diff options
author | Ursula Braun <ursula.braun@de.ibm.com> | 2014-05-13 14:38:02 +0200 |
---|---|---|
committer | David S. Miller <davem@davemloft.net> | 2014-05-14 15:38:39 -0400 |
commit | f5738e2ef88070ef1372e6e718124d88e9abe4ac (patch) | |
tree | be10857725cb3d1dbaca1a8c6c0f2d94e4bb190b /net/iucv/af_iucv.c | |
parent | 03a58baa785f48a85126ab043a14cb80b7e670e0 (diff) | |
download | lwn-f5738e2ef88070ef1372e6e718124d88e9abe4ac.tar.gz lwn-f5738e2ef88070ef1372e6e718124d88e9abe4ac.zip |
af_iucv: wrong mapping of sent and confirmed skbs
When sending data through IUCV a MESSAGE COMPLETE interrupt
signals that sent data memory can be freed or reused again.
With commit f9c41a62bba3f3f7ef3541b2a025e3371bcbba97
"af_iucv: fix recvmsg by replacing skb_pull() function" the
MESSAGE COMPLETE callback iucv_callback_txdone() identifies
the wrong skb as being confirmed, which leads to data corruption.
This patch fixes the skb mapping logic in iucv_callback_txdone().
Signed-off-by: Ursula Braun <ursula.braun@de.ibm.com>
Signed-off-by: Frank Blaschka <frank.blaschka@de.ibm.com>
Cc: <stable@vger.kernel.org>
Signed-off-by: David S. Miller <davem@davemloft.net>
Diffstat (limited to 'net/iucv/af_iucv.c')
-rw-r--r-- | net/iucv/af_iucv.c | 2 |
1 files changed, 1 insertions, 1 deletions
diff --git a/net/iucv/af_iucv.c b/net/iucv/af_iucv.c index 01e77b0ae075..8c9d7302c846 100644 --- a/net/iucv/af_iucv.c +++ b/net/iucv/af_iucv.c @@ -1830,7 +1830,7 @@ static void iucv_callback_txdone(struct iucv_path *path, spin_lock_irqsave(&list->lock, flags); while (list_skb != (struct sk_buff *)list) { - if (msg->tag != IUCV_SKB_CB(list_skb)->tag) { + if (msg->tag == IUCV_SKB_CB(list_skb)->tag) { this = list_skb; break; } |