Skip to content

Commit

Permalink
batman-adv: increase orig refcount when storing ref in gw_node
Browse files Browse the repository at this point in the history
A pointer to the orig_node representing a bat-gateway is
stored in the gw_node->orig_node member, but the refcount
for such orig_node is never increased.
This leads to memory faults when gw_node->orig_node is accessed
and the originator has already been freed.

Fix this by increasing the refcount on gw_node creation
and decreasing it on gw_node free.

Signed-off-by: Antonio Quartulli <[email protected]>
Signed-off-by: Marek Lindner <[email protected]>
  • Loading branch information
ordex committed May 15, 2014
1 parent be18101 commit 377fe0f
Showing 1 changed file with 9 additions and 2 deletions.
11 changes: 9 additions & 2 deletions net/batman-adv/gateway_client.c
Original file line number Diff line number Diff line change
Expand Up @@ -42,8 +42,10 @@

static void batadv_gw_node_free_ref(struct batadv_gw_node *gw_node)
{
if (atomic_dec_and_test(&gw_node->refcount))
if (atomic_dec_and_test(&gw_node->refcount)) {
batadv_orig_node_free_ref(gw_node->orig_node);
kfree_rcu(gw_node, rcu);
}
}

static struct batadv_gw_node *
Expand Down Expand Up @@ -406,9 +408,14 @@ static void batadv_gw_node_add(struct batadv_priv *bat_priv,
if (gateway->bandwidth_down == 0)
return;

if (!atomic_inc_not_zero(&orig_node->refcount))
return;

gw_node = kzalloc(sizeof(*gw_node), GFP_ATOMIC);
if (!gw_node)
if (!gw_node) {
batadv_orig_node_free_ref(orig_node);
return;
}

INIT_HLIST_NODE(&gw_node->list);
gw_node->orig_node = orig_node;
Expand Down

0 comments on commit 377fe0f

Please sign in to comment.