cifs: Replace wrtPending with a real reference count
authorDave Kleikamp <shaggy@linux.vnet.ibm.com>
Mon, 31 Aug 2009 15:07:12 +0000 (11:07 -0400)
committerSteve French <sfrench@us.ibm.com>
Tue, 1 Sep 2009 22:35:01 +0000 (22:35 +0000)
Currently, cifs_close() tries to wait until all I/O is complete and then
frees the file private data.  If I/O does not completely in a reasonable
amount of time it frees the structure anyway, leaving a potential use-
after-free situation.

This patch changes the wrtPending counter to a complete reference count and
lets the last user free the structure.

Signed-off-by: Dave Kleikamp <shaggy@linux.vnet.ibm.com>
Reviewed-by: Jeff Layton <jlayton@redhat.com>
Tested-by: Shirish Pargaonkar <shirishp@us.ibm.com>
Signed-off-by: Steve French <sfrench@us.ibm.com>

No differences found