Re: [PATCH] scatterlist: prevent invalid free when alloc fails

From: Jeffrey Carlyle
Date: Fri Aug 27 2010 - 16:15:26 EST


On Fri, Aug 27, 2010 at 2:45 PM, Jeffrey Carlyle
<jeff.carlyle@xxxxxxxxxxxx> wrote:
> On Fri, Aug 27, 2010 at 5:18 AM, Tejun Heo <tj@xxxxxxxxxx> wrote:
>> On 08/26/2010 06:04 PM, Jeffrey Carlyle wrote:
>>> diff --git a/lib/scatterlist.c b/lib/scatterlist.c
>>> index a5ec428..acf2c6e 100644
>>> --- a/lib/scatterlist.c
>>> +++ b/lib/scatterlist.c
>>> @@ -163,7 +163,7 @@ void __sg_free_table(struct sg_table *table,
>>> unsigned int max_ents,
>>>               return;
>>>
>>>       sgl = table->sgl;
>>> -     while (table->orig_nents) {
>>> +     while (table->orig_nents && sgl) {
>>>               unsigned int alloc_size = table->orig_nents;
>>>               unsigned int sg_size;
>>
>> Why is this change necessary?
>
> Well the problem we were seeing manifested itself when we called
> free_fn on a NULL value. This was a naive attempt at avoiding that. If
> the logic in __sg_alloc_table is corrected, I agree that we shouldn't
> need this.

Actually, please disregard the comment about trying to free NULL. I
don't think we need to add the "&& sgl" under any circumstances.
--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at http://vger.kernel.org/majordomo-info.html
Please read the FAQ at http://www.tux.org/lkml/