Skip to content

Commit

Permalink
block: WARN in __blk_put_request() for potential bio leak
Browse files Browse the repository at this point in the history
Put a WARN_ON in __blk_put_request if it is about to
leak bio(s). This is a serious bug that can happen in error
handling code paths.

For this to work I have fixed a couple of places in block/ where
request->bio != NULL ownership was not honored. And a small cleanup
at sg_io() while at it.

Signed-off-by: Boaz Harrosh <[email protected]>
Signed-off-by: Jens Axboe <[email protected]>
  • Loading branch information
Boaz Harrosh authored and Jens Axboe committed Mar 26, 2009
1 parent f028f3b commit 1cd96c2
Show file tree
Hide file tree
Showing 3 changed files with 9 additions and 17 deletions.
3 changes: 3 additions & 0 deletions block/blk-core.c
Original file line number Diff line number Diff line change
Expand Up @@ -1062,6 +1062,9 @@ void __blk_put_request(struct request_queue *q, struct request *req)

elv_completed_request(q, req);

/* this is a bio leak */
WARN_ON(req->bio != NULL);

/*
* Request may not have originated from ll_rw_blk. if not,
* it didn't come out of our reserved rq pools
Expand Down
2 changes: 2 additions & 0 deletions block/blk-merge.c
Original file line number Diff line number Diff line change
Expand Up @@ -403,6 +403,8 @@ static int attempt_merge(struct request_queue *q, struct request *req,
if (blk_rq_cpu_valid(next))
req->cpu = next->cpu;

/* owner-ship of bio passed from next to req */
next->bio = NULL;
__blk_put_request(q, next);
return 1;
}
Expand Down
21 changes: 4 additions & 17 deletions block/scsi_ioctl.c
Original file line number Diff line number Diff line change
Expand Up @@ -214,21 +214,10 @@ static int blk_fill_sghdr_rq(struct request_queue *q, struct request *rq,
return 0;
}

/*
* unmap a request that was previously mapped to this sg_io_hdr. handles
* both sg and non-sg sg_io_hdr.
*/
static int blk_unmap_sghdr_rq(struct request *rq, struct sg_io_hdr *hdr)
{
blk_rq_unmap_user(rq->bio);
blk_put_request(rq);
return 0;
}

static int blk_complete_sghdr_rq(struct request *rq, struct sg_io_hdr *hdr,
struct bio *bio)
{
int r, ret = 0;
int ret = 0;

/*
* fill in all the output members
Expand All @@ -253,12 +242,10 @@ static int blk_complete_sghdr_rq(struct request *rq, struct sg_io_hdr *hdr,
ret = -EFAULT;
}

rq->bio = bio;
r = blk_unmap_sghdr_rq(rq, hdr);
if (ret)
r = ret;
blk_rq_unmap_user(bio);
blk_put_request(rq);

return r;
return ret;
}

static int sg_io(struct request_queue *q, struct gendisk *bd_disk,
Expand Down

0 comments on commit 1cd96c2

Please sign in to comment.