summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorBen Pfaff <blp@nicira.com>2011-03-31 14:11:57 -0700
committerBen Pfaff <blp@nicira.com>2011-03-31 14:28:42 -0700
commitf41240e6f32f1162132d4f307e95e4d452e24a0f (patch)
tree6e3c684f93f077167baf31777bd436d4de2ec10c
parentac1e8ee90853b5d248ea5d2d0f63ce0b5686a5b7 (diff)
downloadopenvswitch-f41240e6f32f1162132d4f307e95e4d452e24a0f.tar.gz
ofproto: Fix order of destruction in ofproto_destroy().
ofproto_flush_flows() calls into the connmgr (via connmgr_flushed()) so it must be called before destroying the connmgr to avoid a use-after-free error. Bug #5231. Reported-by: Krishna Miriyala <krishna@nicira.com>
-rw-r--r--ofproto/ofproto.c4
1 files changed, 1 insertions, 3 deletions
diff --git a/ofproto/ofproto.c b/ofproto/ofproto.c
index 6994b1172..7cdc98adf 100644
--- a/ofproto/ofproto.c
+++ b/ofproto/ofproto.c
@@ -683,10 +683,8 @@ ofproto_destroy(struct ofproto *p)
shash_find_and_delete(&all_ofprotos, dpif_name(p->dpif));
- /* Destroy connmgr early, since it touches the classifier. */
- connmgr_destroy(p->connmgr);
-
ofproto_flush_flows(p);
+ connmgr_destroy(p->connmgr);
classifier_destroy(&p->cls);
hmap_destroy(&p->facets);