cifs: Replace wrtPending with a real reference count
authorDave Kleikamp <shaggy@linux.vnet.ibm.com>
Mon, 31 Aug 2009 15:07:12 +0000 (11:07 -0400)
committerSteve French <sfrench@us.ibm.com>
Tue, 1 Sep 2009 22:35:01 +0000 (22:35 +0000)
commit6ab409b53dcaf28f83d518a6702f904b7cee3f41
tree050bfb690ac9df049343034681478a5bb174a823
parent1b49c5566136455764a8d17ead25784f534c202d
cifs: Replace wrtPending with a real reference count

Currently, cifs_close() tries to wait until all I/O is complete and then
frees the file private data.  If I/O does not completely in a reasonable
amount of time it frees the structure anyway, leaving a potential use-
after-free situation.

This patch changes the wrtPending counter to a complete reference count and
lets the last user free the structure.

Signed-off-by: Dave Kleikamp <shaggy@linux.vnet.ibm.com>
Reviewed-by: Jeff Layton <jlayton@redhat.com>
Tested-by: Shirish Pargaonkar <shirishp@us.ibm.com>
Signed-off-by: Steve French <sfrench@us.ibm.com>
fs/cifs/cifsacl.c
fs/cifs/cifsglob.h
fs/cifs/dir.c
fs/cifs/file.c
fs/cifs/inode.c