Page MenuHomeFreeBSD

gve: fix double free on ring allocation failure
AcceptedPublic

Authored by jtranoleary_google.com on Mon, Oct 5, 10:02 PM.

Details

Reviewers
markj
adrian
Group Reviewers
network
Summary

When gve_alloc_rings fails (such as when failing to acquire MSI-X
vectors or during partial ring allocation), ring cleanup can be
executed multiple times across nested error paths (e.g. within
gve_alloc_rings abort and gve_attach abort).

Because gve_free_counters invoked counter_u64_free without nullifying
the pointer in the stats array, repeated invocation caused a double-free
panic when freeing the same counter references.

Check for non-NULL before freeing and nullify each counter pointer
upon release in gve_free_counters.

Signed-off-by: Jasper Tran O'Leary <jtranoleary@google.com>

Diff Detail

Repository
rG FreeBSD src repository
Lint
Lint Skipped
Unit
Tests Skipped
Build Status
Buildable 77742
Build 74625: arc lint + arc unit