Patch "ext4: fix reference counting bug on block allocation error" has been added to the 4.7-stable tree
From: <gregkh@linuxfoundation.org>
Date: 2016-08-14 19:48:08
This is a note to let you know that I've just added the patch titled
ext4: fix reference counting bug on block allocation error
to the 4.7-stable tree which can be found at:
http://www.kernel.org/git/?p=linux/kernel/git/stable/stable-queue.git;a=summary
The filename of the patch is:
ext4-fix-reference-counting-bug-on-block-allocation-error.patch
and it can be found in the queue-4.7 subdirectory.
If you, or anyone else, feels it should not be added to the stable tree,
please let [off-list ref] know about it.
From 554a5ccc4e4a20c5f3ec859de0842db4b4b9c77e Mon Sep 17 00:00:00 2001
From: Vegard Nossum <redacted>
Date: Thu, 14 Jul 2016 23:02:47 -0400
Subject: ext4: fix reference counting bug on block allocation error
From: Vegard Nossum <redacted>
commit 554a5ccc4e4a20c5f3ec859de0842db4b4b9c77e upstream.
If we hit this error when mounted with errors=continue or
errors=remount-ro:
EXT4-fs error (device loop0): ext4_mb_mark_diskspace_used:2940: comm ext4.exe: Allocating blocks 5090-6081 which overlap fs metadata
then ext4_mb_new_blocks() will call ext4_mb_release_context() and try to
continue. However, ext4_mb_release_context() is the wrong thing to call
here since we are still actually using the allocation context.
Instead, just error out. We could retry the allocation, but there is a
possibility of getting stuck in an infinite loop instead, so this seems
safer.
[ Fixed up so we don't return EAGAIN to userspace. --tytso ]
Fixes: 8556e8f3b6 ("ext4: Don't allow new groups to be added during block allocation")
Signed-off-by: Vegard Nossum <redacted>
Signed-off-by: Theodore Ts'o <tytso@mit.edu>
Cc: Aneesh Kumar K.V <redacted>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
fs/ext4/mballoc.c | 17 +++--------------
1 file changed, 3 insertions(+), 14 deletions(-)
--- a/fs/ext4/mballoc.c
+++ b/fs/ext4/mballoc.c@@ -2939,7 +2939,7 @@ ext4_mb_mark_diskspace_used(struct ext4_ ext4_error(sb, "Allocating blocks %llu-%llu which overlap " "fs metadata", block, block+len); /* File system mounted not to panic on error - * Fix the bitmap and repeat the block allocation + * Fix the bitmap and return EFSCORRUPTED * We leak some of the blocks here. */ ext4_lock_group(sb, ac->ac_b_ex.fe_group);
@@ -2948,7 +2948,7 @@ ext4_mb_mark_diskspace_used(struct ext4_ ext4_unlock_group(sb, ac->ac_b_ex.fe_group); err = ext4_handle_dirty_metadata(handle, NULL, bitmap_bh); if (!err) - err = -EAGAIN; + err = -EFSCORRUPTED; goto out_err; }
@@ -4513,18 +4513,7 @@ repeat: } if (likely(ac->ac_status == AC_STATUS_FOUND)) { *errp = ext4_mb_mark_diskspace_used(ac, handle, reserv_clstrs); - if (*errp == -EAGAIN) { - /* - * drop the reference that we took - * in ext4_mb_use_best_found - */ - ext4_mb_release_context(ac); - ac->ac_b_ex.fe_group = 0; - ac->ac_b_ex.fe_start = 0; - ac->ac_b_ex.fe_len = 0; - ac->ac_status = AC_STATUS_CONTINUE; - goto repeat; - } else if (*errp) { + if (*errp) { ext4_discard_allocated_blocks(ac); goto errout; } else {
Patches currently in stable-queue which might be from vegard.nossum@oracle.com are queue-4.7/ext4-verify-extent-header-depth.patch queue-4.7/ext4-short-cut-orphan-cleanup-on-error.patch queue-4.7/block-fix-use-after-free-in-seq-file.patch queue-4.7/ext4-check-for-extents-that-wrap-around.patch queue-4.7/net-irda-fix-null-pointer-dereference-on-memory-allocation-failure.patch queue-4.7/ext4-validate-s_reserved_gdt_blocks-on-mount.patch queue-4.7/ext4-don-t-call-ext4_should_journal_data-on-the-journal-inode.patch queue-4.7/ext4-fix-reference-counting-bug-on-block-allocation-error.patch queue-4.7/net-sctp-terminate-rhashtable-walk-correctly.patch