NFS4: Fix use-after-free in trace_event_raw_event_nfs4_set_lock
commit5.4-rM2-2.2.x-imx-squashed3d1a90ab0e
upstream. It is only safe to call the tracepoint before rpc_put_task() because 'data' is freed inside nfs4_lock_release (rpc_release). Fixes:48c9579a1a
("Adding stateid information to tracepoints") Signed-off-by: Dave Wysochanski <dwysocha@redhat.com> Signed-off-by: Trond Myklebust <trond.myklebust@hammerspace.com> Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
parent
c70f6e0ac9
commit
69d121ca89
|
@ -6959,9 +6959,9 @@ static int _nfs4_do_setlk(struct nfs4_state *state, int cmd, struct file_lock *f
|
||||||
data->arg.new_lock_owner, ret);
|
data->arg.new_lock_owner, ret);
|
||||||
} else
|
} else
|
||||||
data->cancelled = true;
|
data->cancelled = true;
|
||||||
|
trace_nfs4_set_lock(fl, state, &data->res.stateid, cmd, ret);
|
||||||
rpc_put_task(task);
|
rpc_put_task(task);
|
||||||
dprintk("%s: done, ret = %d!\n", __func__, ret);
|
dprintk("%s: done, ret = %d!\n", __func__, ret);
|
||||||
trace_nfs4_set_lock(fl, state, &data->res.stateid, cmd, ret);
|
|
||||||
return ret;
|
return ret;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|
Loading…
Reference in New Issue