GFS2: Fix use-after-free bug on umount (try #2)
authorSteven Whitehouse <swhiteho@redhat.com>
Fri, 19 Dec 2008 15:43:05 +0000 (15:43 +0000)
committerSteven Whitehouse <swhiteho@redhat.com>
Mon, 5 Jan 2009 07:39:19 +0000 (07:39 +0000)
This should solve the issue with the previous attempt at fixing this.

Signed-off-by: Steven Whitehouse <swhiteho@redhat.com>
fs/gfs2/ops_fstype.c
fs/gfs2/ops_super.c

index 4cae60f4a1758d1fde59186ec37227ca97bd8b9f..f91eebdde5817f1f3eba25a724d48f1dc6132c59 100644 (file)
@@ -1263,17 +1263,21 @@ static int gfs2_get_sb_meta(struct file_system_type *fs_type, int flags,
 static void gfs2_kill_sb(struct super_block *sb)
 {
        struct gfs2_sbd *sdp = sb->s_fs_info;
-       if (sdp) {
-               gfs2_meta_syncfs(sdp);
-               dput(sdp->sd_root_dir);
-               dput(sdp->sd_master_dir);
-               sdp->sd_root_dir = NULL;
-               sdp->sd_master_dir = NULL;
+
+       if (sdp == NULL) {
+               kill_block_super(sb);
+               return;
        }
+
+       gfs2_meta_syncfs(sdp);
+       dput(sdp->sd_root_dir);
+       dput(sdp->sd_master_dir);
+       sdp->sd_root_dir = NULL;
+       sdp->sd_master_dir = NULL;
        shrink_dcache_sb(sb);
        kill_block_super(sb);
-       if (sdp)
-               gfs2_delete_debugfs_file(sdp);
+       gfs2_delete_debugfs_file(sdp);
+       kfree(sdp);
 }
 
 struct file_system_type gfs2_fs_type = {
index 08837a728635d9ea06d6cff998a86b7531847b6c..777783deddcb8aba814988212d34d4996dfec7e6 100644 (file)
@@ -182,7 +182,6 @@ static void gfs2_put_super(struct super_block *sb)
 
        /*  At this point, we're through participating in the lockspace  */
        gfs2_sys_fs_del(sdp);
-       kfree(sdp);
 }
 
 /**