aio: hold an extra file reference over AIO read/write operations
Otherwise we might dereference an already freed file and/or inode when aio_complete is called before we return from the read_iter or write_iter method. Signed-off-by: Christoph Hellwig <hch@lst.de> Signed-off-by: Al Viro <viro@zeniv.linux.org.uk>
This commit is contained in:
parent
a909d3e636
commit
0b944d3a4b
2
fs/aio.c
2
fs/aio.c
|
@ -1460,6 +1460,7 @@ static ssize_t aio_run_iocb(struct kiocb *req, unsigned opcode,
|
|||
return ret;
|
||||
}
|
||||
|
||||
get_file(file);
|
||||
if (rw == WRITE)
|
||||
file_start_write(file);
|
||||
|
||||
|
@ -1467,6 +1468,7 @@ static ssize_t aio_run_iocb(struct kiocb *req, unsigned opcode,
|
|||
|
||||
if (rw == WRITE)
|
||||
file_end_write(file);
|
||||
fput(file);
|
||||
kfree(iovec);
|
||||
break;
|
||||
|
||||
|
|
Loading…
Reference in New Issue