• Jeff Mahoney's avatar
    reiserfs: fix race in prealloc discard · 08db141b
    Jeff Mahoney authored
    The main loop in __discard_prealloc is protected by the reiserfs write lock
    which is dropped across schedules like the BKL it replaced.  The problem is
    that it checks the value, calls a routine that schedules, and then adjusts
    the state.  As a result, two threads that are calling
    reiserfs_prealloc_discard at the same time can race when one calls
    reiserfs_free_prealloc_block, the lock is dropped, and the other calls
    reiserfs_free_prealloc_block with the same block number.  In the right
    circumstances, it can cause the prealloc count to go negative.
    Signed-off-by: 's avatarJeff Mahoney <jeffm@suse.com>
    Signed-off-by: 's avatarJan Kara <jack@suse.cz>
bitmap.c 39.6 KB