Donate to e Foundation | Murena handsets with /e/OS | Own a part of Murena! Learn more

Commit 9ca99eec authored by Javier Cardona's avatar Javier Cardona Committed by John W. Linville
Browse files

mac80211: Check size of a new mesh path table for changes since allocation.



Not sure if I'm chasing a ghost here, seems like the
mesh_path->size_order needs to be inside an RCU-read section to prevent
that value from changing between table allocation and copying.  We have
observed crashes that might be caused by this.

Signed-off-by: default avatarJavier Cardona <javier@cozybit.com>
Signed-off-by: default avatarJohn W. Linville <linville@tuxdriver.com>
parent 8f9cb77d
Loading
Loading
Loading
Loading
+6 −3
Original line number Diff line number Diff line
@@ -76,7 +76,6 @@ static int mesh_table_grow(struct mesh_table *oldtbl,
			< oldtbl->mean_chain_len * (oldtbl->hash_mask + 1))
		return -EAGAIN;


	newtbl->free_node = oldtbl->free_node;
	newtbl->mean_chain_len = oldtbl->mean_chain_len;
	newtbl->copy_node = oldtbl->copy_node;
@@ -329,7 +328,8 @@ void mesh_mpath_table_grow(void)
{
	struct mesh_table *oldtbl, *newtbl;

	newtbl = mesh_table_alloc(mesh_paths->size_order + 1);
	rcu_read_lock();
	newtbl = mesh_table_alloc(rcu_dereference(mesh_paths)->size_order + 1);
	if (!newtbl)
		return;
	write_lock(&pathtbl_resize_lock);
@@ -339,6 +339,7 @@ void mesh_mpath_table_grow(void)
		write_unlock(&pathtbl_resize_lock);
		return;
	}
	rcu_read_unlock();
	rcu_assign_pointer(mesh_paths, newtbl);
	write_unlock(&pathtbl_resize_lock);

@@ -350,7 +351,8 @@ void mesh_mpp_table_grow(void)
{
	struct mesh_table *oldtbl, *newtbl;

	newtbl = mesh_table_alloc(mpp_paths->size_order + 1);
	rcu_read_lock();
	newtbl = mesh_table_alloc(rcu_dereference(mpp_paths)->size_order + 1);
	if (!newtbl)
		return;
	write_lock(&pathtbl_resize_lock);
@@ -360,6 +362,7 @@ void mesh_mpp_table_grow(void)
		write_unlock(&pathtbl_resize_lock);
		return;
	}
	rcu_read_unlock();
	rcu_assign_pointer(mpp_paths, newtbl);
	write_unlock(&pathtbl_resize_lock);