* [PATCH] net: ifb error path loop fix
@ 2007-01-01 23:55 Mariusz Kozlowski
2007-01-02 7:51 ` David Miller
0 siblings, 1 reply; 5+ messages in thread
From: Mariusz Kozlowski @ 2007-01-01 23:55 UTC (permalink / raw)
To: hadi; +Cc: netdev, jeff, linux-kernel
Hello,
On error we should start freeing resources at [i-1] not [i-2].
Signed-off-by: Mariusz Kozlowski <m.kozlowski@tuxland.pl>
drivers/net/ifb.c | 3 +--
1 file changed, 1 insertion(+), 2 deletions(-)
diff -upr linux-2.6.20-rc2-mm1-a/drivers/net/ifb.c linux-2.6.20-rc2-mm1-b/drivers/net/ifb.c
--- linux-2.6.20-rc2-mm1-a/drivers/net/ifb.c 2006-12-24 05:00:32.000000000 +0100
+++ linux-2.6.20-rc2-mm1-b/drivers/net/ifb.c 2007-01-02 00:25:34.000000000 +0100
@@ -271,8 +271,7 @@ static int __init ifb_init_module(void)
for (i = 0; i < numifbs && !err; i++)
err = ifb_init_one(i);
if (err) {
- i--;
- while (--i >= 0)
+ while (i--)
ifb_free_one(i);
}
--
Regards,
Mariusz Kozlowski
^ permalink raw reply [flat|nested] 5+ messages in thread* Re: [PATCH] net: ifb error path loop fix
2007-01-01 23:55 [PATCH] net: ifb error path loop fix Mariusz Kozlowski
@ 2007-01-02 7:51 ` David Miller
2007-01-02 10:30 ` Jarek Poplawski
2007-01-02 10:49 ` Mariusz Kozlowski
0 siblings, 2 replies; 5+ messages in thread
From: David Miller @ 2007-01-02 7:51 UTC (permalink / raw)
To: m.kozlowski; +Cc: hadi, netdev, jeff, linux-kernel
From: Mariusz Kozlowski <m.kozlowski@tuxland.pl>
Date: Tue, 2 Jan 2007 00:55:51 +0100
> On error we should start freeing resources at [i-1] not [i-2].
>
> Signed-off-by: Mariusz Kozlowski <m.kozlowski@tuxland.pl>
Patch applied, thanks Mariusz.
> diff -upr linux-2.6.20-rc2-mm1-a/drivers/net/ifb.c linux-2.6.20-rc2-mm1-b/drivers/net/ifb.c
> --- linux-2.6.20-rc2-mm1-a/drivers/net/ifb.c 2006-12-24 05:00:32.000000000 +0100
> +++ linux-2.6.20-rc2-mm1-b/drivers/net/ifb.c 2007-01-02 00:25:34.000000000 +0100
> @@ -271,8 +271,7 @@ static int __init ifb_init_module(void)
> for (i = 0; i < numifbs && !err; i++)
> err = ifb_init_one(i);
> if (err) {
> - i--;
> - while (--i >= 0)
> + while (i--)
> ifb_free_one(i);
> }
One could argue from a defensive programming perspective that
this bug comes from the fact that the ifb_init_one() loop
advances state before checking for errors ('i' is advanced before
the 'err' check due to the loop construct), and that's why the
error recovery code had to be coded specially :-)
Anyways, your fix is of course fine and I've applied it.
^ permalink raw reply [flat|nested] 5+ messages in thread* Re: [PATCH] net: ifb error path loop fix
2007-01-02 7:51 ` David Miller
@ 2007-01-02 10:30 ` Jarek Poplawski
2007-01-02 10:49 ` Mariusz Kozlowski
1 sibling, 0 replies; 5+ messages in thread
From: Jarek Poplawski @ 2007-01-02 10:30 UTC (permalink / raw)
To: David Miller; +Cc: hadi, netdev, jeff, linux-kernel
On 02-01-2007 08:51, David Miller wrote:
> From: Mariusz Kozlowski <m.kozlowski@tuxland.pl>
> Date: Tue, 2 Jan 2007 00:55:51 +0100
>
>> On error we should start freeing resources at [i-1] not [i-2].
>>
>> Signed-off-by: Mariusz Kozlowski <m.kozlowski@tuxland.pl>
>
> Patch applied, thanks Mariusz.
>
>> diff -upr linux-2.6.20-rc2-mm1-a/drivers/net/ifb.c linux-2.6.20-rc2-mm1-b/drivers/net/ifb.c
>> --- linux-2.6.20-rc2-mm1-a/drivers/net/ifb.c 2006-12-24 05:00:32.000000000 +0100
>> +++ linux-2.6.20-rc2-mm1-b/drivers/net/ifb.c 2007-01-02 00:25:34.000000000 +0100
>> @@ -271,8 +271,7 @@ static int __init ifb_init_module(void)
>> for (i = 0; i < numifbs && !err; i++)
>> err = ifb_init_one(i);
>> if (err) {
>> - i--;
>> - while (--i >= 0)
>> + while (i--)
>> ifb_free_one(i);
>> }
After this patch:
for (i = 0 ...); // i == 0
err = ifb_init_one(i); // err != 0
i++; // i == 1
for (... !err ...); // break
if (err) {
while (i--) // i == 1 (when testing)
ifb_free_one(i); // i == 0 (not initialized)
}
Btw. wasn't this place patched yet?
Regards,
Jarek P.
^ permalink raw reply [flat|nested] 5+ messages in thread* Re: [PATCH] net: ifb error path loop fix
2007-01-02 7:51 ` David Miller
2007-01-02 10:30 ` Jarek Poplawski
@ 2007-01-02 10:49 ` Mariusz Kozlowski
2007-01-02 23:20 ` David Miller
1 sibling, 1 reply; 5+ messages in thread
From: Mariusz Kozlowski @ 2007-01-02 10:49 UTC (permalink / raw)
To: David Miller; +Cc: hadi, netdev, jeff, linux-kernel
Hello David,
> One could argue from a defensive programming perspective that
> this bug comes from the fact that the ifb_init_one() loop
> advances state before checking for errors ('i' is advanced before
> the 'err' check due to the loop construct), and that's why the
> error recovery code had to be coded specially :-)
Now when I look at it I might be wrong and it is not a bug at all.
It's just coded in weird way. Anyway isn't there kfree(ifbs) missing
on error path?
The patch below should clear things a bit (against plain 2.6.20-rc2-mm1).
Signed-off-by: Mariusz Kozlowski <m.kozlowski@tuxland.pl>
drivers/net/ifb.c | 16 ++++++++++------
1 file changed, 10 insertions(+), 6 deletions(-)
--- linux-2.6.20-rc2-mm1-a/drivers/net/ifb.c 2006-12-24 05:00:32.000000000 +0100
+++ linux-2.6.20-rc2-mm1-b/drivers/net/ifb.c 2007-01-02 11:35:48.000000000 +0100
@@ -264,18 +264,22 @@ static void ifb_free_one(int index)
static int __init ifb_init_module(void)
{
- int i, err = 0;
+ int i, err;
+
ifbs = kmalloc(numifbs * sizeof(void *), GFP_KERNEL);
if (!ifbs)
return -ENOMEM;
- for (i = 0; i < numifbs && !err; i++)
+ for (i = 0; i < numifbs; i++) {
err = ifb_init_one(i);
- if (err) {
- i--;
- while (--i >= 0)
- ifb_free_one(i);
+ if (err)
+ goto err;
}
+ return 0;
+err:
+ while (i--)
+ ifb_free_one(i);
+ kfree(ifbs);
return err;
}
--
Regards,
Mariusz Kozlowski
^ permalink raw reply [flat|nested] 5+ messages in thread* Re: [PATCH] net: ifb error path loop fix
2007-01-02 10:49 ` Mariusz Kozlowski
@ 2007-01-02 23:20 ` David Miller
0 siblings, 0 replies; 5+ messages in thread
From: David Miller @ 2007-01-02 23:20 UTC (permalink / raw)
To: m.kozlowski; +Cc: hadi, netdev, jeff, linux-kernel
From: Mariusz Kozlowski <m.kozlowski@tuxland.pl>
Date: Tue, 2 Jan 2007 11:49:42 +0100
> Hello David,
>
> > One could argue from a defensive programming perspective that
> > this bug comes from the fact that the ifb_init_one() loop
> > advances state before checking for errors ('i' is advanced before
> > the 'err' check due to the loop construct), and that's why the
> > error recovery code had to be coded specially :-)
>
> Now when I look at it I might be wrong and it is not a bug at all.
> It's just coded in weird way. Anyway isn't there kfree(ifbs) missing
> on error path?
>
> The patch below should clear things a bit (against plain 2.6.20-rc2-mm1).
>
> Signed-off-by: Mariusz Kozlowski <m.kozlowski@tuxland.pl>
Ok, I've removed the original patch from my tree.
I'll let this cleanup sit for a while so others can review
it :-)
^ permalink raw reply [flat|nested] 5+ messages in thread
end of thread, other threads:[~2007-01-02 23:20 UTC | newest]
Thread overview: 5+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2007-01-01 23:55 [PATCH] net: ifb error path loop fix Mariusz Kozlowski
2007-01-02 7:51 ` David Miller
2007-01-02 10:30 ` Jarek Poplawski
2007-01-02 10:49 ` Mariusz Kozlowski
2007-01-02 23:20 ` David Miller
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).