[XFS] Fix use-after-free with log and quotas
authorLachlan McIlroy <lachlan@sgi.com>
Thu, 30 Oct 2008 05:53:25 +0000 (16:53 +1100)
committerLachlan McIlroy <lachlan@redback.melbourne.sgi.com>
Mon, 10 Nov 2008 06:43:23 +0000 (17:43 +1100)
commit9ccbece546cf836f67f6d9bb4bf2f70f7476cb2c
tree86b6b97537c46eb70555fbe8ffdc16e1ec8b69d0
parent75fa67706cce5272bcfc51ed646f2da21f3bdb6e
[XFS] Fix use-after-free with log and quotas

Destroying the quota stuff on unmount can access the log - ie
XFS_QM_DONE() ends up in xfs_dqunlock() which calls
xfs_trans_unlocked_item() and then xfs_log_move_tail(). By this time the
log has already been destroyed. Just move the cleanup of the quota code
earlier in xfs_unmountfs() before the call to xfs_log_unmount(). Moving
XFS_QM_DONE() up near XFS_QM_DQPURGEALL() seems like a good spot.

SGI-PV: 987086

SGI-Modid: xfs-linux-melb:xfs-kern:32148a

Signed-off-by: Lachlan McIlroy <lachlan@sgi.com>
Signed-off-by: Christoph Hellwig <hch@infradead.org>
Signed-off-by: Peter Leckie <pleckie@sgi.com>
fs/xfs/xfs_mount.c