Thread (3 messages) flat view 3 messages, 2 authors, 2012-03-21

Re: [PATCH] ath9k: fix a memory leak in ath_rx_tasklet()

From: John W. Linville <hidden>
Date: 2012-03-16 14:17:12

On Thu, Mar 15, 2012 at 01:43:29PM -0700, Eric Dumazet wrote:
commit 0d95521ea7 (ath9k: use split rx buffers to get rid of order-1 skb
allocations) added in memory leak in error path.

sc->rx.frag should be cleared after the pskb_expand_head() call, or else
we jump to requeue_drop_frag and leak an skb.

Signed-off-by: Eric Dumazet <redacted>
Cc: Jouni Malinen <redacted>
Cc: Felix Fietkau <redacted>
Cc: John W. Linville <redacted>
Cc: Trond Wuellner <redacted>
Cc: Grant Grundler <redacted>
Cc: Paul Stewart <redacted>
Cc: David Miller <davem@davemloft.net>
Acked-by: John W. Linville <redacted>

Dave, will you pick this up yourself?  Or should I take it around the bend?

John
quoted hunk ↗ jump to hunk
---
 drivers/net/wireless/ath/ath9k/recv.c |    4 ++--
 1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/drivers/net/wireless/ath/ath9k/recv.c b/drivers/net/wireless/ath/ath9k/recv.c
index 7e1a91a..e74fc99 100644
--- a/drivers/net/wireless/ath/ath9k/recv.c
+++ b/drivers/net/wireless/ath/ath9k/recv.c
@@ -1917,13 +1917,13 @@ int ath_rx_tasklet(struct ath_softc *sc, int flush, bool hp)
 		if (sc->rx.frag) {
 			int space = skb->len - skb_tailroom(hdr_skb);
 
-			sc->rx.frag = NULL;
-
 			if (pskb_expand_head(hdr_skb, 0, space, GFP_ATOMIC) < 0) {
 				dev_kfree_skb(skb);
 				goto requeue_drop_frag;
 			}
 
+			sc->rx.frag = NULL;
+
 			skb_copy_from_linear_data(skb, skb_put(hdr_skb, skb->len),
 						  skb->len);
 			dev_kfree_skb_any(skb);

-- 
John W. Linville		Someday the world will need a hero, and you
linville@tuxdriver.com			might be all we have.  Be ready.
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help