vfs: Fix vfsmount_lock imbalance in path_init()
authorBen Hutchings <ben@decadent.org.uk>
Mon, 16 Feb 2015 03:21:17 +0000 (03:21 +0000)
committerBen Hutchings <ben@decadent.org.uk>
Fri, 20 Feb 2015 00:49:41 +0000 (00:49 +0000)
When backporting commit 4023bfc9f351 ("be careful with nd->inode in
path_init() and follow_dotdot_rcu()"), I failed to account for the
vfsmount_lock that is used in 3.2 but not upstream.  path_init() takes
the lock if performing RCU lookup, but must drop it if (and only if)
it subsequently fails.

Reported-by: nuxi@vault24.org
References: https://bugzilla.kernel.org/show_bug.cgi?id=92531
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
Tested-by: nuxi@vault24.org
fs/namei.c

index dea2dab..c8b13a9 100644 (file)
@@ -1567,6 +1567,7 @@ static int path_init(int dfd, const char *name, unsigned int flags,
        if (!(nd->flags & LOOKUP_ROOT))
                nd->root.mnt = NULL;
        rcu_read_unlock();
+       br_read_unlock(vfsmount_lock);
        return -ECHILD;
 
 fput_fail: