Donate to e Foundation | Murena handsets with /e/OS | Own a part of Murena! Learn more

Commit 9b4f526c authored by Al Viro's avatar Al Viro
Browse files

[PATCH] proc_readfd_common() race fix



Since we drop the rcu_read_lock inside the loop, we can't assume
that files->fdt will remain unchanged (and not freed) between
iterations.

Signed-off-by: default avatarAl Viro <viro@zeniv.linux.org.uk>
parent ed152437
Loading
Loading
Loading
Loading
+1 −3
Original line number Diff line number Diff line
@@ -1626,7 +1626,6 @@ static int proc_readfd_common(struct file * filp, void * dirent,
	unsigned int fd, ino;
	int retval;
	struct files_struct * files;
	struct fdtable *fdt;

	retval = -ENOENT;
	if (!p)
@@ -1649,9 +1648,8 @@ static int proc_readfd_common(struct file * filp, void * dirent,
			if (!files)
				goto out;
			rcu_read_lock();
			fdt = files_fdtable(files);
			for (fd = filp->f_pos-2;
			     fd < fdt->max_fds;
			     fd < files_fdtable(files)->max_fds;
			     fd++, filp->f_pos++) {
				char name[PROC_NUMBUF];
				int len;