mirror of
https://github.com/torvalds/linux.git
synced 2026-07-27 01:32:21 +02:00
libceph: remove debugfs files before client teardown
ceph_destroy_client() tears down the monitor client before removing
the per-client debugfs files. A concurrent read of the monmap debugfs
file can enter monmap_show() after ceph_monc_stop() has freed
monc->monmap, triggering a use-after-free.
Remove the debugfs files before stopping the OSD and monitor clients.
debugfs_remove() drains active handlers and prevents new accesses, so
the debugfs callbacks can no longer race the rest of client teardown.
Cc: stable@vger.kernel.org
Fixes: 76aa844d5b ("ceph: debugfs")
Reported-by: Yuan Tan <yuantan098@gmail.com>
Reported-by: Zhengchuan Liang <zcliangcn@gmail.com>
Reported-by: Xin Liu <bird@lzu.edu.cn>
Assisted-by: Codex:GPT-5.4
Signed-off-by: Douya Le <ldy3087146292@gmail.com>
Signed-off-by: Ren Wei <n05ec@lzu.edu.cn>
Reviewed-by: Viacheslav Dubeyko <slava@dubeyko.com>
Signed-off-by: Ilya Dryomov <idryomov@gmail.com>
This commit is contained in:
parent
d3c32939fa
commit
e4c804726c
|
|
@ -762,13 +762,13 @@ void ceph_destroy_client(struct ceph_client *client)
|
|||
|
||||
atomic_set(&client->msgr.stopping, 1);
|
||||
|
||||
ceph_debugfs_client_cleanup(client);
|
||||
|
||||
/* unmount */
|
||||
ceph_osdc_stop(&client->osdc);
|
||||
ceph_monc_stop(&client->monc);
|
||||
ceph_messenger_fini(&client->msgr);
|
||||
|
||||
ceph_debugfs_client_cleanup(client);
|
||||
|
||||
ceph_destroy_options(client->options);
|
||||
|
||||
kfree(client);
|
||||
|
|
|
|||
Loading…
Reference in New Issue
Block a user