Thread (4 messages) 4 messages, 2 authors, 2016-01-25

Re: [BUG REPORT] NULL pointer dereference in jdb2_journal_grab_journal_head (RDI)

From: Jeff Merkey <hidden>
Date: 2016-01-25 15:41:39
Also in: lkml

On 1/25/16, Jan Kara [off-list ref] wrote:
On Sat 23-01-16 09:42:52, Jeff Merkey wrote:
quoted
If I leave the system in the debugger console overnight with all the
processors suspended for about 8 hours, then type go, the following
bug shows up during file I/O.  This particular bug showed up while
using git to update some branches.

I have only seen this bug once and I attempted to reproduce it to get
a trace dump but have not been able to trigger it again.  The NULL
pointer is RDI set to NULL while trying to obtain a lock.

(2)> .z grab_journal
ffffffffa00bb740 t jbd2_journal_grab_journal_head [jbd2]
(2)> u ffffffffa00bb740
jbd2|jbd2_journal_grab_journal_head:
0xffffffffa00bb740 0F1F440000      nop    DWORD PTR [rax+rax]=0x0
0xffffffffa00bb745 55              push   rbp
0xffffffffa00bb746 4889E5          mov    rbp,rsp
<<<<<<<<<<<<   Crashes here with RDI set to NULL
0xffffffffa00bb749 F00FBA2F18      lock bts DWORD PTR [rdi]=0x0,0x18
<<<<<<<<<<<<
Thanks for report. Ok, this means jbd2_journal_grab_journal_head() got
called with 'bh == NULL'. That is certainly wrong but unless we know a full
stack trace, it's hard to guess what went wrong.

								Honza

--
Jan Kara [off-list ref]
SUSE Labs, CR

I have a system setup to get a better trace if it triggers again.
When it happened the first time I was not able to get a good dump.  If
it triggers again, I'll send you the trace.   So far it has not
triggered.

:-)

Jeff
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help