mirror of
https://github.com/torvalds/linux.git
synced 2026-10-08 19:46:02 +02:00
tipc: Fix a data race on mon->peer_cnt in mon_timeout()
mon_timeout() evaluates dom_size(mon->peer_cnt) before it takes mon->lock,
while mon->peer_cnt is updated under that lock by tipc_mon_add_peer() and
tipc_mon_remove_peer(). The value can therefore be stale, and the decision
whether the local domain has to be recomputed can be based on an outdated
member count.
Read mon->peer_cnt inside the write_lock_bh(&mon->lock) protected region.
Fixes: 35c55c9877 ("tipc: add neighbor monitoring framework")
Signed-off-by: Ginger Li <ginger.jzllee@gmail.com>
Reviewed-by: Tung Nguyen <tung.quang.nguyen@est.tech>
Link: https://patch.msgid.link/20260922080909.21123-1-ginger.jzllee@gmail.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
This commit is contained in:
parent
b94773dc4d
commit
8e1937fed6
|
|
@ -632,9 +632,10 @@ static void mon_timeout(struct timer_list *t)
|
|||
{
|
||||
struct tipc_monitor *mon = timer_container_of(mon, t, timer);
|
||||
struct tipc_peer *self;
|
||||
int best_member_cnt = dom_size(mon->peer_cnt) - 1;
|
||||
int best_member_cnt;
|
||||
|
||||
write_lock_bh(&mon->lock);
|
||||
best_member_cnt = dom_size(mon->peer_cnt) - 1;
|
||||
self = mon->self;
|
||||
if (self && (best_member_cnt != self->applied)) {
|
||||
mon_update_local_domain(mon);
|
||||
|
|
|
|||
Loading…
Reference in New Issue
Block a user