提交 f00e35e2 编写于 作者: W wangyunjian 提交者: David S. Miller

virtio_net: fix virtnet_open and virtnet_probe competing for try_fill_recv

In function virtnet_open() and virtnet_probe(), func try_fill_recv() may
be executed at the same time. VQ in virtqueue_add() has not been protected
well and BUG_ON will be triggered when virito_net.ko being removed.
Signed-off-by: NYunjian Wang <wangyunjian@huawei.com>
Acked-by: NJason Wang <jasowang@redhat.com>
Acked-by: NMichael S. Tsirkin <mst@redhat.com>
Signed-off-by: NDavid S. Miller <davem@davemloft.net>
上级 bae5499c
...@@ -1925,24 +1925,11 @@ static int virtnet_probe(struct virtio_device *vdev) ...@@ -1925,24 +1925,11 @@ static int virtnet_probe(struct virtio_device *vdev)
virtio_device_ready(vdev); virtio_device_ready(vdev);
/* Last of all, set up some receive buffers. */
for (i = 0; i < vi->curr_queue_pairs; i++) {
try_fill_recv(vi, &vi->rq[i], GFP_KERNEL);
/* If we didn't even get one input buffer, we're useless. */
if (vi->rq[i].vq->num_free ==
virtqueue_get_vring_size(vi->rq[i].vq)) {
free_unused_bufs(vi);
err = -ENOMEM;
goto free_recv_bufs;
}
}
vi->nb.notifier_call = &virtnet_cpu_callback; vi->nb.notifier_call = &virtnet_cpu_callback;
err = register_hotcpu_notifier(&vi->nb); err = register_hotcpu_notifier(&vi->nb);
if (err) { if (err) {
pr_debug("virtio_net: registering cpu notifier failed\n"); pr_debug("virtio_net: registering cpu notifier failed\n");
goto free_recv_bufs; goto free_unregister_netdev;
} }
/* Assume link up if device can't report link status, /* Assume link up if device can't report link status,
...@@ -1960,10 +1947,9 @@ static int virtnet_probe(struct virtio_device *vdev) ...@@ -1960,10 +1947,9 @@ static int virtnet_probe(struct virtio_device *vdev)
return 0; return 0;
free_recv_bufs: free_unregister_netdev:
vi->vdev->config->reset(vdev); vi->vdev->config->reset(vdev);
free_receive_bufs(vi);
unregister_netdev(dev); unregister_netdev(dev);
free_vqs: free_vqs:
cancel_delayed_work_sync(&vi->refill); cancel_delayed_work_sync(&vi->refill);
......
Markdown is supported
0% .
You are about to add 0 people to the discussion. Proceed with caution.
先完成此消息的编辑!
想要评论请 注册