In cpu_stopper_thread(), @work->done may be NULL if the cpu stop work is queued from stop_one_cpu_nowait(); however, cpu_stopper_thread() updates @done->ret without checking whether @done exists or not when the work function fails.
While this can lead to oops, the only current user of stop_one_cpu_nowait() - active_load_balance_cpu_stop() - always returns 0 and thus there's no in-kernel user which triggers this bug. Fix it by checking whether @done exists before updating @done->ret. Thanks Tejun for sharing commit message. Signed-off-by: Hillf Danton <dhi...@gmail.com> Reviewed-by: Namhyung Kim <namhy...@kernel.org> --- --- a/kernel/stop_machine.c Sun Feb 10 12:51:46 2013 +++ b/kernel/stop_machine.c Sun Feb 10 12:58:58 2013 @@ -279,7 +279,7 @@ repeat: preempt_disable(); ret = fn(arg); - if (ret) + if (ret && done) done->ret = ret; /* restore preemption and check it's still balanced */ -- -- To unsubscribe from this list: send the line "unsubscribe linux-kernel" in the body of a message to majord...@vger.kernel.org More majordomo info at http://vger.kernel.org/majordomo-info.html Please read the FAQ at http://www.tux.org/lkml/