All of lore.kernel.org
 help / color / mirror / Atom feed
* [PATCH] drivers/md: raid10: Fix null pointer dereference in fix_read_error()
@ 2010-06-21 22:14 prasanna.panchamukhi
  2010-06-21 22:55 ` Neil Brown
  0 siblings, 1 reply; 5+ messages in thread
From: prasanna.panchamukhi @ 2010-06-21 22:14 UTC (permalink / raw)
  To: linux-raid; +Cc: prasanna.panchamukhi, rbecker

From: Prasanna S. Panchamukhi <prasanna.panchamukhi@riverbed.com>

Such NULL pointer dereference can occur when the driver was fixing the
read errors/bad blocks and the disk was physically removed
causing a system crash. This patch check if the
rcu_dereference() returns valid rdev before accessing it in fix_read_error().

Signed-off-by: Prasanna S. Panchamukhi <prasanna.panchamukhi@riverbed.com>
Signed-off-by: Rob Becker <rbecker@riverbed.com>
---
 drivers/md/raid10.c |   51 +++++++++++++++++++++++++++------------------------
 1 files changed, 27 insertions(+), 24 deletions(-)

diff --git a/drivers/md/raid10.c b/drivers/md/raid10.c
index 0372499..9556faa 100644
--- a/drivers/md/raid10.c
+++ b/drivers/md/raid10.c
@@ -1490,31 +1490,34 @@ static void fix_read_error(conf_t *conf, mddev_t *mddev, r10bio_t *r10_bio)
 		int cur_read_error_count = 0;
 
 		rdev = rcu_dereference(conf->mirrors[d].rdev);
-		bdevname(rdev->bdev, b);
+		if (rdev) { /* Check if the mirror raid device is not NULL*/
+			bdevname(rdev->bdev, b);
 
-		if (test_bit(Faulty, &rdev->flags)) {
-			rcu_read_unlock();
-			/* drive has already been failed, just ignore any
-			   more fix_read_error() attempts */
-			return;
-		}
+			if (test_bit(Faulty, &rdev->flags)) {
+				rcu_read_unlock();
+				/* drive has already been failed, just ignore
+				   any more fix_read_error() attempts */
+				return;
+			}
 
-		check_decay_read_errors(mddev, rdev);
-		atomic_inc(&rdev->read_errors);
-		cur_read_error_count = atomic_read(&rdev->read_errors);
-		if (cur_read_error_count > max_read_errors) {
-			rcu_read_unlock();
-			printk(KERN_NOTICE
-			       "md/raid10:%s: %s: Raid device exceeded "
-			       "read_error threshold "
-			       "[cur %d:max %d]\n",
-			       mdname(mddev),
-			       b, cur_read_error_count, max_read_errors);
-			printk(KERN_NOTICE
-			       "md/raid10:%s: %s: Failing raid "
-			       "device\n", mdname(mddev), b);
-			md_error(mddev, conf->mirrors[d].rdev);
-			return;
+			check_decay_read_errors(mddev, rdev);
+			atomic_inc(&rdev->read_errors);
+			cur_read_error_count = atomic_read(&rdev->read_errors);
+			if (cur_read_error_count > max_read_errors) {
+				rcu_read_unlock();
+				printk(KERN_NOTICE
+				       "md/raid10:%s: %s: Raid device exceeded "
+				       "read_error threshold "
+				       "[cur %d:max %d]\n",
+				       mdname(mddev),
+				       b, cur_read_error_count,
+				       max_read_errors);
+				printk(KERN_NOTICE
+				       "md/raid10:%s: %s: Failing raid "
+				       "device\n", mdname(mddev), b);
+				md_error(mddev, conf->mirrors[d].rdev);
+				return;
+			}
 		}
 	}
 	rcu_read_unlock();
-- 
1.7.0.4


^ permalink raw reply related	[flat|nested] 5+ messages in thread

end of thread, other threads:[~2010-06-24  0:16 UTC | newest]

Thread overview: 5+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2010-06-21 22:14 [PATCH] drivers/md: raid10: Fix null pointer dereference in fix_read_error() prasanna.panchamukhi
2010-06-21 22:55 ` Neil Brown
2010-06-21 23:10   ` Prasanna Panchamukhi
2010-06-23  2:40   ` Prasanna S. Panchamukhi
2010-06-24  0:16     ` Neil Brown

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.