From: ZhangGuoDong <zhangguodong-UOlijcLmZ/[email protected]>
nfs41_free_stateid() takes a reference on the nfs_client before
allocating the FREE_STATEID calldata. If the calldata allocation fails,
the function returns -ENOMEM without dropping that reference.
The normal async RPC release path drops the reference from
nfs41_free_stateid_release(), but that path is not reached when calldata
allocation fails. Drop the nfs_client reference before returning the
allocation error.
Signed-off-by: ZhangGuoDong <zhangguodong-UOlijcLmZ/[email protected]>
---
fs/nfs/nfs4proc.c | 4 +++-
1 file changed, 3 insertions(+), 1 deletion(-)
diff --git a/fs/nfs/nfs4proc.c b/fs/nfs/nfs4proc.c
index c48281db3..b86818607 100644
--- a/fs/nfs/nfs4proc.c
+++ b/fs/nfs/nfs4proc.c
@@ -10380,8 +10380,10 @@ static int nfs41_free_stateid(struct nfs_server *server,
dprintk("NFS call free_stateid %p\n", stateid);
data = kmalloc_obj(*data);
- if (!data)
+ if (!data) {
+ nfs_put_client(clp);
return -ENOMEM;
+ }
data->server = server;
nfs4_stateid_copy(&data->args.stateid, stateid);
--
2.43.0
lmpx.com only provides a reader for public news (NNTP) servers. It is not
affiliated with the servers or forums shown here and is not responsible for
the content of articles, which is written by their respective authors.