Skip to content

Commit

Permalink
Staging: android: task_get_unused_fd_flags: fix the wrong usage of ts…
Browse files Browse the repository at this point in the history
…k->signal

Compile tested.

task_struct->signal is not protected by RCU, the code is bogus.
Change the code to take ->siglock to pin ->signal.

Signed-off-by: Oleg Nesterov <oleg@redhat.com>
Cc: Arve Hjønnevåg <arve@android.com>
Cc: Brian Swetland <swetland@google.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@suse.de>
  • Loading branch information
Oleg Nesterov authored and Greg Kroah-Hartman committed Jan 28, 2009
1 parent 191805a commit 1176e83
Showing 1 changed file with 5 additions and 5 deletions.
10 changes: 5 additions & 5 deletions drivers/staging/android/binder.c
Original file line number Diff line number Diff line change
Expand Up @@ -319,6 +319,7 @@ int task_get_unused_fd_flags(struct task_struct *tsk, int flags)
int fd, error;
struct fdtable *fdt;
unsigned long rlim_cur;
unsigned long irqs;

if (files == NULL)
return -ESRCH;
Expand All @@ -335,12 +336,11 @@ int task_get_unused_fd_flags(struct task_struct *tsk, int flags)
* N.B. For clone tasks sharing a files structure, this test
* will limit the total number of files that can be opened.
*/
rcu_read_lock();
if (tsk->signal)
rlim_cur = 0;
if (lock_task_sighand(tsk, &irqs)) {
rlim_cur = tsk->signal->rlim[RLIMIT_NOFILE].rlim_cur;
else
rlim_cur = 0;
rcu_read_unlock();
unlock_task_sighand(tsk, &irqs);
}
if (fd >= rlim_cur)
goto out;

Expand Down

0 comments on commit 1176e83

Please sign in to comment.