Skip site navigation (1)Skip section navigation (2)
Date:      Wed, 15 Oct 2014 22:09:05 +0300
From:      Alexander Motin <mav@FreeBSD.org>
To:        NGie Cooper <yaneurabeya@gmail.com>
Cc:        "svn-src-head@freebsd.org" <svn-src-head@freebsd.org>, "svn-src-all@freebsd.org" <svn-src-all@freebsd.org>, "src-committers@freebsd.org" <src-committers@freebsd.org>
Subject:   Re: svn commit: r273143 - head/sys/kern
Message-ID:  <543EC651.1060903@FreeBSD.org>
In-Reply-To: <CAGHfRMCF030buMAVgpQxXQ8SvPMB%2BFZaDHsdKXP7GaYD7DG1cw@mail.gmail.com>
References:  <201410151836.s9FIaZBU090173@svn.freebsd.org> <CAGHfRMCF030buMAVgpQxXQ8SvPMB%2BFZaDHsdKXP7GaYD7DG1cw@mail.gmail.com>

next in thread | previous in thread | raw e-mail | index | archive | help
On 15.10.2014 21:48, NGie Cooper wrote:
> On Wed, Oct 15, 2014 at 11:36 AM, Alexander Motin <mav@freebsd.org> wrote:
>> Author: mav
>> Date: Wed Oct 15 18:36:34 2014
>> New Revision: 273143
>> URL: https://svnweb.freebsd.org/changeset/base/273143
>>
>> Log:
>>   Remove setting BIO_DONE flag for BIOs that have done() method.
>>
>>   This fixes use-after-free, caused by geom_disk, completing same BIO twice
>>   to save extra allocation, and getting BIO_DONE set after the first.
>>
>>   MFC after:    1 week
> 
> Hi mav,
>     This bug is present in stable/10 as well. Could you please merge
> it back to releng/10.1 before the release is cut?

I'll send request to re@ after required minimal three days. Though this
code was committed to head about a year ago, so not sure how big is this
problem.

-- 
Alexander Motin



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?543EC651.1060903>