mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: "Jesper Juhl" <jesper.juhl@gmail.com>
To: linux-kernel@vger.kernel.org, isdn4linux@listserv.isdn4linux.de,
	"Jesper Juhl" <jesper.juhl@gmail.com>,
	"David Miller" <davem@davemloft.net>
Subject: Re: [PATCH] ISDN: fix double free bug in isdn_net
Date: Wed, 16 Aug 2006 22:22:46 +0200	[thread overview]
Message-ID: <9a8748490608161322q64e7d48fmbdf68288db22b64e@mail.gmail.com> (raw)
In-Reply-To: <20060815160657.GA14266@pingi.kke.suse.de>

On 15/08/06, Karsten Keil <kkeil@suse.de> wrote:
> On Tue, Aug 15, 2006 at 02:15:03AM -0700, David Miller wrote:
> > From: "Jesper Juhl" <jesper.juhl@gmail.com>
> > Date: Tue, 15 Aug 2006 11:08:35 +0200
> >
> > > Hmm, perhaps I made a mistake and missed a path. Maybe it would be
> > > better to fix if by making isdn_writebuf_skb_stub() always set the skb
> > > to NULL when it does free it. That would add a few more assignments
> > > but should ensure the right result always.
> > > What do you say?
> >
> > Do we know if the ->writebuf_skb() method ever frees the skb?  If it
> > never does, then yes your suggestion would be one way to handle this.
>
>
> It does if it consumes the skb (then it returns skb->len).
> But the skb have not to be freed imediately in this case, it maybe
> queued or used until all bytes are written to the physical device.
>
> If it returns any other value the skb is not freed.
>
> This logic came from using skb for transparent data too.
> Here it was possible, that the hw driver only take some bytes from the
> skb (so it returns < skb->len), then the isdn layer should requeue
> the skb so no transparent data get lost.
>
> But this mechanism was never used in drivers, only 3 states:
>
> The driver accept the packet then it is responsible for the skb
> and return skb->len or the driver do not accept it (e.g. buffer full,
> conntection is going down), then it return 0 and does not free the
> skb.
>
> If some internal error in the HW driver occur, it should return a
> negative value and it also do not free the skb.
>

Ok, if I understand you correctly, then there's no actual problem here.
right?

-- 
Jesper Juhl <jesper.juhl@gmail.com>
Don't top-post  http://www.catb.org/~esr/jargon/html/T/top-post.html
Plain text mails only, please      http://www.expita.com/nomime.html

  reply	other threads:[~2006-08-16 20:22 UTC|newest]

Thread overview: 10+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2006-08-12 20:48 Jesper Juhl
2006-08-15  9:00 ` David Miller
2006-08-15  9:08   ` Jesper Juhl
2006-08-15  9:15     ` David Miller
2006-08-15 10:42       ` Jesper Juhl
2006-08-15 16:06       ` Karsten Keil
2006-08-16 20:22         ` Jesper Juhl [this message]
2006-08-16 20:39           ` Karsten Keil
2006-08-16 20:44             ` David Miller
2006-08-16 20:48             ` Jesper Juhl

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=9a8748490608161322q64e7d48fmbdf68288db22b64e@mail.gmail.com \
    --to=jesper.juhl@gmail.com \
    --cc=davem@davemloft.net \
    --cc=isdn4linux@listserv.isdn4linux.de \
    --cc=linux-kernel@vger.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®