1 jbd2: don't leak memory if setting up journal fails
3 From: Eric Biggers <ebiggers@google.com>
5 In journal_init_common(), if we failed to allocate the j_wbuf array, or
6 if we failed to create the buffer_head for the journal superblock, we
7 leaked the memory allocated for the revocation tables. Fix this.
9 Cc: stable@vger.kernel.org # 4.9
10 Fixes: f0c9fd5458bacf7b12a9a579a727dc740cbe047e
11 Signed-off-by: Eric Biggers <ebiggers@google.com>
12 Signed-off-by: Theodore Ts'o <tytso@mit.edu>
13 Reviewed-by: Jan Kara <jack@suse.cz>
15 fs/jbd2/journal.c | 22 +++++++++++-----------
16 fs/jbd2/revoke.c | 1 +
17 2 files changed, 12 insertions(+), 11 deletions(-)
19 diff --git a/fs/jbd2/journal.c b/fs/jbd2/journal.c
20 index a1a359bfcc9c..5adc2fb62b0f 100644
21 --- a/fs/jbd2/journal.c
22 +++ b/fs/jbd2/journal.c
23 @@ -1125,10 +1125,8 @@ static journal_t *journal_init_common(struct block_device *bdev,
25 /* Set up a default-sized revoke table for the new mount. */
26 err = jbd2_journal_init_revoke(journal, JOURNAL_REVOKE_DEFAULT_HASH);
34 spin_lock_init(&journal->j_history_lock);
36 @@ -1145,23 +1143,25 @@ static journal_t *journal_init_common(struct block_device *bdev,
37 journal->j_wbufsize = n;
38 journal->j_wbuf = kmalloc_array(n, sizeof(struct buffer_head *),
40 - if (!journal->j_wbuf) {
44 + if (!journal->j_wbuf)
47 bh = getblk_unmovable(journal->j_dev, start, journal->j_blocksize);
49 pr_err("%s: Cannot get buffer for journal superblock\n",
51 - kfree(journal->j_wbuf);
56 journal->j_sb_buffer = bh;
57 journal->j_superblock = (journal_superblock_t *)bh->b_data;
62 + kfree(journal->j_wbuf);
63 + jbd2_journal_destroy_revoke(journal);
68 /* jbd2_journal_init_dev and jbd2_journal_init_inode:
69 diff --git a/fs/jbd2/revoke.c b/fs/jbd2/revoke.c
70 index cfc38b552118..f9aefcda5854 100644
71 --- a/fs/jbd2/revoke.c
72 +++ b/fs/jbd2/revoke.c
73 @@ -280,6 +280,7 @@ int jbd2_journal_init_revoke(journal_t *journal, int hash_size)
76 jbd2_journal_destroy_revoke_table(journal->j_revoke_table[0]);
77 + journal->j_revoke_table[0] = NULL;