]> git.baikalelectronics.ru Git - kernel.git/commit
watch_queue, pipe: Free watchqueue state after clearing pipe ring
authorDavid Howells <dhowells@redhat.com>
Fri, 11 Mar 2022 13:23:38 +0000 (13:23 +0000)
committerLinus Torvalds <torvalds@linux-foundation.org>
Fri, 11 Mar 2022 18:17:12 +0000 (10:17 -0800)
commita7c30157079a2cbdb6864cd9c8164aef93282ca2
tree2f51a12315d4a96ce097736087eec3eec548f50a
parent9cfff156066d9217c3adcff4fc3dddf8b9e2fb12
watch_queue, pipe: Free watchqueue state after clearing pipe ring

In free_pipe_info(), free the watchqueue state after clearing the pipe
ring as each pipe ring descriptor has a release function, and in the
case of a notification message, this is watch_queue_pipe_buf_release()
which tries to mark the allocation bitmap that was previously released.

Fix this by moving the put of the pipe's ref on the watch queue to after
the ring has been cleared.  We still need to call watch_queue_clear()
before doing that to make sure that the pipe is disconnected from any
notification sources first.

Fixes: 175295c8c9fa ("pipe: Add general notification queue support")
Reported-by: Jann Horn <jannh@google.com>
Signed-off-by: David Howells <dhowells@redhat.com>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
fs/pipe.c