提交 87d918d6 编写于 作者: J J. Bruce Fields 提交者: Trond Myklebust

rpc: gss: fix a kmap_atomic race in krb5 code

This code is never called from interrupt context; it's always run by either
a user thread or rpciod.  So KM_SKB_SUNRPC_DATA is inappropriate here.

Thanks to Aimé Le Rouzic for capturing an oops which showed the kernel
taking an interrupt while we were in this piece of code, resulting in a
nested kmap_atomic(.,KM_SKB_SUNRPC_DATA) call from
xdr_partial_copy_from_skb().
Signed-off-by: NJ. Bruce Fields <bfields@citi.umich.edu>
Signed-off-by: NTrond Myklebust <Trond.Myklebust@netapp.com>
上级 8fc7500b
...@@ -57,9 +57,9 @@ gss_krb5_remove_padding(struct xdr_buf *buf, int blocksize) ...@@ -57,9 +57,9 @@ gss_krb5_remove_padding(struct xdr_buf *buf, int blocksize)
>>PAGE_CACHE_SHIFT; >>PAGE_CACHE_SHIFT;
int offset = (buf->page_base + len - 1) int offset = (buf->page_base + len - 1)
& (PAGE_CACHE_SIZE - 1); & (PAGE_CACHE_SIZE - 1);
ptr = kmap_atomic(buf->pages[last], KM_SKB_SUNRPC_DATA); ptr = kmap_atomic(buf->pages[last], KM_USER0);
pad = *(ptr + offset); pad = *(ptr + offset);
kunmap_atomic(ptr, KM_SKB_SUNRPC_DATA); kunmap_atomic(ptr, KM_USER0);
goto out; goto out;
} else } else
len -= buf->page_len; len -= buf->page_len;
......
Markdown is supported
0% .
You are about to add 0 people to the discussion. Proceed with caution.
先完成此消息的编辑!
想要评论请 注册