From: Jens Axboe Date: Fri, 20 Jul 2007 13:21:36 +0000 (+0200) Subject: splice: fix double page unlock X-Git-Tag: v2.6.22.2~52 X-Git-Url: http://git.ipfire.org/gitweb.cgi?a=commitdiff_plain;h=36e1ed699210fd0173dfe0a8b2cde8a6b648ba3f;p=thirdparty%2Fkernel%2Fstable.git splice: fix double page unlock If add_to_page_cache_lru() fails, the page will not be locked. But splice jumps to an error path that does a page release and unlock, causing a BUG() in unlock_page(). Fix this by adding one more label that just releases the page. This bug was actually triggered on EL5 by gurudas pai using fio. Signed-off-by: Jens Axboe Signed-off-by: Greg Kroah-Hartman --- diff --git a/fs/splice.c b/fs/splice.c index e7d7080de2f97..d3c6668bdbdd5 100644 --- a/fs/splice.c +++ b/fs/splice.c @@ -601,7 +601,7 @@ find_page: ret = add_to_page_cache_lru(page, mapping, index, GFP_KERNEL); if (unlikely(ret)) - goto out; + goto out_release; } ret = mapping->a_ops->prepare_write(file, page, offset, offset+this_len); @@ -657,8 +657,9 @@ find_page: */ mark_page_accessed(page); out: - page_cache_release(page); unlock_page(page); +out_release: + page_cache_release(page); out_ret: return ret; }