]> git.ipfire.org Git - thirdparty/kernel/linux.git/commitdiff
md/raid1: fix memory leak in raid1_run() if no active rdev
authorZheng Qixing <zhengqixing@huawei.com>
Sat, 15 Feb 2025 02:01:37 +0000 (10:01 +0800)
committerYu Kuai <yukuai@kernel.org>
Sat, 15 Feb 2025 11:45:58 +0000 (19:45 +0800)
When `raid1_set_limits()` fails or when the array has no active
`rdev`, the allocated memory for `conf` is not properly freed.

Add raid1_free() call to properly free the conf in error path.

Fixes: 799af947ed13 ("md/raid1: don't free conf on raid0_run failure")
Signed-off-by: Zheng Qixing <zhengqixing@huawei.com>
Link: https://lore.kernel.org/linux-raid/20250215020137.3703757-1-zhengqixing@huaweicloud.com
Singed-off-by: Yu Kuai <yukuai3@huawei.com>
drivers/md/raid1.c

index 9d57a88dbd261184194545e3565fa6e576396474..a87eb9a3b016846d64e139052f7911d9f41fca24 100644 (file)
@@ -45,6 +45,7 @@
 
 static void allow_barrier(struct r1conf *conf, sector_t sector_nr);
 static void lower_barrier(struct r1conf *conf, sector_t sector_nr);
+static void raid1_free(struct mddev *mddev, void *priv);
 
 #define RAID_1_10_NAME "raid1"
 #include "raid1-10.c"
@@ -3258,8 +3259,11 @@ static int raid1_run(struct mddev *mddev)
 
        if (!mddev_is_dm(mddev)) {
                ret = raid1_set_limits(mddev);
-               if (ret)
+               if (ret) {
+                       if (!mddev->private)
+                               raid1_free(mddev, conf);
                        return ret;
+               }
        }
 
        mddev->degraded = 0;
@@ -3273,6 +3277,8 @@ static int raid1_run(struct mddev *mddev)
         */
        if (conf->raid_disks - mddev->degraded < 1) {
                md_unregister_thread(mddev, &conf->thread);
+               if (!mddev->private)
+                       raid1_free(mddev, conf);
                return -EINVAL;
        }