• Mike Snitzer's avatar
    dm mpath: fix attached_handler_name leak and dangling hw_handler_name pointer · b592211c
    Mike Snitzer authored
    Commit e8f74a0f ("dm mpath: eliminate need to use
    scsi_device_from_queue") introduced 2 regressions:
    1) memory leak occurs if attached_handler_name is not assigned to
       m->hw_handler_name
    2) m->hw_handler_name can become a dangling pointer if the
       RETAIN_ATTACHED_HW_HANDLER flag is set and scsi_dh_attach() returns
       -EBUSY.
    
    Fix both of these by clearing 'attached_handler_name' pointer passed to
    setup_scsi_dh() after it is assigned to m->hw_handler_name.  And if
    setup_scsi_dh() doesn't consume 'attached_handler_name' parse_path()
    will kfree() it.
    
    Fixes: e8f74a0f ("dm mpath: eliminate need to use scsi_device_from_queue")
    Cc: stable@vger.kernel.org # 4.16+
    Reported-by: default avatarBart Van Assche <bvanassche@acm.org>
    Signed-off-by: default avatarMike Snitzer <snitzer@redhat.com>
    b592211c
dm-mpath.c 50.5 KB