diff options
| author | Steve Wise <swise@opengridcomputing.com> | 2013-11-21 15:40:14 -0600 |
|---|---|---|
| committer | Roland Dreier <roland@purestorage.com> | 2013-12-15 16:47:47 -0800 |
| commit | 6b59ba609bb61e4fa2ecca7827f170ac07842d64 (patch) | |
| tree | cb7f4cc3a619bf13bc01f0f7175e7f61c36ec9d6 /net/dsa/dsa.c | |
| parent | 374b105797c3d4f29c685f3be535c35f5689b30e (diff) | |
RDMA/iwcm: Don't touch cm_id after deref in rem_ref
rem_ref() calls iwcm_deref_id(), which will wake up any blockers on
cm_id_priv->destroy_comp if the refcnt hits 0. That will unblock
someone in iw_destroy_cm_id() which will free the cmid. If that
happens before rem_ref() calls test_bit(IWCM_F_CALLBACK_DESTROY,
&cm_id_priv->flags), then the test_bit() will touch freed memory.
The fix is to read the bit first, then deref. We should never be in
iw_destroy_cm_id() with IWCM_F_CALLBACK_DESTROY set, and there is a
BUG_ON() to make sure of that.
Signed-off-by: Steve Wise <swise@opengridcomputing.com>
Signed-off-by: Roland Dreier <roland@purestorage.com>
Diffstat (limited to 'net/dsa/dsa.c')
0 files changed, 0 insertions, 0 deletions
