From: Jiri Pirko <redacted>
In atm_tc_destroy, the flow qdisc filter chains are destroyed. However
the main chain is not. So fix this memory and reference leak.
Signed-off-by: Jiri Pirko <redacted>
---
Sending this for net-next because this is present at least from the
beginning of git epoch. Feel free to apply on -net, however I don't have
"Fixes: " :)
---
net/sched/sch_atm.c | 3 +++
1 file changed, 3 insertions(+)
diff --git a/net/sched/sch_atm.c b/net/sched/sch_atm.c
index 2209c2d..56421da 100644
--- a/net/sched/sch_atm.c
+++ b/net/sched/sch_atm.c
@@ -560,6 +560,9 @@ static void atm_tc_destroy(struct Qdisc *sch)
struct atm_flow_data *flow, *tmp;
pr_debug("atm_tc_destroy(sch %p,[qdisc %p])\n", sch, p);
+
+ tcf_destroy_chain(&p->link.filter_list);
+
list_for_each_entry(flow, &p->flows, list)
tcf_destroy_chain(&flow->filter_list);
--
2.7.4
On Fri, Mar 24, 2017 at 6:39 AM, Jiri Pirko [off-list ref] wrote:
From: Jiri Pirko <redacted>
In atm_tc_destroy, the flow qdisc filter chains are destroyed. However
the main chain is not. So fix this memory and reference leak.
Are you sure? 'link' is on the 'flows' already according
to this comment:
struct atm_qdisc_data {
struct atm_flow_data link; /* unclassified skbs go here */
struct list_head flows; /* NB: "link" is also on this
list */
struct tasklet_struct task; /* dequeue tasklet */
};
Fri, Mar 24, 2017 at 06:46:55PM CET, xiyou.wangcong@gmail.com wrote:
On Fri, Mar 24, 2017 at 6:39 AM, Jiri Pirko [off-list ref] wrote:
quoted
From: Jiri Pirko <redacted>
In atm_tc_destroy, the flow qdisc filter chains are destroyed. However
the main chain is not. So fix this memory and reference leak.
Are you sure? 'link' is on the 'flows' already according
Ah. You are correct. Scratch this. Thanks.
Btw, I think that in atm_tc_change:
list_add(&flow->list, &p->link.list);
should be:
list_add(&flow->list, &p->flows);
to this comment:
struct atm_qdisc_data {
struct atm_flow_data link; /* unclassified skbs go here */
struct list_head flows; /* NB: "link" is also on this
list */
struct tasklet_struct task; /* dequeue tasklet */
};