* [Drbd-dev] connector: Bugfix for cn_call_callback()
@ 2007-03-07 11:26 Philipp Reisner
2007-03-07 11:59 ` [Drbd-dev] " Evgeniy Polyakov
0 siblings, 1 reply; 2+ messages in thread
From: Philipp Reisner @ 2007-03-07 11:26 UTC (permalink / raw)
To: Evgeniy Polyakov, linux-kernel; +Cc: drbd-dev
Hi Evgeniy,
When one stresses the connector code, with sending many messages
from userspace to kernel, one could get in the "unlikely()"
part in cn_call_callback().
There a new __cbq gets allocated, and a NULL pointer got assigned
to the callback by dereferencing __cbq. This is the bug. The right
thing is the dereference the original __cbq. Therefore the bugfix
is to use a new variable for the newly allocated __cbq.
This is tested, and it fixes the issue.
Signed-off-by: Philipp Reisner <philipp.reisner@linbit.com>
Signed-off-by: Lars Ellenberg <lars.ellenberg@linbit.com>
--- /usr/src/linux-2.6.20/drivers/connector/connector.c 2007-03-07 11:45:38.000000000 +0100
+++ /usr/src/linux-2.6.20-modified/drivers/connector/connector.c 2007-03-07 11:39:11.000000000 +0100
@@ -128,7 +128,7 @@
*/
static int cn_call_callback(struct cn_msg *msg, void (*destruct_data)(void *), void *data)
{
- struct cn_callback_entry *__cbq;
+ struct cn_callback_entry *__cbq, *__new_cbq;
struct cn_dev *dev = &cdev;
int err = -ENODEV;
@@ -148,23 +148,23 @@
} else {
struct cn_callback_data *d;
- __cbq = kzalloc(sizeof(*__cbq), GFP_ATOMIC);
- if (__cbq) {
- d = &__cbq->data;
+ __new_cbq = kzalloc(sizeof(*__new_cbq), GFP_ATOMIC);
+ if (__new_cbq) {
+ d = &__new_cbq->data;
d->callback_priv = msg;
d->callback = __cbq->data.callback;
d->ddata = data;
d->destruct_data = destruct_data;
- d->free = __cbq;
+ d->free = __new_cbq;
- INIT_WORK(&__cbq->work,
- &cn_queue_wrapper);
+ INIT_WORK(&__new_cbq->work,
+ &cn_queue_wrapper);
if (queue_work(dev->cbdev->cn_queue,
- &__cbq->work))
+ &__new_cbq->work))
err = 0;
else {
- kfree(__cbq);
+ kfree(__new_cbq);
err = -EINVAL;
}
} else
--
: Dipl-Ing Philipp Reisner Tel +43-1-8178292-50 :
: LINBIT Information Technologies GmbH Fax +43-1-8178292-82 :
: Vivenotgasse 48, 1120 Vienna, Austria http://www.linbit.com :
^ permalink raw reply [flat|nested] 2+ messages in thread* [Drbd-dev] Re: connector: Bugfix for cn_call_callback()
2007-03-07 11:26 [Drbd-dev] connector: Bugfix for cn_call_callback() Philipp Reisner
@ 2007-03-07 11:59 ` Evgeniy Polyakov
0 siblings, 0 replies; 2+ messages in thread
From: Evgeniy Polyakov @ 2007-03-07 11:59 UTC (permalink / raw)
To: Philipp Reisner; +Cc: linux-kernel, drbd-dev
On Wed, Mar 07, 2007 at 12:26:12PM +0100, Philipp Reisner (philipp.reisner@linbit.com) wrote:
> Hi Evgeniy,
Hi Philipp.
> When one stresses the connector code, with sending many messages
> from userspace to kernel, one could get in the "unlikely()"
> part in cn_call_callback().
>
> There a new __cbq gets allocated, and a NULL pointer got assigned
> to the callback by dereferencing __cbq. This is the bug. The right
> thing is the dereference the original __cbq. Therefore the bugfix
> is to use a new variable for the newly allocated __cbq.
>
> This is tested, and it fixes the issue.
Yes, your patch is correct.
> Signed-off-by: Philipp Reisner <philipp.reisner@linbit.com>
> Signed-off-by: Lars Ellenberg <lars.ellenberg@linbit.com>
I will push it, thanks a lot.
--
Evgeniy Polyakov
^ permalink raw reply [flat|nested] 2+ messages in thread
end of thread, other threads:[~2007-03-07 12:33 UTC | newest]
Thread overview: 2+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2007-03-07 11:26 [Drbd-dev] connector: Bugfix for cn_call_callback() Philipp Reisner
2007-03-07 11:59 ` [Drbd-dev] " Evgeniy Polyakov
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox