Donate to e Foundation | Murena handsets with /e/OS | Own a part of Murena! Learn more

Commit 9bd95261 authored by Sage Weil's avatar Sage Weil
Browse files

libceph: avoid NULL kref_put when osd reset races with alloc_msg

The ceph_on_in_msg_alloc() method drops con->mutex while it allocates a
message.  If that races with a timeout that resends a zillion messages and
resets the connection, and the ->alloc_msg() method returns a NULL message,
it will call ceph_msg_put(NULL) and BUG.

Fix by only calling put if msg is non-NULL.

Fixes http://tracker.newdream.net/issues/3142



Signed-off-by: default avatarSage Weil <sage@inktank.com>
parent 588377d6
Loading
Loading
Loading
Loading
+2 −1
Original line number Diff line number Diff line
@@ -2750,6 +2750,7 @@ static int ceph_con_in_msg_alloc(struct ceph_connection *con, int *skip)
		msg = con->ops->alloc_msg(con, hdr, skip);
		mutex_lock(&con->mutex);
		if (con->state != CON_STATE_OPEN) {
			if (msg)
				ceph_msg_put(msg);
			return -EAGAIN;
		}