Currently the error path of function gfs2_inode_lookup calls function
gfs2_glock_put corresponding to an earlier call to gfs2_glock_get for
the inode glock. That's wrong because the error path also calls
iget_failed() which eventually calls iput, which eventually calls
gfs2_evict_inode, which does another gfs2_glock_put. This double-put
can cause the glock reference count to get off.

Signed-off-by: Bob Peterson <rpete...@redhat.com>
---
 fs/gfs2/inode.c | 1 -
 1 file changed, 1 deletion(-)

diff --git a/fs/gfs2/inode.c b/fs/gfs2/inode.c
index 87fa599..009b551 100644
--- a/fs/gfs2/inode.c
+++ b/fs/gfs2/inode.c
@@ -198,7 +198,6 @@ fail_iopen:
                gfs2_glock_put(io_gl);
 fail_put:
        ip->i_gl->gl_object = NULL;
-       gfs2_glock_put(ip->i_gl);
 fail:
        iget_failed(inode);
        return ERR_PTR(error);
-- 
2.5.0

Reply via email to