From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S932112AbbFHSvt (ORCPT ); Mon, 8 Jun 2015 14:51:49 -0400 Received: from mx1.redhat.com ([209.132.183.28]:35168 "EHLO mx1.redhat.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1752765AbbFHSvl (ORCPT ); Mon, 8 Jun 2015 14:51:41 -0400 From: Jeff Moyer To: Tejun Heo Cc: axboe@kernel.dk, linux-kernel@vger.kernel.org, cgroups@vger.kernel.org, vgoyal@redhat.com, avanzini.arianna@gmail.com Subject: Re: [PATCH 3/8] cfq-iosched: fix oom cfq_queue ref leak in cfq_set_request() References: <1433753973-23684-1-git-send-email-tj@kernel.org> <1433753973-23684-4-git-send-email-tj@kernel.org> X-PGP-KeyID: 1F78E1B4 X-PGP-CertKey: F6FE 280D 8293 F72C 65FD 5A58 1FF8 A7CA 1F78 E1B4 X-PCLoadLetter: What the f**k does that mean? Date: Mon, 08 Jun 2015 14:51:39 -0400 In-Reply-To: <1433753973-23684-4-git-send-email-tj@kernel.org> (Tejun Heo's message of "Mon, 8 Jun 2015 17:59:28 +0900") Message-ID: User-Agent: Gnus/5.13 (Gnus v5.13) Emacs/24.3 (gnu/linux) MIME-Version: 1.0 Content-Type: text/plain Sender: linux-kernel-owner@vger.kernel.org List-ID: X-Mailing-List: linux-kernel@vger.kernel.org Tejun Heo writes: > If the cfq_queue cached in cfq_io_cq is the oom one, cfq_set_request() > replaces it by invoking cfq_get_queue() again without putting the oom > queue leaking the reference it was holding. While oom queues are not > released through reference counting, they're still reference counted > and this can theoretically lead to the reference count overflowing and > incorrectly invoke the usual release path on it. > > Fix it by making cfq_set_request() put the ref it was holding. > > Signed-off-by: Tejun Heo > Cc: Vivek Goyal > Cc: Arianna Avanzini Reviewed-by: Jeff Moyer