summaryrefslogtreecommitdiffstats
path: root/include
diff options
context:
space:
mode:
authorJosh Durgin <josh.durgin@inktank.com>2013-08-29 17:26:31 -0700
committerJosh Durgin <josh.durgin@inktank.com>2013-09-09 11:16:25 -0700
commit9875201e10496612080e7d164acc8f625c18725c (patch)
tree9921ff119c3d9e87db94e455597fbe772906ac81 /include
parent20e0af67ce88c657d0601977b9941a2256afbdaa (diff)
downloadlinux-9875201e10496612080e7d164acc8f625c18725c.tar.gz
linux-9875201e10496612080e7d164acc8f625c18725c.tar.bz2
linux-9875201e10496612080e7d164acc8f625c18725c.zip
rbd: fix use-after free of rbd_dev->disk
Removing a device deallocates the disk, unschedules the watch, and finally cleans up the rbd_dev structure. rbd_dev_refresh(), called from the watch callback, updates the disk size and rbd_dev structure. With no locking between them, rbd_dev_refresh() may use the device or rbd_dev after they've been freed. To fix this, check whether RBD_DEV_FLAG_REMOVING is set before updating the disk size in rbd_dev_refresh(). In order to prevent a race where rbd_dev_refresh() is already revalidating the disk when rbd_remove() is called, move the call to rbd_bus_del_dev() after the watch is unregistered and all notifies are complete. It's safe to defer deleting this structure because no new requests can be submitted once the RBD_DEV_FLAG_REMOVING is set, since the device cannot be opened. Fixes: http://tracker.ceph.com/issues/5636 Signed-off-by: Josh Durgin <josh.durgin@inktank.com> Reviewed-by: Alex Elder <elder@linaro.org>
Diffstat (limited to 'include')
0 files changed, 0 insertions, 0 deletions