提交 ce3c4ad7 编写于 作者: C Chuck Lever

NFSD: Fix possible sleep during nfsd4_release_lockowner()

nfsd4_release_lockowner() holds clp->cl_lock when it calls
check_for_locks(). However, check_for_locks() calls nfsd_file_get()
/ nfsd_file_put() to access the backing inode's flc_posix list, and
nfsd_file_put() can sleep if the inode was recently removed.

Let's instead rely on the stateowner's reference count to gate
whether the release is permitted. This should be a reliable
indication of locks-in-use since file lock operations and
->lm_get_owner take appropriate references, which are released
appropriately when file locks are removed.
Reported-by: NDai Ngo <dai.ngo@oracle.com>
Signed-off-by: NChuck Lever <chuck.lever@oracle.com>
Cc: stable@vger.kernel.org
上级 fd5e363e
...@@ -7557,16 +7557,12 @@ nfsd4_release_lockowner(struct svc_rqst *rqstp, ...@@ -7557,16 +7557,12 @@ nfsd4_release_lockowner(struct svc_rqst *rqstp,
if (sop->so_is_open_owner || !same_owner_str(sop, owner)) if (sop->so_is_open_owner || !same_owner_str(sop, owner))
continue; continue;
/* see if there are still any locks associated with it */ if (atomic_read(&sop->so_count) != 1) {
lo = lockowner(sop); spin_unlock(&clp->cl_lock);
list_for_each_entry(stp, &sop->so_stateids, st_perstateowner) { return nfserr_locks_held;
if (check_for_locks(stp->st_stid.sc_file, lo)) {
status = nfserr_locks_held;
spin_unlock(&clp->cl_lock);
return status;
}
} }
lo = lockowner(sop);
nfs4_get_stateowner(sop); nfs4_get_stateowner(sop);
break; break;
} }
......
Markdown is supported
0% .
You are about to add 0 people to the discussion. Proceed with caution.
先完成此消息的编辑!
想要评论请 注册