(struct file * filp, void * dirent,
if (!files) if (!files)
goto out; goto out;
rcu_read_lock(); rcu_read_lock();
fdt = files_fdtable(files);
for (fd = filp->f_pos-2; for (fd = filp->f_pos-2;
fd < fdt->max_fds; fd < files_fdtable(files)->max_fds;
fd++, filp->f_pos++) { fd++, filp->f_pos++) {
char name[PROC_NUMBUF]; char name[PROC_NUMBUF];
int len; int len;
......
Markdown is supported
0% .
You are about to add 0 people to the discussion. Proceed with caution.
先完成此消息的编辑!
想要评论请 注册