summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorDouya Le <ldy3087146292@gmail.com>2026-06-15 14:31:06 +0800
committerIlya Dryomov <idryomov@gmail.com>2026-07-23 20:29:41 +0200
commite4c804726c4afce3ba648b982d564f6af2cfa328 (patch)
treedfc52088fcf8d9b05e910bb8127b15f3814f1fbd
parentd3c32939fa0e3ee9b883b9a0fd1972c5c444e3d0 (diff)
downloadlinux-e4c804726c4afce3ba648b982d564f6af2cfa328.tar.gz
linux-e4c804726c4afce3ba648b982d564f6af2cfa328.tar.bz2
linux-e4c804726c4afce3ba648b982d564f6af2cfa328.zip
libceph: remove debugfs files before client teardown
ceph_destroy_client() tears down the monitor client before removing the per-client debugfs files. A concurrent read of the monmap debugfs file can enter monmap_show() after ceph_monc_stop() has freed monc->monmap, triggering a use-after-free. Remove the debugfs files before stopping the OSD and monitor clients. debugfs_remove() drains active handlers and prevents new accesses, so the debugfs callbacks can no longer race the rest of client teardown. Cc: stable@vger.kernel.org Fixes: 76aa844d5b2f ("ceph: debugfs") Reported-by: Yuan Tan <yuantan098@gmail.com> Reported-by: Zhengchuan Liang <zcliangcn@gmail.com> Reported-by: Xin Liu <bird@lzu.edu.cn> Assisted-by: Codex:GPT-5.4 Signed-off-by: Douya Le <ldy3087146292@gmail.com> Signed-off-by: Ren Wei <n05ec@lzu.edu.cn> Reviewed-by: Viacheslav Dubeyko <slava@dubeyko.com> Signed-off-by: Ilya Dryomov <idryomov@gmail.com>
-rw-r--r--net/ceph/ceph_common.c4
1 files changed, 2 insertions, 2 deletions
diff --git a/net/ceph/ceph_common.c b/net/ceph/ceph_common.c
index 952121849180..a797c7360e3c 100644
--- a/net/ceph/ceph_common.c
+++ b/net/ceph/ceph_common.c
@@ -762,13 +762,13 @@ void ceph_destroy_client(struct ceph_client *client)
atomic_set(&client->msgr.stopping, 1);
+ ceph_debugfs_client_cleanup(client);
+
/* unmount */
ceph_osdc_stop(&client->osdc);
ceph_monc_stop(&client->monc);
ceph_messenger_fini(&client->msgr);
- ceph_debugfs_client_cleanup(client);
-
ceph_destroy_options(client->options);
kfree(client);