diff options
Diffstat (limited to 'ipc')
| -rw-r--r-- | ipc/shm.c | 53 | 
1 files changed, 43 insertions, 10 deletions
| diff --git a/ipc/shm.c b/ipc/shm.c index ed3027d0f277..331fc1b0b3c7 100644 --- a/ipc/shm.c +++ b/ipc/shm.c @@ -156,11 +156,12 @@ static inline struct shmid_kernel *shm_lock(struct ipc_namespace *ns, int id)  	struct kern_ipc_perm *ipcp = ipc_lock(&shm_ids(ns), id);  	/* -	 * We raced in the idr lookup or with shm_destroy().  Either way, the -	 * ID is busted. +	 * Callers of shm_lock() must validate the status of the returned ipc +	 * object pointer (as returned by ipc_lock()), and error out as +	 * appropriate.  	 */ -	WARN_ON(IS_ERR(ipcp)); - +	if (IS_ERR(ipcp)) +		return (void *)ipcp;  	return container_of(ipcp, struct shmid_kernel, shm_perm);  } @@ -186,18 +187,33 @@ static inline void shm_rmid(struct ipc_namespace *ns, struct shmid_kernel *s)  } -/* This is called by fork, once for every shm attach. */ -static void shm_open(struct vm_area_struct *vma) +static int __shm_open(struct vm_area_struct *vma)  {  	struct file *file = vma->vm_file;  	struct shm_file_data *sfd = shm_file_data(file);  	struct shmid_kernel *shp;  	shp = shm_lock(sfd->ns, sfd->id); + +	if (IS_ERR(shp)) +		return PTR_ERR(shp); +  	shp->shm_atim = get_seconds();  	shp->shm_lprid = task_tgid_vnr(current);  	shp->shm_nattch++;  	shm_unlock(shp); +	return 0; +} + +/* This is called by fork, once for every shm attach. */ +static void shm_open(struct vm_area_struct *vma) +{ +	int err = __shm_open(vma); +	/* +	 * We raced in the idr lookup or with shm_destroy(). +	 * Either way, the ID is busted. +	 */ +	WARN_ON_ONCE(err);  }  /* @@ -260,6 +276,14 @@ static void shm_close(struct vm_area_struct *vma)  	down_write(&shm_ids(ns).rwsem);  	/* remove from the list of attaches of the shm segment */  	shp = shm_lock(ns, sfd->id); + +	/* +	 * We raced in the idr lookup or with shm_destroy(). +	 * Either way, the ID is busted. +	 */ +	if (WARN_ON_ONCE(IS_ERR(shp))) +		goto done; /* no-op */ +  	shp->shm_lprid = task_tgid_vnr(current);  	shp->shm_dtim = get_seconds();  	shp->shm_nattch--; @@ -267,6 +291,7 @@ static void shm_close(struct vm_area_struct *vma)  		shm_destroy(ns, shp);  	else  		shm_unlock(shp); +done:  	up_write(&shm_ids(ns).rwsem);  } @@ -388,17 +413,25 @@ static int shm_mmap(struct file *file, struct vm_area_struct *vma)  	struct shm_file_data *sfd = shm_file_data(file);  	int ret; +	/* +	 * In case of remap_file_pages() emulation, the file can represent +	 * removed IPC ID: propogate shm_lock() error to caller. +	 */ +	ret =__shm_open(vma); +	if (ret) +		return ret; +  	ret = sfd->file->f_op->mmap(sfd->file, vma); -	if (ret != 0) +	if (ret) { +		shm_close(vma);  		return ret; +	}  	sfd->vm_ops = vma->vm_ops;  #ifdef CONFIG_MMU  	WARN_ON(!sfd->vm_ops->fault);  #endif  	vma->vm_ops = &shm_vm_ops; -	shm_open(vma); - -	return ret; +	return 0;  }  static int shm_release(struct inode *ino, struct file *file) | 
