Commit a0f10464 authored by Alexey Khoroshilov's avatar Alexey Khoroshilov Committed by Greg Kroah-Hartman

w1: do not unlock unheld list_mutex in __w1_remove_master_device()

w1_process_callbacks() expects to be called with dev->list_mutex held,
but it is the fact only in w1_process(). __w1_remove_master_device()
calls w1_process_callbacks() after it releases list_mutex.

The patch fixes __w1_remove_master_device() to acquire list_mutex
for w1_process_callbacks().

Found by Linux Driver Verification project (linuxtesting.org).
Signed-off-by: default avatarAlexey Khoroshilov <khoroshilov@ispras.ru>
Acked-by: default avatarDavid Fries <david@fries.net>
Acked-by: default avatarEvgeniy Polyakov <zbr@ioremap.net>
Cc: stable <stable@vger.kernel.org> # 3.15
Signed-off-by: default avatarGreg Kroah-Hartman <gregkh@linuxfoundation.org>
parent 8a0427d1
...@@ -1078,6 +1078,8 @@ static void w1_search_process(struct w1_master *dev, u8 search_type) ...@@ -1078,6 +1078,8 @@ static void w1_search_process(struct w1_master *dev, u8 search_type)
* w1_process_callbacks() - execute each dev->async_list callback entry * w1_process_callbacks() - execute each dev->async_list callback entry
* @dev: w1_master device * @dev: w1_master device
* *
* The w1 master list_mutex must be held.
*
* Return: 1 if there were commands to executed 0 otherwise * Return: 1 if there were commands to executed 0 otherwise
*/ */
int w1_process_callbacks(struct w1_master *dev) int w1_process_callbacks(struct w1_master *dev)
......
...@@ -219,9 +219,13 @@ void __w1_remove_master_device(struct w1_master *dev) ...@@ -219,9 +219,13 @@ void __w1_remove_master_device(struct w1_master *dev)
if (msleep_interruptible(1000)) if (msleep_interruptible(1000))
flush_signals(current); flush_signals(current);
mutex_lock(&dev->list_mutex);
w1_process_callbacks(dev); w1_process_callbacks(dev);
mutex_unlock(&dev->list_mutex);
} }
mutex_lock(&dev->list_mutex);
w1_process_callbacks(dev); w1_process_callbacks(dev);
mutex_unlock(&dev->list_mutex);
memset(&msg, 0, sizeof(msg)); memset(&msg, 0, sizeof(msg));
msg.id.mst.id = dev->id; msg.id.mst.id = dev->id;
......
Markdown is supported
0%
or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment