aboutsummaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorNeilBrown <neilb@suse.de>2015-06-25 03:01:40 -0400
committerNeilBrown <neilb@suse.de>2015-06-25 03:14:09 -0400
commitbd6919228d7e1867ae9e24ab27e3e4a366c87d21 (patch)
treebff3abd584f425a50b61330bec2083dcbec062b0
parent4e023612325a9034a542bfab79f78b1fe5ebb841 (diff)
md: clear mddev->private when it has been freed.
If ->private is set when ->run is called, it is assumed to be a 'config' prepared as part of 'reshape'. So it is important when we free that config, that we also clear ->private. This is not often a problem as the mddev will normally be discarded shortly after the config us freed. However if an 'assemble' races with a final close, the assemble can use the old mddev which has a stale ->private. This leads to any of various sorts of crashes. So clear ->private after calling ->free(). Reported-by: Nate Clark <nate@neworld.us> Cc: stable@vger.kernel.org (v4.0+) Fixes: afa0f557cb15 ("md: rename ->stop to ->free") Signed-off-by: NeilBrown <neilb@suse.com>
-rw-r--r--drivers/md/md.c3
1 files changed, 3 insertions, 0 deletions
diff --git a/drivers/md/md.c b/drivers/md/md.c
index 3d339e283cf6..939739f0f881 100644
--- a/drivers/md/md.c
+++ b/drivers/md/md.c
@@ -5178,6 +5178,7 @@ int md_run(struct mddev *mddev)
5178 mddev_detach(mddev); 5178 mddev_detach(mddev);
5179 if (mddev->private) 5179 if (mddev->private)
5180 pers->free(mddev, mddev->private); 5180 pers->free(mddev, mddev->private);
5181 mddev->private = NULL;
5181 module_put(pers->owner); 5182 module_put(pers->owner);
5182 bitmap_destroy(mddev); 5183 bitmap_destroy(mddev);
5183 return err; 5184 return err;
@@ -5313,6 +5314,7 @@ static void md_clean(struct mddev *mddev)
5313 mddev->changed = 0; 5314 mddev->changed = 0;
5314 mddev->degraded = 0; 5315 mddev->degraded = 0;
5315 mddev->safemode = 0; 5316 mddev->safemode = 0;
5317 mddev->private = NULL;
5316 mddev->merge_check_needed = 0; 5318 mddev->merge_check_needed = 0;
5317 mddev->bitmap_info.offset = 0; 5319 mddev->bitmap_info.offset = 0;
5318 mddev->bitmap_info.default_offset = 0; 5320 mddev->bitmap_info.default_offset = 0;
@@ -5385,6 +5387,7 @@ static void __md_stop(struct mddev *mddev)
5385 mddev->pers = NULL; 5387 mddev->pers = NULL;
5386 spin_unlock(&mddev->lock); 5388 spin_unlock(&mddev->lock);
5387 pers->free(mddev, mddev->private); 5389 pers->free(mddev, mddev->private);
5390 mddev->private = NULL;
5388 if (pers->sync_request && mddev->to_remove == NULL) 5391 if (pers->sync_request && mddev->to_remove == NULL)
5389 mddev->to_remove = &md_redundancy_group; 5392 mddev->to_remove = &md_redundancy_group;
5390 module_put(pers->owner); 5393 module_put(pers->owner);