futex: remove the pointer math from double_unlock_hb, fix
Ingo Molnar [Fri, 13 Mar 2009 09:32:07 +0000 (10:32 +0100)]
Impact: fix double unlock crash

Thomas Gleixner noticed that the simplified double_unlock_hb()
became ... too unsophisticated: in the hb1 == hb2 case it will
do a double unlock.

Reported-by: Thomas Gleixner <tglx@linutronix.de>
Cc: Darren Hart <dvhltc@us.ibm.com>
LKML-Reference: <20090312221118.11146.68610.stgit@Aeon>
Signed-off-by: Ingo Molnar <mingo@elte.hu>

kernel/futex.c

index 2331b73..6b50a02 100644 (file)
@@ -659,7 +659,8 @@ static inline void
 double_unlock_hb(struct futex_hash_bucket *hb1, struct futex_hash_bucket *hb2)
 {
        spin_unlock(&hb1->lock);
-       spin_unlock(&hb2->lock);
+       if (hb1 != hb2)
+               spin_unlock(&hb2->lock);
 }
 
 /*