Commit e413a823f60b582af471f0079eb99f50d34b0da7

Authored by Steve Wise
Committed by Roland Dreier
1 parent cc529c0d72

RDMA/iwcm: Don't touch cmid after dropping reference

The function cm_work_handler() cannot touch the cm_id after it derefs
it, because it might be freed on another concurrent thread.  If there
are more work items queued for this cm_id, then we know there must be
more references because they are added when the work items are queued.
So in the while loop inside cm_work_handler(), after derefing, if the
queue is empty, then exit the function.  Otherwise we know it's safe
to re-acquire the lock.

Signed-off-by: Steve Wise <swise@opengridcomputing.com>
Signed-off-by: Roland Dreier <roland@purestorage.com>

Showing 1 changed file with 2 additions and 0 deletions Side-by-side Diff

drivers/infiniband/core/iwcm.c
... ... @@ -878,6 +878,8 @@
878 878 }
879 879 return;
880 880 }
  881 + if (empty)
  882 + return;
881 883 spin_lock_irqsave(&cm_id_priv->lock, flags);
882 884 }
883 885 spin_unlock_irqrestore(&cm_id_priv->lock, flags);