> Is that clear? Is there something I'm still missing? Basically if they are not invariant I don't see why it can't go around the loop, allocate the buffer, free it and then the next time find there is nothing there and thus double free. Either way if its patched the problem goes away so it's mostly for my own understanding. -- To unsubscribe from this list: send the line "unsubscribe ceph-devel" in the body of a message to majordomo@xxxxxxxxxxxxxxx More majordomo info at http://vger.kernel.org/majordomo-info.html