net/smc: prevent races between smc_lgr_terminate() and smc_conn_free()
authorKarsten Graul <kgraul@linux.ibm.com>
Wed, 30 Jan 2019 17:51:02 +0000 (18:51 +0100)
committerGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Thu, 5 Dec 2019 08:21:08 +0000 (09:21 +0100)
commitf8e7423f5e182d60a0350c455195af5ff63f67cb
tree6667672c8983b0c06f91c5858321c5dd227d33dd
parentdcb901cebe0f1e97fb6d5fc9adafe65515785e6f
net/smc: prevent races between smc_lgr_terminate() and smc_conn_free()

[ Upstream commit 77f838ace755d2f466536c44dac6c856f62cd901 ]

To prevent races between smc_lgr_terminate() and smc_conn_free() add an
extra check of the lgr field before accessing it, and cancel a delayed
free_work when a new smc connection is created.
This fixes the problem that free_work cleared the lgr variable but
smc_lgr_terminate() or smc_conn_free() still access it in parallel.

Signed-off-by: Karsten Graul <kgraul@linux.ibm.com>
Signed-off-by: Ursula Braun <ubraun@linux.ibm.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Sasha Levin <sashal@kernel.org>
net/smc/smc_core.c