Commit 6775cab9 authored by Herbert Xu's avatar Herbert Xu Committed by Linus Torvalds
Browse files

[PATCH] Fix dst_destroy() race



When we are not the real parent of the dst (e.g., when we're xfrm_dst and
the child is an rtentry), it may already be on the GC list.

In fact the current code is buggy to, we need to check dst->flags before
the dec as dst may no longer be valid afterwards.

Signed-off-by: default avatarHerbert Xu <herbert@gondor.apana.org.au>
Signed-off-by: default avatarDavid S. Miller <davem@davemloft.net>
Signed-off-by: default avatarAndrew Morton <akpm@osdl.org>
Signed-off-by: default avatarLinus Torvalds <torvalds@osdl.org>
parent 2a278051
Loading
Loading
Loading
Loading
+4 −2
Original line number Diff line number Diff line
@@ -198,13 +198,15 @@ struct dst_entry *dst_destroy(struct dst_entry * dst)

	dst = child;
	if (dst) {
		int nohash = dst->flags & DST_NOHASH;

		if (atomic_dec_and_test(&dst->__refcnt)) {
			/* We were real parent of this dst, so kill child. */
			if (dst->flags&DST_NOHASH)
			if (nohash)
				goto again;
		} else {
			/* Child is still referenced, return it for freeing. */
			if (dst->flags&DST_NOHASH)
			if (nohash)
				return dst;
			/* Child is still in his hash table */
		}