summaryrefslogtreecommitdiffstats
path: root/fs/ext4/inode.c
diff options
context:
space:
mode:
authorAlexey Khoroshilov2013-07-01 14:12:36 +0200
committerTheodore Ts'o2013-07-01 14:12:36 +0200
commit2c00ef3ee309142041c7395f42aa1d49fc9f44b9 (patch)
tree0ec1ff904065832f1c29bbd789d513d5098937ff /fs/ext4/inode.c
parentext4: fix corruption when online resizing a fs with 1K block size (diff)
downloadkernel-qcow2-linux-2c00ef3ee309142041c7395f42aa1d49fc9f44b9.tar.gz
kernel-qcow2-linux-2c00ef3ee309142041c7395f42aa1d49fc9f44b9.tar.xz
kernel-qcow2-linux-2c00ef3ee309142041c7395f42aa1d49fc9f44b9.zip
ext4: implement error handling of ext4_mb_new_preallocation()
If memory allocation in ext4_mb_new_group_pa() is failed, it returns error code, ext4_mb_new_preallocation() propages it, but ext4_mb_new_blocks() ignores it. An observed result was: - allocation fail means ext4_mb_new_group_pa() does not update ext4_allocation_context; - ext4_mb_new_blocks() sets ext4_allocation_request->len (ar->len = ac->ac_b_ex.fe_len;) to number of blocks preallocated (512) instead of number of blocks requested (1); - that activates update cycle in ext4_splice_branch(): for (i = 1; i < blks; i++) <-- blks is 512 instead of 1 here *(where->p + i) = cpu_to_le32(current_block++); - it iterates 511 times and corrupts a chunk of memory including inode structure; - page fault happens at EXT4_SB(inode->i_sb) in ext4_mark_inode_dirty(); - system hangs with 'scheduling while atomic' BUG. The patch implements a check for ext4_mb_new_preallocation() error code and handles its failure as if ext4_mb_regular_allocator() fails. Found by Linux File System Verification project (linuxtesting.org). [ Patch restructed by tytso to make the flow of control easier to follow. ] Signed-off-by: Alexey Khoroshilov <khoroshilov@ispras.ru> Signed-off-by: "Theodore Ts'o" <tytso@mit.edu>
Diffstat (limited to 'fs/ext4/inode.c')
0 files changed, 0 insertions, 0 deletions