Whamcloud - gitweb
LU-4360 Fix use after free in ksocknal_send 67/8667/3
authorOleg Drokin <oleg.drokin@intel.com>
Sat, 28 Dec 2013 03:31:15 +0000 (22:31 -0500)
committerOleg Drokin <oleg.drokin@intel.com>
Sat, 11 Jan 2014 17:22:49 +0000 (17:22 +0000)
Call to ksocknal_launch_packet might schedule a callback that
might free the just sent message, and so subsequent access to it
via lntmsg->msg_vmflush goes to freed memory.

Instead we'll just remember if we are in the vmflush thread and
only restore if we happened to set mempressure flag.

Change-Id: I2f0f8b27e26e11b37ad60fde4c98e86c39768349
Signed-off-by: Oleg Drokin <oleg.drokin@intel.com>
Reviewed-on: http://review.whamcloud.com/8667
Tested-by: Jenkins
Tested-by: Maloo <hpdd-maloo@intel.com>
Reviewed-by: Liang Zhen <liang.zhen@intel.com>
Reviewed-by: Amir Shehata <amir.shehata@intel.com>
lnet/klnds/socklnd/socklnd_cb.c

index e945ef2..9db13f8 100644 (file)
@@ -928,7 +928,7 @@ ksocknal_launch_packet (lnet_ni_t *ni, ksock_tx_t *tx, lnet_process_id_t id)
 int
 ksocknal_send(lnet_ni_t *ni, void *private, lnet_msg_t *lntmsg)
 {
-        int               mpflag = 0;
+        int               mpflag = 1;
         int               type = lntmsg->msg_type;
         lnet_process_id_t target = lntmsg->msg_target;
         unsigned int      payload_niov = lntmsg->msg_niov;
@@ -997,8 +997,9 @@ ksocknal_send(lnet_ni_t *ni, void *private, lnet_msg_t *lntmsg)
 
         /* The first fragment will be set later in pro_pack */
         rc = ksocknal_launch_packet(ni, tx, target);
-        if (lntmsg->msg_vmflush)
+        if (!mpflag)
                 cfs_memory_pressure_restore(mpflag);
+
         if (rc == 0)
                 return (0);