| From 2218ccf108ae438caf8f8fdb1871b1c16f586840 Mon Sep 17 00:00:00 2001 |
| From: Shenghui Wang <shhuiw@foxmail.com> |
| Date: Fri, 8 Feb 2019 19:02:42 +0800 |
| Subject: [PATCH 17/18] bcache: fix wrong usage use-after-freed on keylist in |
| out_nocoalesce branch of btree_gc_coalesce |
| |
| Elements of keylist should be accessed before the list is freed. |
| Move bch_keylist_free() calling after the while loop to avoid wrong |
| content accessed. |
| |
| Signed-off-by: Shenghui Wang <shhuiw@foxmail.com> |
| Signed-off-by: Coly Li <colyli@suse.de> |
| --- |
| drivers/md/bcache/btree.c | 2 +- |
| 1 file changed, 1 insertion(+), 1 deletion(-) |
| |
| diff --git a/drivers/md/bcache/btree.c b/drivers/md/bcache/btree.c |
| index 64def336f053..b139858b0802 100644 |
| --- a/drivers/md/bcache/btree.c |
| +++ b/drivers/md/bcache/btree.c |
| @@ -1476,11 +1476,11 @@ static int btree_gc_coalesce(struct btree *b, struct btree_op *op, |
| |
| out_nocoalesce: |
| closure_sync(&cl); |
| - bch_keylist_free(&keylist); |
| |
| while ((k = bch_keylist_pop(&keylist))) |
| if (!bkey_cmp(k, &ZERO_KEY)) |
| atomic_dec(&b->c->prio_blocked); |
| + bch_keylist_free(&keylist); |
| |
| for (i = 0; i < nodes; i++) |
| if (!IS_ERR_OR_NULL(new_nodes[i])) { |
| -- |
| 2.16.4 |
| |