[7/8] ceph: fix potential race in ceph_check_caps
diff mbox series

Message ID 20200323160708.104152-8-jlayton@kernel.org
State New
Headers show
Series
  • ceph: cap handling code fixes, cleanups and comments
Related show

Commit Message

Jeff Layton March 23, 2020, 4:07 p.m. UTC
Nothing ensures that session will still be valid by the time we
dereference the pointer. Take and put a reference.

Signed-off-by: Jeff Layton <jlayton@kernel.org>
---
 fs/ceph/caps.c | 2 ++
 1 file changed, 2 insertions(+)

Patch
diff mbox series

diff --git a/fs/ceph/caps.c b/fs/ceph/caps.c
index 3eab905ba74b..061e52912991 100644
--- a/fs/ceph/caps.c
+++ b/fs/ceph/caps.c
@@ -2051,12 +2051,14 @@  void ceph_check_caps(struct ceph_inode_info *ci, int flags,
 			if (mutex_trylock(&session->s_mutex) == 0) {
 				dout("inverting session/ino locks on %p\n",
 				     session);
+				session = ceph_get_mds_session(session);
 				spin_unlock(&ci->i_ceph_lock);
 				if (took_snap_rwsem) {
 					up_read(&mdsc->snap_rwsem);
 					took_snap_rwsem = 0;
 				}
 				mutex_lock(&session->s_mutex);
+				ceph_put_mds_session(session);
 				goto retry;
 			}
 		}