Donate to e Foundation | Murena handsets with /e/OS | Own a part of Murena! Learn more

Commit 0d7718f6 authored by Nikolay Borisov's avatar Nikolay Borisov Committed by Ilya Dryomov
Browse files

ceph: fix error handling in ceph_read_iter



In case __ceph_do_getattr returns an error and the retry_op in
ceph_read_iter is not READ_INLINE, then it's possible to invoke
__free_page on a page which is NULL, this naturally leads to a crash.
This can happen when, for example, a process waiting on a MDS reply
receives sigterm.

Fix this by explicitly checking whether the page is set or not.

Cc: stable@vger.kernel.org # 3.19+
Signed-off-by: default avatarNikolay Borisov <kernel@kyup.com>
Reviewed-by: default avatarYan, Zheng <zyan@redhat.com>
Signed-off-by: default avatarIlya Dryomov <idryomov@gmail.com>
parent 4d73644b
Loading
Loading
Loading
Loading
+2 −1
Original line number Original line Diff line number Diff line
@@ -1272,6 +1272,7 @@ static ssize_t ceph_read_iter(struct kiocb *iocb, struct iov_iter *to)
		statret = __ceph_do_getattr(inode, page,
		statret = __ceph_do_getattr(inode, page,
					    CEPH_STAT_CAP_INLINE_DATA, !!page);
					    CEPH_STAT_CAP_INLINE_DATA, !!page);
		if (statret < 0) {
		if (statret < 0) {
			if (page)
				__free_page(page);
				__free_page(page);
			if (statret == -ENODATA) {
			if (statret == -ENODATA) {
				BUG_ON(retry_op != READ_INLINE);
				BUG_ON(retry_op != READ_INLINE);