From: Chris Wright <chrisw@sous-sol.org>
To: linux-kernel@vger.kernel.org, stable@kernel.org,
git-commits-head@vger.kernel.org
Cc: Justin Forbes <jmforbes@linuxtx.org>,
Zwane Mwaikambo <zwane@arm.linux.org.uk>,
"Theodore Ts'o" <tytso@mit.edu>,
Randy Dunlap <rdunlap@xenotime.net>,
Dave Jones <davej@redhat.com>,
Chuck Wolber <chuckw@quantumlinux.com>,
torvalds@osdl.org, akpm@osdl.org, alan@lxorguk.ukuu.org.uk,
Oleg Drokin <green@linuxhacker.ru>,
Trond Myklebust <trond.myklebust@fys.uio.no>,
<viro@parcelfarce.linux.theplanet.co.uk>,
Christoph Hellwig <hch@lst.de>
Subject: [PATCH 03/23] [PATCH] d_instantiate_unique / NFS inode leakage
Date: Tue, 07 Feb 2006 22:45:06 -0800 [thread overview]
Message-ID: <20060208064852.371401000@sorel.sous-sol.org> (raw)
In-Reply-To: <20060208064503.924238000@sorel.sous-sol.org>
[-- Attachment #1: d_instantiate_unique-nfs-inode-leakage.patch --]
[-- Type: text/plain, Size: 1707 bytes --]
-stable review patch. If anyone has any objections, please let us know.
------------------
If we have found aliased dentry that we return, inode reference is not
dropped and inode is not attached anywhere, so it seems the reference to
inode is leaked in that case.
Cc: Trond Myklebust <trond.myklebust@fys.uio.no>,
Cc: <viro@parcelfarce.linux.theplanet.co.uk>
Cc: Christoph Hellwig <hch@lst.de>
Signed-off-by: Andrew Morton <akpm@osdl.org>
Signed-off-by: Linus Torvalds <torvalds@osdl.org>
Signed-off-by: Chris Wright <chrisw@sous-sol.org>
---
fs/dcache.c | 7 ++++++-
1 files changed, 6 insertions(+), 1 deletion(-)
Index: linux-2.6.15.3/fs/dcache.c
===================================================================
--- linux-2.6.15.3.orig/fs/dcache.c
+++ linux-2.6.15.3/fs/dcache.c
@@ -808,10 +808,14 @@ void d_instantiate(struct dentry *entry,
*
* Fill in inode information in the entry. On success, it returns NULL.
* If an unhashed alias of "entry" already exists, then we return the
- * aliased dentry instead.
+ * aliased dentry instead and drop one reference to inode.
*
* Note that in order to avoid conflicts with rename() etc, the caller
* had better be holding the parent directory semaphore.
+ *
+ * This also assumes that the inode count has been incremented
+ * (or otherwise set) by the caller to indicate that it is now
+ * in use by the dcache.
*/
struct dentry *d_instantiate_unique(struct dentry *entry, struct inode *inode)
{
@@ -838,6 +842,7 @@ struct dentry *d_instantiate_unique(stru
dget_locked(alias);
spin_unlock(&dcache_lock);
BUG_ON(!d_unhashed(alias));
+ iput(inode);
return alias;
}
list_add(&entry->d_alias, &inode->i_dentry);
--
next prev parent reply other threads:[~2006-02-08 6:46 UTC|newest]
Thread overview: 26+ messages / expand[flat|nested] mbox.gz Atom feed top
2006-02-08 6:45 [PATCH 00/23] -stable review Chris Wright
2006-02-08 6:45 ` [PATCH 01/23] SCSI: turn off ordered flush barriers Chris Wright
2006-02-08 6:45 ` [PATCH 02/23] [PATCH] dm-crypt: zero key before freeing it Chris Wright
2006-02-08 6:45 ` Chris Wright [this message]
2006-02-08 6:45 ` [PATCH 04/23] seclvl settime fix Chris Wright
2006-02-08 6:45 ` [PATCH 05/23] [XFS] fix regression in xfs_buf_rele Chris Wright
2006-02-08 6:45 ` [PATCH 06/23] Input: mousedev - fix memory leak Chris Wright
2006-02-08 6:45 ` [PATCH 07/23] Input: grip - fix crash when accessing device Chris Wright
2006-02-08 6:45 ` [PATCH 08/23] Input: db9 - fix possible crash with Saturn gamepads Chris Wright
2006-02-08 6:45 ` [PATCH 09/23] Input: sidewinder - fix an oops Chris Wright
2006-02-08 6:45 ` [PATCH 10/23] Input: iforce - do not return ENOMEM upon successful allocation Chris Wright
2006-02-08 6:45 ` [PATCH 11/23] Input: iforce - fix detection of USB devices Chris Wright
2006-02-08 6:45 ` [PATCH 12/23] [SPARC64]: Kill compat_sys_clock_settime sign extension stub Chris Wright
2006-02-08 6:45 ` [PATCH 13/23] Fix keyctl usage of strnlen_user() Chris Wright
2006-02-08 6:45 ` [PATCH 14/23] [PATCH] PCMCIA=m, HOSTAP_CS=y is not a legal configuration Chris Wright
2006-02-08 6:45 ` [PATCH 15/23] [PATCH] SELinux: fix size-128 slab leak Chris Wright
2006-02-08 6:45 ` [PATCH 16/23] [PPP]: Fixed hardware RX checksum handling Chris Wright
2006-02-08 6:45 ` [PATCH 17/23] [PATCH] x86_64: Let impossible CPUs point to reference per cpu data Chris Wright
2006-02-08 6:45 ` [PATCH 18/23] [PATCH] x86_64: Clear more state when ignoring empty node in SRAT parsing Chris Wright
2006-02-08 6:45 ` [PATCH 19/23] [PATCH] bridge: netfilter races on device removal Chris Wright
2006-02-08 6:45 ` [PATCH 20/23] [PATCH] bridge: fix RCU race " Chris Wright
2006-02-08 6:45 ` [PATCH 21/23] [ALSA] emu10k1 - Fix the confliction of Front control Chris Wright
2006-02-08 6:45 ` [PATCH 22/23] [PATCH] x86_64: Dont record local apic ids when they are disabled in MADT Chris Wright
2006-02-08 6:45 ` [PATCH 23/23] [alpha] __cmpxchg() must really always be inlined Chris Wright
2006-02-08 10:07 ` [PATCH 13/23] Fix keyctl usage of strnlen_user() David Howells
2006-02-08 23:39 ` [PATCH 24/23] md: remove slashes from disk names when creation dev names in sysfs Chris Wright
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20060208064852.371401000@sorel.sous-sol.org \
--to=chrisw@sous-sol.org \
--cc=akpm@osdl.org \
--cc=alan@lxorguk.ukuu.org.uk \
--cc=chuckw@quantumlinux.com \
--cc=davej@redhat.com \
--cc=git-commits-head@vger.kernel.org \
--cc=green@linuxhacker.ru \
--cc=hch@lst.de \
--cc=jmforbes@linuxtx.org \
--cc=linux-kernel@vger.kernel.org \
--cc=rdunlap@xenotime.net \
--cc=stable@kernel.org \
--cc=torvalds@osdl.org \
--cc=trond.myklebust@fys.uio.no \
--cc=tytso@mit.edu \
--cc=viro@parcelfarce.linux.theplanet.co.uk \
--cc=zwane@arm.linux.org.uk \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®