Patchwork ibmveth: Fix leak when recycling skb and hypervisor returns error

login
register
mail settings
Submitter Anton Blanchard
Date Aug. 25, 2011, 12:55 a.m.
Message ID <20110825105520.5ba7ae90@kryten>
Download mbox | patch
Permalink /patch/111438/
State Accepted
Delegated to: David Miller
Headers show

Comments

Anton Blanchard - Aug. 25, 2011, 12:55 a.m.
Hi Dave,

> Please generate this patch against Linus's tree, instead of -next

Sure, here it is.

Anton

--

If h_add_logical_lan_buffer returns an error we need to free
the skb.

Signed-off-by: Anton Blanchard <anton@samba.org>
Cc: stable <stable@kernel.org>
---

--
To unsubscribe from this list: send the line "unsubscribe netdev" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
David Miller - Aug. 25, 2011, 12:56 a.m.
From: Anton Blanchard <anton@samba.org>
Date: Thu, 25 Aug 2011 10:55:20 +1000

>> Please generate this patch against Linus's tree, instead of -next
> 
> Sure, here it is.

Applied, thanks.
--
To unsubscribe from this list: send the line "unsubscribe netdev" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html

Patch

Index: linux-2.6-work/drivers/net/ibmveth.c
===================================================================
--- linux-2.6-work.orig/drivers/net/ibmveth.c	2011-07-31 20:45:29.729141545 +1000
+++ linux-2.6-work/drivers/net/ibmveth.c	2011-08-25 10:49:04.200718870 +1000
@@ -395,7 +395,7 @@  static inline struct sk_buff *ibmveth_rx
 }
 
 /* recycle the current buffer on the rx queue */
-static void ibmveth_rxq_recycle_buffer(struct ibmveth_adapter *adapter)
+static int ibmveth_rxq_recycle_buffer(struct ibmveth_adapter *adapter)
 {
 	u32 q_index = adapter->rx_queue.index;
 	u64 correlator = adapter->rx_queue.queue_addr[q_index].correlator;
@@ -403,6 +403,7 @@  static void ibmveth_rxq_recycle_buffer(s
 	unsigned int index = correlator & 0xffffffffUL;
 	union ibmveth_buf_desc desc;
 	unsigned long lpar_rc;
+	int ret = 1;
 
 	BUG_ON(pool >= IBMVETH_NUM_BUFF_POOLS);
 	BUG_ON(index >= adapter->rx_buff_pool[pool].size);
@@ -410,7 +411,7 @@  static void ibmveth_rxq_recycle_buffer(s
 	if (!adapter->rx_buff_pool[pool].active) {
 		ibmveth_rxq_harvest_buffer(adapter);
 		ibmveth_free_buffer_pool(adapter, &adapter->rx_buff_pool[pool]);
-		return;
+		goto out;
 	}
 
 	desc.fields.flags_len = IBMVETH_BUF_VALID |
@@ -423,12 +424,16 @@  static void ibmveth_rxq_recycle_buffer(s
 		netdev_dbg(adapter->netdev, "h_add_logical_lan_buffer failed "
 			   "during recycle rc=%ld", lpar_rc);
 		ibmveth_remove_buffer_from_pool(adapter, adapter->rx_queue.queue_addr[adapter->rx_queue.index].correlator);
+		ret = 0;
 	}
 
 	if (++adapter->rx_queue.index == adapter->rx_queue.num_slots) {
 		adapter->rx_queue.index = 0;
 		adapter->rx_queue.toggle = !adapter->rx_queue.toggle;
 	}
+
+out:
+	return ret;
 }
 
 static void ibmveth_rxq_harvest_buffer(struct ibmveth_adapter *adapter)
@@ -1084,8 +1089,9 @@  restart_poll:
 				if (rx_flush)
 					ibmveth_flush_buffer(skb->data,
 						length + offset);
+				if (!ibmveth_rxq_recycle_buffer(adapter))
+					kfree_skb(skb);
 				skb = new_skb;
-				ibmveth_rxq_recycle_buffer(adapter);
 			} else {
 				ibmveth_rxq_harvest_buffer(adapter);
 				skb_reserve(skb, offset);