aboutsummaryrefslogtreecommitdiffstats
path: root/net
diff options
context:
space:
mode:
authorAlex Elder <elder@inktank.com>2012-12-07 10:57:58 -0500
committerAlex Elder <elder@inktank.com>2012-12-17 09:37:23 -0500
commit685a7555ca69030739ddb57a47f0ea8ea80196a4 (patch)
treea24ada30ed29f2329b7d3b62c6206ab5f9ca5df6 /net
parent7d5f24812bd182a2471cb69c1c2baf0648332e1f (diff)
libceph: avoid using freed osd in __kick_osd_requests()
If an osd has no requests and no linger requests, __reset_osd() will just remove it with a call to __remove_osd(). That drops a reference to the osd, and therefore the osd may have been free by the time __reset_osd() returns. That function offers no indication this may have occurred, and as a result the osd will continue to be used even when it's no longer valid. Change__reset_osd() so it returns an error (ENODEV) when it deletes the osd being reset. And change __kick_osd_requests() so it returns immediately (before referencing osd again) if __reset_osd() returns *any* error. Signed-off-by: Alex Elder <elder@inktank.com> Reviewed-by: Sage Weil <sage@inktank.com>
Diffstat (limited to 'net')
-rw-r--r--net/ceph/osd_client.c3
1 files changed, 2 insertions, 1 deletions
diff --git a/net/ceph/osd_client.c b/net/ceph/osd_client.c
index ac7be7202faa..60c74c1f1ea9 100644
--- a/net/ceph/osd_client.c
+++ b/net/ceph/osd_client.c
@@ -581,7 +581,7 @@ static void __kick_osd_requests(struct ceph_osd_client *osdc,
581 581
582 dout("__kick_osd_requests osd%d\n", osd->o_osd); 582 dout("__kick_osd_requests osd%d\n", osd->o_osd);
583 err = __reset_osd(osdc, osd); 583 err = __reset_osd(osdc, osd);
584 if (err == -EAGAIN) 584 if (err)
585 return; 585 return;
586 586
587 list_for_each_entry(req, &osd->o_requests, r_osd_item) { 587 list_for_each_entry(req, &osd->o_requests, r_osd_item) {
@@ -745,6 +745,7 @@ static int __reset_osd(struct ceph_osd_client *osdc, struct ceph_osd *osd)
745 if (list_empty(&osd->o_requests) && 745 if (list_empty(&osd->o_requests) &&
746 list_empty(&osd->o_linger_requests)) { 746 list_empty(&osd->o_linger_requests)) {
747 __remove_osd(osdc, osd); 747 __remove_osd(osdc, osd);
748 ret = -ENODEV;
748 } else if (memcmp(&osdc->osdmap->osd_addr[osd->o_osd], 749 } else if (memcmp(&osdc->osdmap->osd_addr[osd->o_osd],
749 &osd->o_con.peer_addr, 750 &osd->o_con.peer_addr,
750 sizeof(osd->o_con.peer_addr)) == 0 && 751 sizeof(osd->o_con.peer_addr)) == 0 &&