fuse: prevent fuse_put_request on invalid pointer
authorAnand V. Avati <avati@gluster.com>
Thu, 22 Oct 2009 13:24:52 +0000 (06:24 -0700)
committerMiklos Szeredi <mszeredi@suse.cz>
Wed, 4 Nov 2009 09:24:50 +0000 (10:24 +0100)
fuse_direct_io() has a loop where requests are allocated in each
iteration. if allocation fails, the loop is broken out and follows
into an unconditional fuse_put_request() on that invalid pointer.

Signed-off-by: Anand V. Avati <avati@gluster.com>
Signed-off-by: Miklos Szeredi <mszeredi@suse.cz>
Cc: stable@kernel.org
fs/fuse/file.c

index a3492f7..5887a63 100644 (file)
@@ -1063,7 +1063,8 @@ ssize_t fuse_direct_io(struct file *file, const char __user *buf,
                                break;
                }
        }
-       fuse_put_request(fc, req);
+       if (!IS_ERR(req))
+               fuse_put_request(fc, req);
        if (res > 0)
                *ppos = pos;