Commit 689901ce authored by Ilya Zykov's avatar Ilya Zykov Committed by Ben Hutchings

tty: Correct tty buffer flush.

commit 64325a3b upstream.

  The root of problem is carelessly zeroing pointer(in function __tty_buffer_flush()),
when another thread can use it. It can be cause of "NULL pointer dereference".
  Main idea of the patch, this is never free last (struct tty_buffer) in the active buffer.
Only flush the data for ldisc(buf->head->read = buf->head->commit).
At that moment driver can collect(write) data in buffer without conflict.
It is repeat behavior of flush_to_ldisc(), only without feeding data to ldisc.
Signed-off-by: default avatarIlya Zykov <ilya@ilyx.ru>
Signed-off-by: default avatarBen Hutchings <ben@decadent.org.uk>
parent 8c92cb1f
......@@ -114,11 +114,14 @@ static void __tty_buffer_flush(struct tty_struct *tty)
{
struct tty_buffer *thead;
while ((thead = tty->buf.head) != NULL) {
tty->buf.head = thead->next;
tty_buffer_free(tty, thead);
if (tty->buf.head == NULL)
return;
while ((thead = tty->buf.head->next) != NULL) {
tty_buffer_free(tty, tty->buf.head);
tty->buf.head = thead;
}
tty->buf.tail = NULL;
WARN_ON(tty->buf.head != tty->buf.tail);
tty->buf.head->read = tty->buf.head->commit;
}
/**
......
Markdown is supported
0%
or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment