diff options
| author | Johannes Berg <johannes.berg@intel.com> | 2015-11-17 14:25:21 +0100 | 
|---|---|---|
| committer | Johannes Berg <johannes.berg@intel.com> | 2015-11-17 15:49:25 +0100 | 
| commit | c2e703a55245bfff3db53b1f7cbe59f1ee8a4339 (patch) | |
| tree | 99b32f45dd6476c616c95379a80abf6d85aefc23 /lib/string_helpers.c | |
| parent | 45bb780a2147b9995f3d288c44ecb87ca8a330e2 (diff) | |
mac80211: mesh: fix call_rcu() usage
When using call_rcu(), the called function may be delayed quite
significantly, and without a matching rcu_barrier() there's no
way to be sure it has finished.
Therefore, global state that could be gone/freed/reused should
never be touched in the callback.
Fix this in mesh by moving the atomic_dec() into the caller;
that's not really a problem since we already unlinked the path
and it will be destroyed anyway.
This fixes a crash Jouni observed when running certain tests in
a certain order, in which the mesh interface was torn down, the
memory reused for a function pointer (work struct) and running
that then crashed since the pointer had been decremented by 1,
resulting in an invalid instruction byte stream.
Cc: stable@vger.kernel.org
Fixes: eb2b9311fd00 ("mac80211: mesh path table implementation")
Reported-by: Jouni Malinen <j@w1.fi>
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Diffstat (limited to 'lib/string_helpers.c')
0 files changed, 0 insertions, 0 deletions
