Re: [PATCH 1/1] libceph: debugfs: remove client files before teardown

Viacheslav Dubeyko <[email protected]>
Newsgroups org.kernel.vger.ceph-devel
Message-ID <[email protected]>
On Mon, 2026-06-15 at 14:31 +0800, Ren Wei wrote:
> From: Douya Le <[email protected]>
> 
> ceph_destroy_client() tears down the monitor client before removing
> the per-client debugfs files. A concurrent read of the monmap debugfs
> file can enter monmap_show() after ceph_monc_stop() has freed
> monc->monmap, triggering a use-after-free.
> 
> Remove the debugfs files before stopping the OSD and monitor clients.
> debugfs_remove() drains active handlers and prevents new accesses, so
> the debugfs callbacks can no longer race the rest of client teardown.
> 
> Fixes: 76aa844d5b2f ("ceph: debugfs")
> Cc: [email protected]
> Reported-by: Yuan Tan <[email protected]>
> Reported-by: Zhengchuan Liang <[email protected]>
> Reported-by: Xin Liu <[email protected]>
> Assisted-by: Codex:gpt-5.4
> Signed-off-by: Douya Le <[email protected]>
> Signed-off-by: Ren Wei <[email protected]>
> ---
>  net/ceph/ceph_common.c | 4 ++--
>  1 file changed, 2 insertions(+), 2 deletions(-)
> 
> diff --git a/net/ceph/ceph_common.c b/net/ceph/ceph_common.c
> index 952121849..a797c7360 100644
> --- a/net/ceph/ceph_common.c
> +++ b/net/ceph/ceph_common.c
> @@ -762,13 +762,13 @@ void ceph_destroy_client(struct ceph_client
> *client)
>  
>  	atomic_set(&client->msgr.stopping, 1);
>  
> +	ceph_debugfs_client_cleanup(client);
> +
>  	/* unmount */
>  	ceph_osdc_stop(&client->osdc);
>  	ceph_monc_stop(&client->monc);
>  	ceph_messenger_fini(&client->msgr);
>  
> -	ceph_debugfs_client_cleanup(client);
> -
>  	ceph_destroy_options(client->options);
>  
>  	kfree(client);

Makes sense to me.

Reviewed-by: Viacheslav Dubeyko <[email protected]>

Thanks,
Slava.
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.