md: fix refcount problem on mddev when stopping array.
authorNeilBrown <neilb@suse.com>
Mon, 5 Dec 2016 05:40:50 +0000 (16:40 +1100)
committerGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Thu, 12 Jan 2017 10:39:35 +0000 (11:39 +0100)
commit e2342ca832726a840ca6bd196dd2cc073815b08a upstream.

md_open() gets a counted reference on an mddev using mddev_find().
If it ends up returning an error, it must drop this reference.

There are two error paths where the reference is not dropped.
One only happens if the process is signalled and an awkward time,
which is quite unlikely.
The other was introduced recently in commit af8d8e6f0.

Change the code to ensure the drop the reference when returning an error,
and make it harded to re-introduce this sort of bug in the future.

Reported-by: Marc Smith <marc.smith@mcc.edu>
Fixes: af8d8e6f0315 ("md: changes for MD_STILL_CLOSED flag")
Signed-off-by: NeilBrown <neilb@suse.com>
Acked-by: Guoqing Jiang <gqjiang@suse.com>
Signed-off-by: Shaohua Li <shli@fb.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
drivers/md/md.c

index 1a9131b6594c59b1daaab62e0b5db0a3afbdd47e..24925f2aa23539e8b870048629cf2f7373c6e5d9 100644 (file)
@@ -7092,7 +7092,8 @@ static int md_open(struct block_device *bdev, fmode_t mode)
 
        if (test_bit(MD_CLOSING, &mddev->flags)) {
                mutex_unlock(&mddev->open_mutex);
-               return -ENODEV;
+               err = -ENODEV;
+               goto out;
        }
 
        err = 0;
@@ -7101,6 +7102,8 @@ static int md_open(struct block_device *bdev, fmode_t mode)
 
        check_disk_change(bdev);
  out:
+       if (err)
+               mddev_put(mddev);
        return err;
 }