NFSv4.2: fix error handling in nfs42_proc_getxattr
[ Upstream commit4e3733fd2b
] There is a slight issue with error handling code inside nfs42_proc_getxattr(). If page allocating loop fails then we free the failing page array element which is NULL but __free_page() can't deal with NULL args. Found by Linux Verification Center (linuxtesting.org). Fixes:a1f26739cc
("NFSv4.2: improve page handling for GETXATTR") Signed-off-by: Fedor Pchelkin <pchelkin@ispras.ru> Reviewed-by: Benjamin Coddington <bcodding@redhat.com> Signed-off-by: Trond Myklebust <trond.myklebust@hammerspace.com> Signed-off-by: Sasha Levin <sashal@kernel.org>
This commit is contained in:
committed by
Greg Kroah-Hartman
parent
5de0a325c4
commit
323b830eeb
@ -1339,7 +1339,6 @@ ssize_t nfs42_proc_getxattr(struct inode *inode, const char *name,
|
|||||||
for (i = 0; i < np; i++) {
|
for (i = 0; i < np; i++) {
|
||||||
pages[i] = alloc_page(GFP_KERNEL);
|
pages[i] = alloc_page(GFP_KERNEL);
|
||||||
if (!pages[i]) {
|
if (!pages[i]) {
|
||||||
np = i + 1;
|
|
||||||
err = -ENOMEM;
|
err = -ENOMEM;
|
||||||
goto out;
|
goto out;
|
||||||
}
|
}
|
||||||
@ -1363,8 +1362,8 @@ ssize_t nfs42_proc_getxattr(struct inode *inode, const char *name,
|
|||||||
} while (exception.retry);
|
} while (exception.retry);
|
||||||
|
|
||||||
out:
|
out:
|
||||||
while (--np >= 0)
|
while (--i >= 0)
|
||||||
__free_page(pages[np]);
|
__free_page(pages[i]);
|
||||||
kfree(pages);
|
kfree(pages);
|
||||||
|
|
||||||
return err;
|
return err;
|
||||||
|
Reference in New Issue
Block a user