Linux kernel mirror (for testing) git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git
kernel os linux

libceph: avoid using freed osd in __kick_osd_requests()

If an osd has no requests and no linger requests, __reset_osd()
will just remove it with a call to __remove_osd(). That drops
a reference to the osd, and therefore the osd may have been free
by the time __reset_osd() returns. That function offers no
indication this may have occurred, and as a result the osd will
continue to be used even when it's no longer valid.

Change__reset_osd() so it returns an error (ENODEV) when it
deletes the osd being reset. And change __kick_osd_requests() so it
returns immediately (before referencing osd again) if __reset_osd()
returns *any* error.

Signed-off-by: Alex Elder <elder@inktank.com>
Reviewed-by: Sage Weil <sage@inktank.com>

+2 -1
+2 -1
net/ceph/osd_client.c
··· 581 581 582 582 dout("__kick_osd_requests osd%d\n", osd->o_osd); 583 583 err = __reset_osd(osdc, osd); 584 - if (err == -EAGAIN) 584 + if (err) 585 585 return; 586 586 587 587 list_for_each_entry(req, &osd->o_requests, r_osd_item) { ··· 745 745 if (list_empty(&osd->o_requests) && 746 746 list_empty(&osd->o_linger_requests)) { 747 747 __remove_osd(osdc, osd); 748 + ret = -ENODEV; 748 749 } else if (memcmp(&osdc->osdmap->osd_addr[osd->o_osd], 749 750 &osd->o_con.peer_addr, 750 751 sizeof(osd->o_con.peer_addr)) == 0 &&