Commit 122deabf authored by Zhihao Cheng's avatar Zhihao Cheng Committed by Richard Weinberger

ubifs: dirty_cow_znode: Fix memleak in error handling path

Following process will cause a memleak for copied up znode:

dirty_cow_znode
  zn = copy_znode(c, znode);
  err = insert_old_idx(c, zbr->lnum, zbr->offs);
  if (unlikely(err))
     return ERR_PTR(err);   // No one refers to zn.

Fix it by adding copied znode back to tnc, then it will be freed
by ubifs_destroy_tnc_subtree() while closing tnc.

Fetch a reproducer in [Link].

Link: https://bugzilla.kernel.org/show_bug.cgi?id=216705
Fixes: 1e51764a ("UBIFS: add new flash file system")
Signed-off-by: default avatarZhihao Cheng <chengzhihao1@huawei.com>
Signed-off-by: default avatarRichard Weinberger <richard@nod.at>
parent 944e096a
...@@ -267,11 +267,18 @@ static struct ubifs_znode *dirty_cow_znode(struct ubifs_info *c, ...@@ -267,11 +267,18 @@ static struct ubifs_znode *dirty_cow_znode(struct ubifs_info *c,
if (zbr->len) { if (zbr->len) {
err = insert_old_idx(c, zbr->lnum, zbr->offs); err = insert_old_idx(c, zbr->lnum, zbr->offs);
if (unlikely(err)) if (unlikely(err))
return ERR_PTR(err); /*
* Obsolete znodes will be freed by tnc_destroy_cnext()
* or free_obsolete_znodes(), copied up znodes should
* be added back to tnc and freed by
* ubifs_destroy_tnc_subtree().
*/
goto out;
err = add_idx_dirt(c, zbr->lnum, zbr->len); err = add_idx_dirt(c, zbr->lnum, zbr->len);
} else } else
err = 0; err = 0;
out:
zbr->znode = zn; zbr->znode = zn;
zbr->lnum = 0; zbr->lnum = 0;
zbr->offs = 0; zbr->offs = 0;
......
Markdown is supported
0%
or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment