Page MenuHomeFreeBSD

gve: fix double free on ring allocation failure
ClosedPublic

Authored by jtranoleary_google.com on Mon, Oct 5, 10:02 PM.
Tags
None
Referenced Files
F175358517: D60386.id188964.diff
Sat, Oct 10, 6:42 AM
F175330406: D60386.diff
Sat, Oct 10, 1:02 AM
F175278593: D60386.diff
Fri, Oct 9, 4:07 PM
Unknown Object (File)
Fri, Oct 9, 6:48 AM
Unknown Object (File)
Thu, Oct 8, 11:29 AM
Unknown Object (File)
Thu, Oct 8, 9:53 AM
Unknown Object (File)
Thu, Oct 8, 8:35 AM
Unknown Object (File)
Thu, Oct 8, 8:18 AM

Details

Summary

When gve_alloc_rings fails (such as when failing to acquire MSI-X
vectors or during partial ring allocation), ring cleanup can be
executed multiple times across nested error paths (e.g. within
gve_alloc_rings abort and gve_attach abort).

Because gve_free_counters invoked counter_u64_free without nullifying
the pointer in the stats array, repeated invocation caused a double-free
panic when freeing the same counter references.

Check for non-NULL before freeing and nullify each counter pointer
upon release in gve_free_counters.

Signed-off-by: Jasper Tran O'Leary <jtranoleary@google.com>

Diff Detail

Repository
rG FreeBSD src repository
Lint
Lint Skipped
Unit
Tests Skipped
Build Status
Buildable 77742
Build 74625: arc lint + arc unit