diff options
Diffstat (limited to 'drivers/vhost/vhost.c')
| -rw-r--r-- | drivers/vhost/vhost.c | 22 | 
1 files changed, 16 insertions, 6 deletions
| diff --git a/drivers/vhost/vhost.c b/drivers/vhost/vhost.c index dd3d6f7406f8..8b5a1b33d0fe 100644 --- a/drivers/vhost/vhost.c +++ b/drivers/vhost/vhost.c | |||
| @@ -320,7 +320,7 @@ long vhost_dev_reset_owner(struct vhost_dev *dev) | |||
| 320 | vhost_dev_cleanup(dev); | 320 | vhost_dev_cleanup(dev); | 
| 321 | 321 | ||
| 322 | memory->nregions = 0; | 322 | memory->nregions = 0; | 
| 323 | dev->memory = memory; | 323 | RCU_INIT_POINTER(dev->memory, memory); | 
| 324 | return 0; | 324 | return 0; | 
| 325 | } | 325 | } | 
| 326 | 326 | ||
| @@ -352,8 +352,9 @@ void vhost_dev_cleanup(struct vhost_dev *dev) | |||
| 352 | fput(dev->log_file); | 352 | fput(dev->log_file); | 
| 353 | dev->log_file = NULL; | 353 | dev->log_file = NULL; | 
| 354 | /* No one will access memory at this point */ | 354 | /* No one will access memory at this point */ | 
| 355 | kfree(dev->memory); | 355 | kfree(rcu_dereference_protected(dev->memory, | 
| 356 | dev->memory = NULL; | 356 | lockdep_is_held(&dev->mutex))); | 
| 357 | RCU_INIT_POINTER(dev->memory, NULL); | ||
| 357 | if (dev->mm) | 358 | if (dev->mm) | 
| 358 | mmput(dev->mm); | 359 | mmput(dev->mm); | 
| 359 | dev->mm = NULL; | 360 | dev->mm = NULL; | 
| @@ -440,14 +441,22 @@ static int vq_access_ok(unsigned int num, | |||
| 440 | /* Caller should have device mutex but not vq mutex */ | 441 | /* Caller should have device mutex but not vq mutex */ | 
| 441 | int vhost_log_access_ok(struct vhost_dev *dev) | 442 | int vhost_log_access_ok(struct vhost_dev *dev) | 
| 442 | { | 443 | { | 
| 443 | return memory_access_ok(dev, dev->memory, 1); | 444 | struct vhost_memory *mp; | 
| 445 | |||
| 446 | mp = rcu_dereference_protected(dev->memory, | ||
| 447 | lockdep_is_held(&dev->mutex)); | ||
| 448 | return memory_access_ok(dev, mp, 1); | ||
| 444 | } | 449 | } | 
| 445 | 450 | ||
| 446 | /* Verify access for write logging. */ | 451 | /* Verify access for write logging. */ | 
| 447 | /* Caller should have vq mutex and device mutex */ | 452 | /* Caller should have vq mutex and device mutex */ | 
| 448 | static int vq_log_access_ok(struct vhost_virtqueue *vq, void __user *log_base) | 453 | static int vq_log_access_ok(struct vhost_virtqueue *vq, void __user *log_base) | 
| 449 | { | 454 | { | 
| 450 | return vq_memory_access_ok(log_base, vq->dev->memory, | 455 | struct vhost_memory *mp; | 
| 456 | |||
| 457 | mp = rcu_dereference_protected(vq->dev->memory, | ||
| 458 | lockdep_is_held(&vq->mutex)); | ||
| 459 | return vq_memory_access_ok(log_base, mp, | ||
| 451 | vhost_has_feature(vq->dev, VHOST_F_LOG_ALL)) && | 460 | vhost_has_feature(vq->dev, VHOST_F_LOG_ALL)) && | 
| 452 | (!vq->log_used || log_access_ok(log_base, vq->log_addr, | 461 | (!vq->log_used || log_access_ok(log_base, vq->log_addr, | 
| 453 | sizeof *vq->used + | 462 | sizeof *vq->used + | 
| @@ -487,7 +496,8 @@ static long vhost_set_memory(struct vhost_dev *d, struct vhost_memory __user *m) | |||
| 487 | kfree(newmem); | 496 | kfree(newmem); | 
| 488 | return -EFAULT; | 497 | return -EFAULT; | 
| 489 | } | 498 | } | 
| 490 | oldmem = d->memory; | 499 | oldmem = rcu_dereference_protected(d->memory, | 
| 500 | lockdep_is_held(&d->mutex)); | ||
| 491 | rcu_assign_pointer(d->memory, newmem); | 501 | rcu_assign_pointer(d->memory, newmem); | 
| 492 | synchronize_rcu(); | 502 | synchronize_rcu(); | 
| 493 | kfree(oldmem); | 503 | kfree(oldmem); | 
