mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* [PATCH] firewire: core: fix crash in iso resource management
       [not found]       ` <1252116551.3383.26.camel@localhost.localdomain>
@ 2009-09-05 11:23         ` Stefan Richter
  0 siblings, 0 replies; only message in thread
From: Stefan Richter @ 2009-09-05 11:23 UTC (permalink / raw)
  To: linux1394-devel; +Cc: Jonathan Cameron, David Moore, linux-kernel

This fixes a regression due to post 2.6.30 commit "firewire: core: do
not DMA-map stack addresses" 6fdc03709433ccc2005f0f593ae9d9dd04f7b485.

As David Moore noted, a previously correct sizeof() expression became
wrong since the commit changed its argument from an array to a pointer.
This resulted in an oops in ohci_cancel_packet in the shared workqueue
thread's context when an isochronous resource was to be freed.

Reported-by: Jonathan Cameron <jic23@cam.ac.uk>
Signed-off-by: Stefan Richter <stefanr@s5r6.in-berlin.de>
---
 drivers/firewire/core-card.c |    2 ++
 drivers/firewire/core-iso.c  |    4 ++--
 2 files changed, 4 insertions(+), 2 deletions(-)

Index: linux-2.6.31-rc7/drivers/firewire/core-iso.c
===================================================================
--- linux-2.6.31-rc7.orig/drivers/firewire/core-iso.c
+++ linux-2.6.31-rc7/drivers/firewire/core-iso.c
@@ -196,7 +196,7 @@ static int manage_bandwidth(struct fw_ca
 		switch (fw_run_transaction(card, TCODE_LOCK_COMPARE_SWAP,
 				irm_id, generation, SCODE_100,
 				CSR_REGISTER_BASE + CSR_BANDWIDTH_AVAILABLE,
-				data, sizeof(data))) {
+				data, 8)) {
 		case RCODE_GENERATION:
 			/* A generation change frees all bandwidth. */
 			return allocate ? -EAGAIN : bandwidth;
@@ -233,7 +233,7 @@ static int manage_channel(struct fw_card
 		data[1] = old ^ c;
 		switch (fw_run_transaction(card, TCODE_LOCK_COMPARE_SWAP,
 					   irm_id, generation, SCODE_100,
-					   offset, data, sizeof(data))) {
+					   offset, data, 8)) {
 		case RCODE_GENERATION:
 			/* A generation change frees all channels. */
 			return allocate ? -EAGAIN : i;

-- 
Stefan Richter
-=====-==--= =--= --=-=
http://arcgraph.de/sr/


^ permalink raw reply	[flat|nested] only message in thread

only message in thread, other threads:[~2009-09-05 11:24 UTC | newest]

Thread overview: (only message) (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
     [not found] <4AA119A5.9000105@cam.ac.uk>
     [not found] ` <tkrat.c6382d44c1c0be7c@s5r6.in-berlin.de>
     [not found]   ` <4AA144D1.7030109@cam.ac.uk>
     [not found]     ` <tkrat.c508979b9af656c0@s5r6.in-berlin.de>
     [not found]       ` <1252116551.3383.26.camel@localhost.localdomain>
2009-09-05 11:23         ` [PATCH] firewire: core: fix crash in iso resource management Stefan Richter

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®