浏览代码

Btrfs: fix a double free on pending snapshots in error handling

When creating a snapshot, failing to commit a transaction can end up
with aborting the transaction, following by doing a cleanup for it, where
we'll free all snapshots pending to disk.

So we check it and avoid double free on pending snapshots.

Signed-off-by: Liu Bo <bo.li.liu@oracle.com>
Signed-off-by: Chris Mason <chris.mason@fusionio.com>
Liu Bo 12 年之前
父节点
当前提交
109f2365f1
共有 1 个文件被更改,包括 5 次插入1 次删除
  1. 5 1
      fs/btrfs/ioctl.c

+ 5 - 1
fs/btrfs/ioctl.c

@@ -571,8 +571,12 @@ static int create_snapshot(struct btrfs_root *root, struct dentry *dentry,
 		ret = btrfs_commit_transaction(trans,
 		ret = btrfs_commit_transaction(trans,
 					       root->fs_info->extent_root);
 					       root->fs_info->extent_root);
 	}
 	}
-	if (ret)
+	if (ret) {
+		/* cleanup_transaction has freed this for us */
+		if (trans->aborted)
+			pending_snapshot = NULL;
 		goto fail;
 		goto fail;
+	}
 
 
 	ret = pending_snapshot->error;
 	ret = pending_snapshot->error;
 	if (ret)
 	if (ret)