Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.kernel > #1621123
| From | Jiri Olsa <jolsa@redhat.com> |
|---|---|
| Newsgroups | linux.kernel |
| Subject | Re: [PATCH v2] perf: fix double free at function perf_hpp__reset_output_field |
| Date | 2017-04-11 12:30 +0200 |
| Message-ID | <tv13Y-5FJ-7@gated-at.bofh.it> (permalink) |
| References | (4 earlier) <tuEK5-7QB-19@gated-at.bofh.it> <tuFPP-8ur-9@gated-at.bofh.it> <tuUlQ-1p3-7@gated-at.bofh.it> <tuYz7-3XH-3@gated-at.bofh.it> <tuZlw-4vi-7@gated-at.bofh.it> |
| Organization | linux.* mail to news gateway |
On Tue, Apr 11, 2017 at 04:25:50PM +0800, Du, Changbin wrote:
> > > (gdb) print fmt.sort_list
> > > $5 = {next = 0x9727d0 <perf_hpp_list+16>, prev = 0x9727d0 <perf_hpp_list+16>}
> > >
> > > In this case, the fmt is linked in sort_list, but not in list. So crash
> > > at the list_del_init(&fmt->list) of second loop.
> >
> > so the only place I can see the POISON could get there
> > is in perf_hpp__column_unregister.. can't we just get
> > rid of it like below
> >
> > jirka
> >
> >
> > ---
> > diff --git a/tools/perf/ui/hist.c b/tools/perf/ui/hist.c
> > index 5d632dca672a..7577effbf746 100644
> > --- a/tools/perf/ui/hist.c
> > +++ b/tools/perf/ui/hist.c
> > @@ -529,7 +529,7 @@ void perf_hpp_list__prepend_sort_field(struct perf_hpp_list *list,
> >
> > void perf_hpp__column_unregister(struct perf_hpp_fmt *format)
> > {
> > - list_del(&format->list);
> > + list_del_init(&format->list);
> > }
> >
> yes, this is an option. But for safety, I sugguest do not rely on list_del_init.
> No rule rather than create one.
>
> But anyway, both are ok for me. What's your options?
hum, also I dont think we need to touch that bit at all
if we are going to remove it right away.. how about the
change below?
jirka
---
diff --git a/tools/perf/ui/hist.c b/tools/perf/ui/hist.c
index 5d632dca672a..0ee7db43dd7d 100644
--- a/tools/perf/ui/hist.c
+++ b/tools/perf/ui/hist.c
@@ -613,15 +613,15 @@ void perf_hpp__reset_output_field(struct perf_hpp_list *list)
/* reset output fields */
perf_hpp_list__for_each_format_safe(list, fmt, tmp) {
- list_del_init(&fmt->list);
- list_del_init(&fmt->sort_list);
+ list_del(&fmt->list);
+ /* Remove the fmt from next loop processing. */
+ list_del(&fmt->sort_list);
fmt_free(fmt);
}
/* reset sort keys */
perf_hpp_list__for_each_sort_list_safe(list, fmt, tmp) {
- list_del_init(&fmt->list);
- list_del_init(&fmt->sort_list);
+ list_del(&fmt->sort_list);
fmt_free(fmt);
}
}
Back to linux.kernel | Previous | Next — Previous in thread | Find similar | Unroll thread
Re: [PATCH v2] perf: fix double free at function perf_hpp__reset_output_field "Du, Changbin" <changbin.du@intel.com> - 2017-04-11 05:10 +0200
Re: [PATCH v2] perf: fix double free at function perf_hpp__reset_output_field Jiri Olsa <jolsa@redhat.com> - 2017-04-11 09:40 +0200
Re: [PATCH v2] perf: fix double free at function perf_hpp__reset_output_field "Du, Changbin" <changbin.du@intel.com> - 2017-04-11 10:30 +0200
Re: [PATCH v2] perf: fix double free at function perf_hpp__reset_output_field "Du, Changbin" <changbin.du@intel.com> - 2017-04-11 12:20 +0200
Re: [PATCH v2] perf: fix double free at function perf_hpp__reset_output_field Jiri Olsa <jolsa@redhat.com> - 2017-04-11 12:40 +0200
Re: [PATCH v2] perf: fix double free at function perf_hpp__reset_output_field "Du, Changbin" <changbin.du@intel.com> - 2017-04-12 04:00 +0200
Re: [PATCH v2] perf: fix double free at function perf_hpp__reset_output_field Jiri Olsa <jolsa@redhat.com> - 2017-04-11 12:30 +0200
csiph-web