Thread (14 messages) 14 messages, 5 authors, 2011-05-11

[PATCH V2] fbcon -- fix race between open and removal of framebuffers

flat view
STALE5628d

From: Tim Gardner <hidden>
Date: 2011-05-10 12:47:59
Also in: lkml

On 05/05/2011 11:00 PM, Jack Stone wrote:
On 05/05/2011 18:41, tim.gardner@canonical.com wrote:
quoted
+static struct fb_info *get_framebuffer_info(int idx)
+__acquires(&registered_lock)
+__releases(&registered_lock)
+{
+	struct fb_info *fb_info;
+
+	spin_lock(&registered_lock);
+	fb_info = registered_fb[idx];
+	fb_info->ref_count++;
+	spin_unlock(&registered_lock);
+
+	return fb_info;
+}
+
  static int
  fb_open(struct inode *inode, struct file *file)
  __acquires(&info->lock)
@@ -1363,13 +1421,17 @@ __releases(&info->lock)

  	if (fbidx>= FB_MAX)
  		return -ENODEV;
-	info = registered_fb[fbidx];
+	info = get_framebuffer_info(fbidx);
  	if (!info)
  		request_module("fb%d", fbidx);
-	info = registered_fb[fbidx];
+	info = get_framebuffer_info(fbidx);
  	if (!info)
  		return -ENODEV;
If the first get_framebuffer_info succeeds don't you up the ref count
twice? Shouldn't this be:

info = get_framebuffer_info(fbidx);
if (!info) {
	request_module("fb%d", fbidx);
	info = get_framebuffer_info(fbidx);
}
if (!info)
	return -ENODEV;

Thanks,

Jack
Good catch. See attached.

rtg
-- 
Tim Gardner tim.gardner@canonical.com

Attachments

Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help