提交 50d61ff7 编写于 作者: R Reshetova, Elena 提交者: David S. Miller

net, rds: convert rds_ib_device.refcount from atomic_t to refcount_t

refcount_t type and corresponding API should be
used instead of atomic_t when the variable is used as
a reference counter. This allows to avoid accidental
refcounter overflows that might lead to use-after-free
situations.
Signed-off-by: NElena Reshetova <elena.reshetova@intel.com>
Signed-off-by: NHans Liljestrand <ishkamiel@gmail.com>
Signed-off-by: NKees Cook <keescook@chromium.org>
Signed-off-by: NDavid Windsor <dwindsor@gmail.com>
Signed-off-by: NDavid S. Miller <davem@davemloft.net>
上级 7ff13969
...@@ -118,8 +118,8 @@ static void rds_ib_dev_free(struct work_struct *work) ...@@ -118,8 +118,8 @@ static void rds_ib_dev_free(struct work_struct *work)
void rds_ib_dev_put(struct rds_ib_device *rds_ibdev) void rds_ib_dev_put(struct rds_ib_device *rds_ibdev)
{ {
BUG_ON(atomic_read(&rds_ibdev->refcount) <= 0); BUG_ON(refcount_read(&rds_ibdev->refcount) == 0);
if (atomic_dec_and_test(&rds_ibdev->refcount)) if (refcount_dec_and_test(&rds_ibdev->refcount))
queue_work(rds_wq, &rds_ibdev->free_work); queue_work(rds_wq, &rds_ibdev->free_work);
} }
...@@ -137,7 +137,7 @@ static void rds_ib_add_one(struct ib_device *device) ...@@ -137,7 +137,7 @@ static void rds_ib_add_one(struct ib_device *device)
return; return;
spin_lock_init(&rds_ibdev->spinlock); spin_lock_init(&rds_ibdev->spinlock);
atomic_set(&rds_ibdev->refcount, 1); refcount_set(&rds_ibdev->refcount, 1);
INIT_WORK(&rds_ibdev->free_work, rds_ib_dev_free); INIT_WORK(&rds_ibdev->free_work, rds_ib_dev_free);
rds_ibdev->max_wrs = device->attrs.max_qp_wr; rds_ibdev->max_wrs = device->attrs.max_qp_wr;
...@@ -205,10 +205,10 @@ static void rds_ib_add_one(struct ib_device *device) ...@@ -205,10 +205,10 @@ static void rds_ib_add_one(struct ib_device *device)
down_write(&rds_ib_devices_lock); down_write(&rds_ib_devices_lock);
list_add_tail_rcu(&rds_ibdev->list, &rds_ib_devices); list_add_tail_rcu(&rds_ibdev->list, &rds_ib_devices);
up_write(&rds_ib_devices_lock); up_write(&rds_ib_devices_lock);
atomic_inc(&rds_ibdev->refcount); refcount_inc(&rds_ibdev->refcount);
ib_set_client_data(device, &rds_ib_client, rds_ibdev); ib_set_client_data(device, &rds_ib_client, rds_ibdev);
atomic_inc(&rds_ibdev->refcount); refcount_inc(&rds_ibdev->refcount);
rds_ib_nodev_connect(); rds_ib_nodev_connect();
...@@ -239,7 +239,7 @@ struct rds_ib_device *rds_ib_get_client_data(struct ib_device *device) ...@@ -239,7 +239,7 @@ struct rds_ib_device *rds_ib_get_client_data(struct ib_device *device)
rcu_read_lock(); rcu_read_lock();
rds_ibdev = ib_get_client_data(device, &rds_ib_client); rds_ibdev = ib_get_client_data(device, &rds_ib_client);
if (rds_ibdev) if (rds_ibdev)
atomic_inc(&rds_ibdev->refcount); refcount_inc(&rds_ibdev->refcount);
rcu_read_unlock(); rcu_read_unlock();
return rds_ibdev; return rds_ibdev;
} }
......
...@@ -230,7 +230,7 @@ struct rds_ib_device { ...@@ -230,7 +230,7 @@ struct rds_ib_device {
unsigned int max_initiator_depth; unsigned int max_initiator_depth;
unsigned int max_responder_resources; unsigned int max_responder_resources;
spinlock_t spinlock; /* protect the above */ spinlock_t spinlock; /* protect the above */
atomic_t refcount; refcount_t refcount;
struct work_struct free_work; struct work_struct free_work;
int *vector_load; int *vector_load;
}; };
......
...@@ -52,7 +52,7 @@ static struct rds_ib_device *rds_ib_get_device(__be32 ipaddr) ...@@ -52,7 +52,7 @@ static struct rds_ib_device *rds_ib_get_device(__be32 ipaddr)
list_for_each_entry_rcu(rds_ibdev, &rds_ib_devices, list) { list_for_each_entry_rcu(rds_ibdev, &rds_ib_devices, list) {
list_for_each_entry_rcu(i_ipaddr, &rds_ibdev->ipaddr_list, list) { list_for_each_entry_rcu(i_ipaddr, &rds_ibdev->ipaddr_list, list) {
if (i_ipaddr->ipaddr == ipaddr) { if (i_ipaddr->ipaddr == ipaddr) {
atomic_inc(&rds_ibdev->refcount); refcount_inc(&rds_ibdev->refcount);
rcu_read_unlock(); rcu_read_unlock();
return rds_ibdev; return rds_ibdev;
} }
...@@ -134,7 +134,7 @@ void rds_ib_add_conn(struct rds_ib_device *rds_ibdev, struct rds_connection *con ...@@ -134,7 +134,7 @@ void rds_ib_add_conn(struct rds_ib_device *rds_ibdev, struct rds_connection *con
spin_unlock_irq(&ib_nodev_conns_lock); spin_unlock_irq(&ib_nodev_conns_lock);
ic->rds_ibdev = rds_ibdev; ic->rds_ibdev = rds_ibdev;
atomic_inc(&rds_ibdev->refcount); refcount_inc(&rds_ibdev->refcount);
} }
void rds_ib_remove_conn(struct rds_ib_device *rds_ibdev, struct rds_connection *conn) void rds_ib_remove_conn(struct rds_ib_device *rds_ibdev, struct rds_connection *conn)
......
Markdown is supported
0% .
You are about to add 0 people to the discussion. Proceed with caution.
先完成此消息的编辑!
想要评论请 注册