| From foo@baz Mon Dec 18 14:12:34 CET 2017 |
| From: Sagi Grimberg <sagi@grimberg.me> |
| Date: Mon, 27 Feb 2017 18:44:45 +0200 |
| Subject: nvme-loop: fix a possible use-after-free when destroying the admin queue |
| |
| From: Sagi Grimberg <sagi@grimberg.me> |
| |
| |
| [ Upstream commit e4c5d3762e2d6d274bd1cc948c47063becfa2103 ] |
| |
| we need to destroy the nvmet sq and let it finish gracefully |
| before continue to cleanup the queue. |
| |
| Reviewed-by: Christoph Hellwig <hch@lst.de> |
| Signed-off-by: Sagi Grimberg <sagi@grimberg.me> |
| Signed-off-by: Sasha Levin <alexander.levin@verizon.com> |
| Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org> |
| --- |
| drivers/nvme/target/loop.c | 2 +- |
| 1 file changed, 1 insertion(+), 1 deletion(-) |
| |
| --- a/drivers/nvme/target/loop.c |
| +++ b/drivers/nvme/target/loop.c |
| @@ -288,9 +288,9 @@ static struct blk_mq_ops nvme_loop_admin |
| |
| static void nvme_loop_destroy_admin_queue(struct nvme_loop_ctrl *ctrl) |
| { |
| + nvmet_sq_destroy(&ctrl->queues[0].nvme_sq); |
| blk_cleanup_queue(ctrl->ctrl.admin_q); |
| blk_mq_free_tag_set(&ctrl->admin_tag_set); |
| - nvmet_sq_destroy(&ctrl->queues[0].nvme_sq); |
| } |
| |
| static void nvme_loop_free_ctrl(struct nvme_ctrl *nctrl) |