From patchwork Wed May 30 17:43:40 2018 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Ilya Dryomov X-Patchwork-Id: 10439483 Return-Path: Received: from mail.wl.linuxfoundation.org (pdx-wl-mail.web.codeaurora.org [172.30.200.125]) by pdx-korg-patchwork.web.codeaurora.org (Postfix) with ESMTP id 7528560327 for ; Wed, 30 May 2018 17:44:08 +0000 (UTC) Received: from mail.wl.linuxfoundation.org (localhost [127.0.0.1]) by mail.wl.linuxfoundation.org (Postfix) with ESMTP id 62914289F1 for ; Wed, 30 May 2018 17:44:08 +0000 (UTC) Received: by mail.wl.linuxfoundation.org (Postfix, from userid 486) id 557D628A4A; Wed, 30 May 2018 17:44:08 +0000 (UTC) X-Spam-Checker-Version: SpamAssassin 3.3.1 (2010-03-16) on pdx-wl-mail.web.codeaurora.org X-Spam-Level: X-Spam-Status: No, score=-7.8 required=2.0 tests=BAYES_00, DKIM_ADSP_CUSTOM_MED, DKIM_SIGNED, FREEMAIL_FROM, MAILING_LIST_MULTI, RCVD_IN_DNSWL_HI, T_DKIM_INVALID autolearn=ham version=3.3.1 Received: from vger.kernel.org (vger.kernel.org [209.132.180.67]) by mail.wl.linuxfoundation.org (Postfix) with ESMTP id 09224289F1 for ; Wed, 30 May 2018 17:44:08 +0000 (UTC) Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S932163AbeE3RoF (ORCPT ); Wed, 30 May 2018 13:44:05 -0400 Received: from mail-wm0-f66.google.com ([74.125.82.66]:34520 "EHLO mail-wm0-f66.google.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S932148AbeE3Rn4 (ORCPT ); Wed, 30 May 2018 13:43:56 -0400 Received: by mail-wm0-f66.google.com with SMTP id q4-v6so2565025wmq.1 for ; Wed, 30 May 2018 10:43:56 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=from:to:cc:subject:date:message-id:in-reply-to:references; bh=F8jYbSFnsruIiKnNDLuveaMOg3G+qtZvBPhffwvhcbc=; b=AIEjeyZidFO6cX1g2ZmScaCwH0PqHQatPOpSolhDisaKQKLrjq4ZLqZ0TQDfiPy6Pq iNkN0/qkMi1XArRzlvlpPNePHE7aV+LTgx4/jck4rIaw3sXk9swyx63Jf3mWbfVjagy8 tBOJBrT30I/8YixJHlFpMYwwyUr6QBSkTQ2IU+H8UM0FRS3IkVG0VQl8Qex6bddlM7rF JPXn+cckcp1yeeFSFUs//qNAcgM/2lsCf9FsSidXyEGT12lxfT2Zf1NyxDf+bUICyDR7 sT66E0mOVuzT+aX90v12HkP6hTmU5PUke/Gr/mmoIn8HoIeADbPTos2YILq6h9NrXeli OQWw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:from:to:cc:subject:date:message-id:in-reply-to :references; bh=F8jYbSFnsruIiKnNDLuveaMOg3G+qtZvBPhffwvhcbc=; b=DHYiIN/MJXgVdFHkW0SPNVLwtzMbyAQGQOjl5g/Lj4OuoxAQQh9XhvuSpTLgrpLpgJ JZXzua4xCsuceff8pJw/0sNsF2QA26IlhXarquuqrk4n/2jJ6YQ6Hqkm89bs4Sb6C8B8 6CTNYXfJSG2WNPFx4GxelEQC1wakZh7/ek6xd85BsJgFDD6MXWQ+7AcvcgyDF7ffRf7G 0Qijwuo66pXbMr/mAFDdLvWKcCZAFjQ+XIqLaLVP0oTi2apZ+HottXUAjjsvY8OVPDjP fdBl8t0LHGHoUYK34ip9iZThMhMCt1IsWJELmFGATCGk7Dvmn7/lKxZeEm5Q//tLhIJa i95Q== X-Gm-Message-State: ALKqPwf15yuYFwDZA4hw3viBETtKuS28pKit50zT/aduo9t6lHEV9fVp tTxCIGNYGc/3GC/vOH8/YO93/nmf X-Google-Smtp-Source: ADUXVKIbslwsNt8CP4n6SvtbzBdiUq8ivhjUIbbrxv6jjwd/Iazxj0Fdh2LuD+oeG6AkMKKHU6EsIA== X-Received: by 2002:a1c:8ccf:: with SMTP id o198-v6mr2272852wmd.82.1527702235458; Wed, 30 May 2018 10:43:55 -0700 (PDT) Received: from orange.brq.redhat.com. (nat-pool-brq-t.redhat.com. [213.175.37.10]) by smtp.gmail.com with ESMTPSA id p3-v6sm18647658wrn.31.2018.05.30.10.43.54 (version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Wed, 30 May 2018 10:43:54 -0700 (PDT) From: Ilya Dryomov To: ceph-devel@vger.kernel.org Cc: Jeff Layton Subject: [PATCH 5/7] libceph: avoid a use-after-free during map check Date: Wed, 30 May 2018 19:43:40 +0200 Message-Id: <1527702222-8232-6-git-send-email-idryomov@gmail.com> X-Mailer: git-send-email 2.4.3 In-Reply-To: <1527702222-8232-1-git-send-email-idryomov@gmail.com> References: <1527702222-8232-1-git-send-email-idryomov@gmail.com> Sender: ceph-devel-owner@vger.kernel.org Precedence: bulk List-ID: X-Mailing-List: ceph-devel@vger.kernel.org X-Virus-Scanned: ClamAV using ClamSMTP Sending map check after complete_request() was called is not only useless, but can lead to a use-after-free as req->r_kref decrement in __complete_request() races with map check code. Signed-off-by: Ilya Dryomov --- net/ceph/osd_client.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/net/ceph/osd_client.c b/net/ceph/osd_client.c index 34b5334548c3..294320400c72 100644 --- a/net/ceph/osd_client.c +++ b/net/ceph/osd_client.c @@ -2266,7 +2266,7 @@ static void __submit_request(struct ceph_osd_request *req, bool wrlocked) complete_request(req, err); mutex_unlock(&osd->lock); - if (ct_res == CALC_TARGET_POOL_DNE) + if (!err && ct_res == CALC_TARGET_POOL_DNE) send_map_check(req); if (promoted)