tcmu: fix cmd user after free

"Linux Kernel Mailing List" <[email protected]>
Newsgroups gmane.linux.kernel.commits.head
Message-ID <[email protected]>
Web:        https://git.kernel.org/torvalds/c/45dc488c0ee19ba5cba7a67be473aeaf88a7447e
Commit:     45dc488c0ee19ba5cba7a67be473aeaf88a7447e
Parent:     c82b59e7c3f81059b1d280e21028c7ac8451dd52
Refname:    refs/heads/master
Author:     Mike Christie <[email protected]>
AuthorDate: Mon Jan 15 14:37:59 2018 -0600
Committer:  Nicholas Bellinger <[email protected]>
CommitDate: Thu Jan 18 01:21:23 2018 -0800

    tcmu: fix cmd user after free
    
    If we are failing the command due to a qfull timeout we are
    also freeing the tcmu command, so we cannot access it later
    to get the se_cmd.
    
    Note: The clearing of cmd->se_cmd is not needed. We do not check
    it later for something like determining if the command was failed
    due to a timeout. As a result I am dropping it.
    
    Signed-off-by: Mike Christie <[email protected]>
    Signed-off-by: Nicholas Bellinger <[email protected]>
---
 drivers/target/target_core_user.c | 3 +--
 1 file changed, 1 insertion(+), 2 deletions(-)

diff --git a/drivers/target/target_core_user.c b/drivers/target/target_core_user.c
index 511168bec159..3096257a00d9 100644
--- a/drivers/target/target_core_user.c
+++ b/drivers/target/target_core_user.c
@@ -1152,6 +1152,7 @@ static int tcmu_check_expired_cmd(int id, void *p, void *data)
 		return 0;
 
 	is_running = list_empty(&cmd->cmdr_queue_entry);
+	se_cmd = cmd->se_cmd;
 
 	if (is_running) {
 		/*
@@ -1177,8 +1178,6 @@ static int tcmu_check_expired_cmd(int id, void *p, void *data)
 	pr_debug("Timing out cmd %u on dev %s that is %s.\n",
 		 id, udev->name, is_running ? "inflight" : "queued");
 
-	se_cmd = cmd->se_cmd;
-	cmd->se_cmd = NULL;
 	target_complete_cmd(se_cmd, scsi_status);
 	return 0;
 }
--
To unsubscribe from this list: send the line "unsubscribe git-commits-head" in
the body of a message to [email protected]
More majordomo info at  http://vger.kernel.org/majordomo-info.html
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.