Skip to content

Commit

Permalink
libceph: fix null dereference when unregistering linger requests
Browse files Browse the repository at this point in the history
We should only clear r_osd if we are neither registered as a linger or a
regular request.  We may unregister as a linger while still registered as
a regular request (e.g., in reset_osd).  Incorrectly clearing r_osd there
leads to a null pointer dereference in __send_request.

Also simplify the parallel check in __unregister_request() where we just
removed r_osd_item and know it's empty.

Signed-off-by: Sage Weil <sage@newdream.net>
  • Loading branch information
Sage Weil committed Mar 29, 2011
1 parent 234af26 commit fbdb919
Showing 1 changed file with 3 additions and 3 deletions.
6 changes: 3 additions & 3 deletions net/ceph/osd_client.c
Original file line number Diff line number Diff line change
Expand Up @@ -837,8 +837,7 @@ static void __unregister_request(struct ceph_osd_client *osdc,
dout("moving osd to %p lru\n", req->r_osd);
__move_osd_to_lru(osdc, req->r_osd);
}
if (list_empty(&req->r_osd_item) &&
list_empty(&req->r_linger_item))
if (list_empty(&req->r_linger_item))
req->r_osd = NULL;
}

Expand Down Expand Up @@ -883,7 +882,8 @@ static void __unregister_linger_request(struct ceph_osd_client *osdc,
dout("moving osd to %p lru\n", req->r_osd);
__move_osd_to_lru(osdc, req->r_osd);
}
req->r_osd = NULL;
if (list_empty(&req->r_osd_item))
req->r_osd = NULL;
}
}

Expand Down

0 comments on commit fbdb919

Please sign in to comment.