summaryrefslogtreecommitdiffstats
path: root/sys/cddl/contrib/opensolaris/uts/common/fs/zfs/vdev_geom.c
diff options
context:
space:
mode:
authormav <mav@FreeBSD.org>2016-10-28 18:22:00 +0000
committermav <mav@FreeBSD.org>2016-10-28 18:22:00 +0000
commita47105ffc325fb82a5ff322d83c2459cbe1a6ab5 (patch)
treed2e8fce635ba5c3de4ba5b35abe1a5fea6f1933b /sys/cddl/contrib/opensolaris/uts/common/fs/zfs/vdev_geom.c
parentd85916f780badddcded9eb4b29c6e1d242d9884c (diff)
downloadFreeBSD-src-a47105ffc325fb82a5ff322d83c2459cbe1a6ab5.zip
FreeBSD-src-a47105ffc325fb82a5ff322d83c2459cbe1a6ab5.tar.gz
MFC r298814 (by asomers): Fix a use-after-free when "zpool import" fails
clear vd->vdev_tsd in vdev_geom_close_locked instead of vdev_geom_detach. In the latter function, it would fail to happen in certain circumstances where cp->private was unset. Ideally, the latter should never happen, but it can happen when vdev open fails, or where spares are involved.
Diffstat (limited to 'sys/cddl/contrib/opensolaris/uts/common/fs/zfs/vdev_geom.c')
-rw-r--r--sys/cddl/contrib/opensolaris/uts/common/fs/zfs/vdev_geom.c6
1 files changed, 2 insertions, 4 deletions
diff --git a/sys/cddl/contrib/opensolaris/uts/common/fs/zfs/vdev_geom.c b/sys/cddl/contrib/opensolaris/uts/common/fs/zfs/vdev_geom.c
index 08fd5e7..8c88745 100644
--- a/sys/cddl/contrib/opensolaris/uts/common/fs/zfs/vdev_geom.c
+++ b/sys/cddl/contrib/opensolaris/uts/common/fs/zfs/vdev_geom.c
@@ -278,10 +278,6 @@ vdev_geom_detach(struct g_consumer *cp, boolean_t open_for_read)
cp->provider && cp->provider->name ? cp->provider->name : "NULL");
vd = cp->private;
- if (vd != NULL) {
- vd->vdev_tsd = NULL;
- vd->vdev_delayed_close = B_FALSE;
- }
cp->private = NULL;
gp = cp->geom;
@@ -313,6 +309,8 @@ vdev_geom_close_locked(vdev_t *vd)
g_topology_assert();
cp = vd->vdev_tsd;
+ vd->vdev_tsd = NULL;
+ vd->vdev_delayed_close = B_FALSE;
if (cp == NULL)
return;
OpenPOWER on IntegriCloud