summaryrefslogtreecommitdiff
path: root/fs/file.c
diff options
context:
space:
mode:
authorKirill Korotaev <dev@openvz.org>2006-07-12 09:03:05 -0700
committerLinus Torvalds <torvalds@g5.osdl.org>2006-07-12 12:52:54 -0700
commitd579091b4385e9386e244622d593fe064aa8e8e7 (patch)
treeb1fc0f3fef38d7580dc6bdf3b1842534126deda6 /fs/file.c
parentabf75a5033d4da7b8a7e92321d74021d1fcfb502 (diff)
downloadlinux-3.10-d579091b4385e9386e244622d593fe064aa8e8e7.tar.gz
linux-3.10-d579091b4385e9386e244622d593fe064aa8e8e7.tar.bz2
linux-3.10-d579091b4385e9386e244622d593fe064aa8e8e7.zip
[PATCH] fix fdset leakage
When found, it is obvious. nfds calculated when allocating fdsets is rewritten by calculation of size of fdtable, and when we are unlucky, we try to free fdsets of wrong size. Found due to OpenVZ resource management (User Beancounters). Signed-off-by: Alexey Kuznetsov <kuznet@ms2.inr.ac.ru> Signed-off-by: Kirill Korotaev <dev@openvz.org> Cc: <stable@kernel.org> Signed-off-by: Andrew Morton <akpm@osdl.org> Signed-off-by: Linus Torvalds <torvalds@osdl.org>
Diffstat (limited to 'fs/file.c')
-rw-r--r--fs/file.c4
1 files changed, 3 insertions, 1 deletions
diff --git a/fs/file.c b/fs/file.c
index 3f356086061..c8f1b0af8e0 100644
--- a/fs/file.c
+++ b/fs/file.c
@@ -273,11 +273,13 @@ static struct fdtable *alloc_fdtable(int nr)
} while (nfds <= nr);
new_fds = alloc_fd_array(nfds);
if (!new_fds)
- goto out;
+ goto out2;
fdt->fd = new_fds;
fdt->max_fds = nfds;
fdt->free_files = NULL;
return fdt;
+out2:
+ nfds = fdt->max_fdset;
out:
if (new_openset)
free_fdset(new_openset, nfds);