Hi Hannes, On 11/30/11 23:49, Mike Snitzer wrote: > On Wed, Nov 30 2011 at 9:25am -0500, > Hannes Reinecke <hare@xxxxxxx> wrote: > >> When requeing a request we should be clearing the map_context >> pointer, otherwise we might access an invalid memory location. Could you elaborate on the mechanism how the map_context->ptr (= mpio) is accessed after freeing it? mpio is known to be non-NULL where it is used. So clearing the pointer should not make any difference in logic. If this is a preventive change so that we can see NULL dereference instead of random invalid access if anything happens, it should be noted in the patch description and in the code. Otherwise, somebody looking at the code/change in future might be confused: "why we have to clear this pointer?" And there are other places where mpio is freed. (E.g. in dispatch_queued_ios() in dm-mpath.c) Don't we need the same change there? >> Cc: Mike Snitzer <snitzer@xxxxxxxxxx> >> Signed-off-by: Hannes Reinecke <hare@xxxxxxx> >> Tested-by: Heiko Carstens <heiko.carstens@xxxxxxxxxx> > > Acked-by: Mike Snitzer <snitzer@xxxxxxxxxx> > > Should Cc: stable too. > > (I was thinking Alasdair would pick this up for 3.2 seeing as it is a > change to dm-mpath.c. Alasdair, James.. I'll let you guys decide) -- Jun'ichi Nomura, NEC Corporation -- To unsubscribe from this list: send the line "unsubscribe linux-scsi" in the body of a message to majordomo@xxxxxxxxxxxxxxx More majordomo info at http://vger.kernel.org/majordomo-info.html