mirror of
https://github.com/hardkernel/linux.git
synced 2026-03-25 20:10:23 +09:00
UPSTREAM: gfs2: Don't deref jdesc in evict
[ Upstream commit504a10d9e4] On corrupt gfs2 file systems the evict code can try to reference the journal descriptor structure, jdesc, after it has been freed and set to NULL. The sequence of events is: init_journal() ... fail_jindex: gfs2_jindex_free(sdp); <------frees journals, sets jdesc = NULL if (gfs2_holder_initialized(&ji_gh)) gfs2_glock_dq_uninit(&ji_gh); fail: iput(sdp->sd_jindex); <--references jdesc in evict_linked_inode evict() gfs2_evict_inode() evict_linked_inode() ret = gfs2_trans_begin(sdp, 0, sdp->sd_jdesc->jd_blocks); <------references the now freed/zeroed sd_jdesc pointer. The call to gfs2_trans_begin is done because the truncate_inode_pages call can cause gfs2 events that require a transaction, such as removing journaled data (jdata) blocks from the journal. This patch fixes the problem by adding a check for sdp->sd_jdesc to function gfs2_evict_inode. In theory, this should only happen to corrupt gfs2 file systems, when gfs2 detects the problem, reports it, then tries to evict all the system inodes it has read in up to that point. Bug: 289870854 Reported-by: Yang Lan <lanyang0908@gmail.com> Signed-off-by: Bob Peterson <rpeterso@redhat.com> Signed-off-by: Andreas Gruenbacher <agruenba@redhat.com> Signed-off-by: Sasha Levin <sashal@kernel.org> (cherry picked from commit5ae4a618a1) Signed-off-by: Lee Jones <joneslee@google.com> Change-Id: I501e8631e1b60479023f5e6ad957540f9e10bcd5
This commit is contained in:
committed by
Treehugger Robot
parent
578ffd6434
commit
feb80c37c6
@@ -1381,6 +1381,14 @@ static void gfs2_evict_inode(struct inode *inode)
|
||||
if (inode->i_nlink || sb_rdonly(sb))
|
||||
goto out;
|
||||
|
||||
/*
|
||||
* In case of an incomplete mount, gfs2_evict_inode() may be called for
|
||||
* system files without having an active journal to write to. In that
|
||||
* case, skip the filesystem evict.
|
||||
*/
|
||||
if (!sdp->sd_jdesc)
|
||||
goto out;
|
||||
|
||||
gfs2_holder_mark_uninitialized(&gh);
|
||||
ret = evict_should_delete(inode, &gh);
|
||||
if (ret == SHOULD_DEFER_EVICTION)
|
||||
|
||||
Reference in New Issue
Block a user