Re: [tabled patch 1/1] running completions over disposed cli
Jeff Garzik <[email protected]> Sat, 15 May 2010 16:43:44 -0400
| Newsgroups | org.kernel.vger.hail-devel |
|---|---|
| Message-ID | <[email protected]> |
On 05/15/2010 03:17 PM, Pete Zaitcev wrote: > Miracluously this never actually crashed on me, but I added unrelated > debugging printout into the dispatch routine and it printed weird > values. Then it dawned on me that a state change function may dispose > of the struct cli, in which case cli_write_run_compl is use-after-free. > > It may seem that checking if the old state was evt_dispose before > running cli_write_run_compl is an expedient fix, but that does not > work, because we do not always dispose of the cli in such case. > If the cli to be disposed still has anything in the queue, we > need to continue to deliver events, and for that we have to > run outstanding completions. > > So, we go a longer route and re-hook the list of completions > to a per-server global instead of a client. The patch is straight- > forward. The only thing we need to be careful is to make sure > that no outstanding completions are left in the queue before > freeing a client struct. This is ensured by force-running completions. > > One other necessary change was to add a back poiter from a completion > to the current client. This is because one caller needed the client > pointer (object_get_more). > > Signed-off-by: Pete Zaitcev<[email protected]> applied