[PATCH] spufs: fix locking in spu_acquire_runnable

We need to check for validity of owner under down_write,
down_read is not enough.

Noticed by Al Viro.

Signed-off-by: Arnd Bergmann <arndb@de.ibm.com>
Signed-off-by: Paul Mackerras <paulus@samba.org>
This commit is contained in:
Arnd Bergmann 2006-01-04 20:31:21 +01:00 committed by Paul Mackerras
parent c902be71dc
commit 762cf6dac2
1 changed files with 6 additions and 4 deletions

View File

@ -120,27 +120,29 @@ int spu_acquire_runnable(struct spu_context *ctx)
ctx->spu->prio = current->prio; ctx->spu->prio = current->prio;
return 0; return 0;
} }
up_read(&ctx->state_sema);
down_write(&ctx->state_sema);
/* ctx is about to be freed, can't acquire any more */ /* ctx is about to be freed, can't acquire any more */
if (!ctx->owner) { if (!ctx->owner) {
ret = -EINVAL; ret = -EINVAL;
goto out; goto out;
} }
up_read(&ctx->state_sema);
down_write(&ctx->state_sema);
if (ctx->state == SPU_STATE_SAVED) { if (ctx->state == SPU_STATE_SAVED) {
ret = spu_activate(ctx, 0); ret = spu_activate(ctx, 0);
ctx->state = SPU_STATE_RUNNABLE; ctx->state = SPU_STATE_RUNNABLE;
} }
downgrade_write(&ctx->state_sema);
if (ret) if (ret)
goto out; goto out;
downgrade_write(&ctx->state_sema);
/* On success, we return holding the lock */ /* On success, we return holding the lock */
return ret; return ret;
out: out:
/* Release here, to simplify calling code. */ /* Release here, to simplify calling code. */
up_read(&ctx->state_sema); up_write(&ctx->state_sema);
return ret; return ret;
} }