b43legacy: fix debugfs crash
authorChristian Lamparter <chunkeey@googlemail.com>
Sat, 17 Sep 2016 19:43:04 +0000 (21:43 +0200)
committerGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Wed, 21 Sep 2016 10:13:34 +0000 (12:13 +0200)
This patch fixes a crash that happens because b43legacy's
debugfs code expects file->f_op to be a pointer to its own
b43legacy_debugfs_fops struct. This is no longer the case
since commit 9fd4dcece43a
("debugfs: prevent access to possibly dead file_operations at file open")

Reviewed-by: Nicolai Stange <nicstange@gmail.com>
Signed-off-by: Christian Lamparter <chunkeey@gmail.com>
Cc: stable <stable@vger.kernel.org> # 4.7+
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
drivers/net/wireless/broadcom/b43legacy/debugfs.c

index 090910e..82ef56e 100644 (file)
@@ -221,7 +221,8 @@ static ssize_t b43legacy_debugfs_read(struct file *file, char __user *userbuf,
                goto out_unlock;
        }
 
-       dfops = container_of(file->f_op, struct b43legacy_debugfs_fops, fops);
+       dfops = container_of(debugfs_real_fops(file),
+                            struct b43legacy_debugfs_fops, fops);
        if (!dfops->read) {
                err = -ENOSYS;
                goto out_unlock;
@@ -287,7 +288,8 @@ static ssize_t b43legacy_debugfs_write(struct file *file,
                goto out_unlock;
        }
 
-       dfops = container_of(file->f_op, struct b43legacy_debugfs_fops, fops);
+       dfops = container_of(debugfs_real_fops(file),
+                            struct b43legacy_debugfs_fops, fops);
        if (!dfops->write) {
                err = -ENOSYS;
                goto out_unlock;