aboutsummaryrefslogtreecommitdiffstats
path: root/ipc
diff options
context:
space:
mode:
Diffstat (limited to 'ipc')
-rw-r--r--ipc/sem.c29
1 files changed, 23 insertions, 6 deletions
diff --git a/ipc/sem.c b/ipc/sem.c
index cd1093cf7e8f..70020066ac0d 100644
--- a/ipc/sem.c
+++ b/ipc/sem.c
@@ -194,14 +194,31 @@ void __init sem_init (void)
194 * sem_lock_(check_) routines are called in the paths where the rw_mutex 194 * sem_lock_(check_) routines are called in the paths where the rw_mutex
195 * is not held. 195 * is not held.
196 */ 196 */
197static inline struct sem_array *sem_lock(struct ipc_namespace *ns, int id) 197static inline struct sem_array *sem_obtain_lock(struct ipc_namespace *ns, int id)
198{ 198{
199 struct kern_ipc_perm *ipcp = ipc_lock(&sem_ids(ns), id); 199 struct kern_ipc_perm *ipcp;
200 struct sem_array *sma;
200 201
201 if (IS_ERR(ipcp)) 202 rcu_read_lock();
202 return (struct sem_array *)ipcp; 203 ipcp = ipc_obtain_object(&sem_ids(ns), id);
204 if (IS_ERR(ipcp)) {
205 sma = ERR_CAST(ipcp);
206 goto err;
207 }
203 208
204 return container_of(ipcp, struct sem_array, sem_perm); 209 spin_lock(&ipcp->lock);
210
211 /* ipc_rmid() may have already freed the ID while sem_lock
212 * was spinning: verify that the structure is still valid
213 */
214 if (!ipcp->deleted)
215 return container_of(ipcp, struct sem_array, sem_perm);
216
217 spin_unlock(&ipcp->lock);
218 sma = ERR_PTR(-EINVAL);
219err:
220 rcu_read_unlock();
221 return sma;
205} 222}
206 223
207static inline struct sem_array *sem_obtain_object(struct ipc_namespace *ns, int id) 224static inline struct sem_array *sem_obtain_object(struct ipc_namespace *ns, int id)
@@ -1593,7 +1610,7 @@ sleep_again:
1593 goto out_free; 1610 goto out_free;
1594 } 1611 }
1595 1612
1596 sma = sem_lock(ns, semid); 1613 sma = sem_obtain_lock(ns, semid);
1597 1614
1598 /* 1615 /*
1599 * Wait until it's guaranteed that no wakeup_sem_queue_do() is ongoing. 1616 * Wait until it's guaranteed that no wakeup_sem_queue_do() is ongoing.