All of lore.kernel.org
 help / color / mirror / Atom feed
* re: btrfs: fix race in reada
@ 2012-04-30 11:11 Dan Carpenter
  2012-04-30 11:23 ` Arne Jansen
  0 siblings, 1 reply; 4+ messages in thread
From: Dan Carpenter @ 2012-04-30 11:11 UTC (permalink / raw)
  To: sensille; +Cc: linux-btrfs

Hello Arne Jansen,

The patch 8c9c2bf7a3c4: "btrfs: fix race in reada" from Feb 25, 2012, 
leads to the following warning:
fs/btrfs/reada.c:308 reada_find_zone()
	 warn: 'zone' was already freed.

@@ -307,13 +302,15 @@ again:
        ret = radix_tree_insert(&dev->reada_zones,
                                (unsigned long)(zone->end >> PAGE_CACHE_SHIFT),
                                zone);
-       spin_unlock(&fs_info->reada_lock);
 
-       if (ret) {
+       if (ret == -EEXIST) {
                kfree(zone);
                ^^^^^^^^^^^
Freed here.

-               looped = 1;
-               goto again;
+               ret = radix_tree_gang_lookup(&dev->reada_zones, (void **)&zone,
                                                                          ^^^^
Use after free inside radix_tree_gang_lookup() function.

+                                            logical >> PAGE_CACHE_SHIFT, 1);
+               if (ret == 1)
+                       kref_get(&zone->refcnt);
        }
+       spin_unlock(&fs_info->reada_lock);
 
        return zone;
 }

regards,
dan carpenter


^ permalink raw reply	[flat|nested] 4+ messages in thread

end of thread, other threads:[~2012-04-30 12:41 UTC | newest]

Thread overview: 4+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2012-04-30 11:11 btrfs: fix race in reada Dan Carpenter
2012-04-30 11:23 ` Arne Jansen
2012-04-30 12:36   ` Dan Carpenter
2012-04-30 12:41   ` Dan Carpenter

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.