MEDIA: lirc, improper locking

From: Jiri Slaby
Date: Wed Jul 07 2010 - 08:53:19 EST


Hi,

stanse found a locking error in lirc_dev_fop_read:
if (mutex_lock_interruptible(&ir->irctl_lock))
return -ERESTARTSYS;
...
while (written < length && ret == 0) {
if (mutex_lock_interruptible(&ir->irctl_lock)) { #1
ret = -ERESTARTSYS;
break;
}
...
}

remove_wait_queue(&ir->buf->wait_poll, &wait);
set_current_state(TASK_RUNNING);
mutex_unlock(&ir->irctl_lock); #2

If lock at #1 fails, it beaks out of the loop, with the lock unlocked,
but there is another "unlock" at #2.

regards,
--
js
--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at http://vger.kernel.org/majordomo-info.html
Please read the FAQ at http://www.tux.org/lkml/