From: Jeremy Allison Date: Fri, 13 Mar 2020 17:40:19 +0000 (-0700) Subject: Revert "s3: VFS: vfs_default. Protect vfs_pread_done() from accessing a freed req... X-Git-Tag: ldb-2.2.0~1407 X-Git-Url: http://git.ipfire.org/cgi-bin/gitweb.cgi?a=commitdiff_plain;h=ce0235be27693b76af8f01e25a25415797b590f7;p=thirdparty%2Fsamba.git Revert "s3: VFS: vfs_default. Protect vfs_pread_done() from accessing a freed req pointer." This reverts commit b9ad06079fe362385cc4c77f8e8d54f5f74d6db6. Now we wait for all aio to finish on all SHUTDOWN_CLOSE cases, this is no longer needed. BUG: https://bugzilla.samba.org/show_bug.cgi?id=14301 Signed-off-by: Jeremy Allison Reviewed-by: Ralph Boehme --- diff --git a/source3/modules/vfs_default.c b/source3/modules/vfs_default.c index 21bc9c7adf7..b8c36180b7c 100644 --- a/source3/modules/vfs_default.c +++ b/source3/modules/vfs_default.c @@ -863,15 +863,6 @@ static void vfs_pread_do(void *private_data) static int vfs_pread_state_destructor(struct vfswrap_pread_state *state) { - /* - * This destructor only gets called if the request is still - * in flight, which is why we deny it by returning -1. We - * also set the req pointer to NULL so the _done function - * can detect the caller doesn't want the result anymore. - * - * Forcing the fsp closed by a SHUTDOWN_CLOSE can cause this. - */ - state->req = NULL; return -1; } @@ -886,17 +877,6 @@ static void vfs_pread_done(struct tevent_req *subreq) TALLOC_FREE(subreq); SMBPROFILE_BYTES_ASYNC_END(state->profile_bytes); talloc_set_destructor(state, NULL); - if (req == NULL) { - /* - * We were shutdown closed in flight. No one - * wants the result, and state has been reparented - * to the NULL context, so just free it so we - * don't leak memory. - */ - DBG_NOTICE("pread request abandoned in flight\n"); - TALLOC_FREE(state); - return; - } if (ret != 0) { if (ret != EAGAIN) { tevent_req_error(req, ret);