* Kernel oops (bug) in fs/buffers.c:create_empty_buffers
@ 2008-07-06 20:23 Arjan van de Ven
2008-07-06 20:31 ` Andrew Morton
0 siblings, 1 reply; 4+ messages in thread
From: Arjan van de Ven @ 2008-07-06 20:23 UTC (permalink / raw)
To: linux-kernel, Al Viro; +Cc: akpm
Hi,
caught this one on kerneloops.org:
http://www.kerneloops.org/searchweek.php?search=create_empty_buffers
void create_empty_buffers(struct page *page,
unsigned long blocksize, unsigned long b_state)
{
struct buffer_head *bh, *head, *tail;
head = alloc_page_buffers(page, blocksize, 1);
bh = head;
do {
bh->b_state |= b_state;
tail = bh;
bh = bh->b_this_page;
} while (bh);
turns out, alloc_page_buffers() can fail and return NULL (for AIO for
example)... yet this code blindly dereferences the result, getting a
predictable NULL pointer fault.
It's not directly clear what to do about... make this function return
the failure to the caller?
--
If you want to reach me at my work email, use arjan@linux.intel.com
For development, discussion and tips for power savings,
visit http://www.lesswatts.org
^ permalink raw reply [flat|nested] 4+ messages in thread
* Re: Kernel oops (bug) in fs/buffers.c:create_empty_buffers
2008-07-06 20:23 Kernel oops (bug) in fs/buffers.c:create_empty_buffers Arjan van de Ven
@ 2008-07-06 20:31 ` Andrew Morton
2008-07-06 21:27 ` Arjan van de Ven
2008-07-09 22:46 ` Jan Kara
0 siblings, 2 replies; 4+ messages in thread
From: Andrew Morton @ 2008-07-06 20:31 UTC (permalink / raw)
To: Arjan van de Ven; +Cc: linux-kernel, Al Viro
On Sun, 6 Jul 2008 13:23:02 -0700 Arjan van de Ven <arjan@infradead.org> wrote:
> Hi,
>
> caught this one on kerneloops.org:
> http://www.kerneloops.org/searchweek.php?search=create_empty_buffers
>
> void create_empty_buffers(struct page *page,
> unsigned long blocksize, unsigned long b_state)
> {
> struct buffer_head *bh, *head, *tail;
>
> head = alloc_page_buffers(page, blocksize, 1);
> bh = head;
> do {
> bh->b_state |= b_state;
> tail = bh;
> bh = bh->b_this_page;
> } while (bh);
>
>
> turns out, alloc_page_buffers() can fail and return NULL (for AIO for
> example)... yet this code blindly dereferences the result, getting a
> predictable NULL pointer fault.
>
> It's not directly clear what to do about... make this function return
> the failure to the caller?
isofs has a habit of returning impossible block sizes and the
while ((offset -= size) >= 0) {
consequently loops zero times and alloc_page_buffers() returns null.
Someone was having a look at it - maybe Jan?
I assume that the kernloops.org records link back to the original
report somewhere but I can't find it?
^ permalink raw reply [flat|nested] 4+ messages in thread
* Re: Kernel oops (bug) in fs/buffers.c:create_empty_buffers
2008-07-06 20:31 ` Andrew Morton
@ 2008-07-06 21:27 ` Arjan van de Ven
2008-07-09 22:46 ` Jan Kara
1 sibling, 0 replies; 4+ messages in thread
From: Arjan van de Ven @ 2008-07-06 21:27 UTC (permalink / raw)
To: Andrew Morton; +Cc: linux-kernel, Al Viro
On Sun, 6 Jul 2008 13:31:00 -0700
Andrew Morton <akpm@linux-foundation.org> wrote:
> isofs has a habit of returning impossible block sizes and the
>
> while ((offset -= size) >= 0) {
>
> consequently loops zero times and alloc_page_buffers() returns null.
>
> Someone was having a look at it - maybe Jan?
>
> I assume that the kernloops.org records link back to the original
> report somewhere but I can't find it?
http://www.kerneloops.org/search.php?search=create_empty_buffers
has two:
http://article.gmane.org/gmane.linux.kernel/696582
http://article.gmane.org/gmane.linux.ide/13658
--
If you want to reach me at my work email, use arjan@linux.intel.com
For development, discussion and tips for power savings,
visit http://www.lesswatts.org
^ permalink raw reply [flat|nested] 4+ messages in thread
* Re: Kernel oops (bug) in fs/buffers.c:create_empty_buffers
2008-07-06 20:31 ` Andrew Morton
2008-07-06 21:27 ` Arjan van de Ven
@ 2008-07-09 22:46 ` Jan Kara
1 sibling, 0 replies; 4+ messages in thread
From: Jan Kara @ 2008-07-09 22:46 UTC (permalink / raw)
To: Andrew Morton; +Cc: Arjan van de Ven, linux-kernel, Al Viro
> On Sun, 6 Jul 2008 13:23:02 -0700 Arjan van de Ven <arjan@infradead.org> wrote:
> > Hi,
> >
> > caught this one on kerneloops.org:
> > http://www.kerneloops.org/searchweek.php?search=create_empty_buffers
> >
> > void create_empty_buffers(struct page *page,
> > unsigned long blocksize, unsigned long b_state)
> > {
> > struct buffer_head *bh, *head, *tail;
> >
> > head = alloc_page_buffers(page, blocksize, 1);
> > bh = head;
> > do {
> > bh->b_state |= b_state;
> > tail = bh;
> > bh = bh->b_this_page;
> > } while (bh);
> >
> >
> > turns out, alloc_page_buffers() can fail and return NULL (for AIO for
> > example)... yet this code blindly dereferences the result, getting a
> > predictable NULL pointer fault.
> >
> > It's not directly clear what to do about... make this function return
> > the failure to the caller?
>
> isofs has a habit of returning impossible block sizes and the
>
> while ((offset -= size) >= 0) {
>
> consequently loops zero times and alloc_page_buffers() returns null.
>
> Someone was having a look at it - maybe Jan?
Yes, I was looking at that. Actually, I've pinpointed the cause of
the Oopses I've seen to a bug in ide-cd driver. It happily sets blocksize
to whatever value the drive reported and some drives have a habit of
reporting bogus values when unreadable medium is inserted.
Jens has actually cooked up a fix for this bug
(http://thread.gmane.org/gmane.linux.kernel/696582) and it fixes the
problem at least for me.
> I assume that the kernloops.org records link back to the original
> report somewhere but I can't find it?
Honza
--
Jan Kara <jack@suse.cz>
SuSE CR Labs
^ permalink raw reply [flat|nested] 4+ messages in thread
end of thread, other threads:[~2008-07-09 22:46 UTC | newest]
Thread overview: 4+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2008-07-06 20:23 Kernel oops (bug) in fs/buffers.c:create_empty_buffers Arjan van de Ven
2008-07-06 20:31 ` Andrew Morton
2008-07-06 21:27 ` Arjan van de Ven
2008-07-09 22:46 ` Jan Kara
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.