diff options
author | Cesar Eduardo Barros <cesarb@cesarb.net> | 2011-03-22 22:03:13 -0400 |
---|---|---|
committer | Linus Torvalds <torvalds@linux-foundation.org> | 2011-03-23 10:54:22 -0400 |
commit | 2130781e2aaab66e5a9f2fdc8af35da0153f405c (patch) | |
tree | ccd654b948587a39b219f74e6cfd73ef6daa3658 | |
parent | 04948c7f80b9446009c1c4791bb93e79729724fb (diff) |
sys_swapon: fix inode locking
A conflict between 52c50567d8ab ("mm: swap: unlock swapfile inode mutex
before closing file on bad swapfiles") and 83ef99befc32 ("sys_swapon:
remove did_down variable") caused a double unlock of the inode mutex
(once in bad_swap: before the filp_close, once at the end just before
returning).
The patch which added the extra unlock cleared did_down to avoid
unlocking twice, but the other patch removed the did_down variable.
To fix, set inode to NULL after the first unlock, since it will be used
after that point only for the final unlock.
While checking this patch, I found a path which could unlock without
locking, in case the same inode was added as a swapfile twice. To fix,
move the setting of the inode variable further down, to just before
claim_swapfile, which will lock the inode before doing anything else.
Cc: Mel Gorman <mgorman@suse.de>
Cc: Hugh Dickins <hughd@google.com>
Cc: Eric B Munson <emunson@mgebm.net>
Cc: KAMEZAWA Hiroyuki <kamezawa.hiroyu@jp.fujitsu.com>
Cc: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Cesar Eduardo Barros <cesarb@cesarb.net>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
-rw-r--r-- | mm/swapfile.c | 7 |
1 files changed, 5 insertions, 2 deletions
diff --git a/mm/swapfile.c b/mm/swapfile.c index aafcf3611b31..71b42ec55b78 100644 --- a/mm/swapfile.c +++ b/mm/swapfile.c | |||
@@ -2088,7 +2088,6 @@ SYSCALL_DEFINE2(swapon, const char __user *, specialfile, int, swap_flags) | |||
2088 | 2088 | ||
2089 | p->swap_file = swap_file; | 2089 | p->swap_file = swap_file; |
2090 | mapping = swap_file->f_mapping; | 2090 | mapping = swap_file->f_mapping; |
2091 | inode = mapping->host; | ||
2092 | 2091 | ||
2093 | for (i = 0; i < nr_swapfiles; i++) { | 2092 | for (i = 0; i < nr_swapfiles; i++) { |
2094 | struct swap_info_struct *q = swap_info[i]; | 2093 | struct swap_info_struct *q = swap_info[i]; |
@@ -2101,6 +2100,8 @@ SYSCALL_DEFINE2(swapon, const char __user *, specialfile, int, swap_flags) | |||
2101 | } | 2100 | } |
2102 | } | 2101 | } |
2103 | 2102 | ||
2103 | inode = mapping->host; | ||
2104 | /* If S_ISREG(inode->i_mode) will do mutex_lock(&inode->i_mutex); */ | ||
2104 | error = claim_swapfile(p, inode); | 2105 | error = claim_swapfile(p, inode); |
2105 | if (unlikely(error)) | 2106 | if (unlikely(error)) |
2106 | goto bad_swap; | 2107 | goto bad_swap; |
@@ -2187,8 +2188,10 @@ bad_swap: | |||
2187 | spin_unlock(&swap_lock); | 2188 | spin_unlock(&swap_lock); |
2188 | vfree(swap_map); | 2189 | vfree(swap_map); |
2189 | if (swap_file) { | 2190 | if (swap_file) { |
2190 | if (inode && S_ISREG(inode->i_mode)) | 2191 | if (inode && S_ISREG(inode->i_mode)) { |
2191 | mutex_unlock(&inode->i_mutex); | 2192 | mutex_unlock(&inode->i_mutex); |
2193 | inode = NULL; | ||
2194 | } | ||
2192 | filp_close(swap_file, NULL); | 2195 | filp_close(swap_file, NULL); |
2193 | } | 2196 | } |
2194 | out: | 2197 | out: |