提交 844cf763 编写于 作者: J Jon Paul Maloy 提交者: David S. Miller

tipc: make macro tipc_wait_for_cond() smp safe

The macro tipc_wait_for_cond() is embedding the macro sk_wait_event()
to fulfil its task. The latter, in turn, is evaluating the stated
condition outside the socket lock context. This is problematic if
the condition is accessing non-trivial data structures which may be
altered by incoming interrupts, as is the case with the cong_links()
linked list, used by socket to keep track of the current set of
congested links. We sometimes see crashes when this list is accessed
by a condition function at the same time as a SOCK_WAKEUP interrupt
is removing an element from the list.

We fix this by expanding selected parts of sk_wait_event() into the
outer macro, while ensuring that all evaluations of a given condition
are performed under socket lock protection.

Fixes: commit 365ad353 ("tipc: reduce risk of user starvation during link congestion")
Reviewed-by: NParthasarathy Bhuvaragan <parthasarathy.bhuvaragan@ericsson.com>
Signed-off-by: NJon Maloy <jon.maloy@ericsson.com>
Signed-off-by: NDavid S. Miller <davem@davemloft.net>
上级 ad990dbe
...@@ -362,25 +362,25 @@ static int tipc_sk_sock_err(struct socket *sock, long *timeout) ...@@ -362,25 +362,25 @@ static int tipc_sk_sock_err(struct socket *sock, long *timeout)
return 0; return 0;
} }
#define tipc_wait_for_cond(sock_, timeout_, condition_) \ #define tipc_wait_for_cond(sock_, timeo_, condition_) \
({ \ ({ \
int rc_ = 0; \ struct sock *sk_; \
int done_ = 0; \ int rc_; \
\ \
while (!(condition_) && !done_) { \ while ((rc_ = !(condition_))) { \
struct sock *sk_ = sock->sk; \ DEFINE_WAIT_FUNC(wait_, woken_wake_function); \
DEFINE_WAIT_FUNC(wait_, woken_wake_function); \ sk_ = (sock_)->sk; \
\ rc_ = tipc_sk_sock_err((sock_), timeo_); \
rc_ = tipc_sk_sock_err(sock_, timeout_); \ if (rc_) \
if (rc_) \ break; \
break; \ prepare_to_wait(sk_sleep(sk_), &wait_, TASK_INTERRUPTIBLE); \
prepare_to_wait(sk_sleep(sk_), &wait_, \ release_sock(sk_); \
TASK_INTERRUPTIBLE); \ *(timeo_) = wait_woken(&wait_, TASK_INTERRUPTIBLE, *(timeo_)); \
done_ = sk_wait_event(sk_, timeout_, \ sched_annotate_sleep(); \
(condition_), &wait_); \ lock_sock(sk_); \
remove_wait_queue(sk_sleep(sk_), &wait_); \ remove_wait_queue(sk_sleep(sk_), &wait_); \
} \ } \
rc_; \ rc_; \
}) })
/** /**
......
Markdown is supported
0% .
You are about to add 0 people to the discussion. Proceed with caution.
先完成此消息的编辑!
想要评论请 注册