All of lore.kernel.org
 help / color / mirror / Atom feed
* Kernel oops (bug) in fs/buffers.c:create_empty_buffers
@ 2008-07-06 20:23 Arjan van de Ven
  2008-07-06 20:31 ` Andrew Morton
  0 siblings, 1 reply; 4+ messages in thread
From: Arjan van de Ven @ 2008-07-06 20:23 UTC (permalink / raw)
  To: linux-kernel, Al Viro; +Cc: akpm

Hi,

caught this one on kerneloops.org: 
http://www.kerneloops.org/searchweek.php?search=create_empty_buffers

void create_empty_buffers(struct page *page,
                        unsigned long blocksize, unsigned long b_state)
{
        struct buffer_head *bh, *head, *tail;

        head = alloc_page_buffers(page, blocksize, 1);
        bh = head;
        do {
                bh->b_state |= b_state;
                tail = bh;
                bh = bh->b_this_page;
        } while (bh);


turns out, alloc_page_buffers() can fail and return NULL (for AIO for
example)... yet this code blindly dereferences the result, getting a
predictable NULL pointer fault.

It's not directly clear what to do about... make this function return
the failure to the caller?


-- 
If you want to reach me at my work email, use arjan@linux.intel.com
For development, discussion and tips for power savings, 
visit http://www.lesswatts.org

^ permalink raw reply	[flat|nested] 4+ messages in thread

* Re: Kernel oops (bug) in fs/buffers.c:create_empty_buffers
  2008-07-06 20:23 Kernel oops (bug) in fs/buffers.c:create_empty_buffers Arjan van de Ven
@ 2008-07-06 20:31 ` Andrew Morton
  2008-07-06 21:27   ` Arjan van de Ven
  2008-07-09 22:46   ` Jan Kara
  0 siblings, 2 replies; 4+ messages in thread
From: Andrew Morton @ 2008-07-06 20:31 UTC (permalink / raw)
  To: Arjan van de Ven; +Cc: linux-kernel, Al Viro

On Sun, 6 Jul 2008 13:23:02 -0700 Arjan van de Ven <arjan@infradead.org> wrote:

> Hi,
> 
> caught this one on kerneloops.org: 
> http://www.kerneloops.org/searchweek.php?search=create_empty_buffers
> 
> void create_empty_buffers(struct page *page,
>                         unsigned long blocksize, unsigned long b_state)
> {
>         struct buffer_head *bh, *head, *tail;
> 
>         head = alloc_page_buffers(page, blocksize, 1);
>         bh = head;
>         do {
>                 bh->b_state |= b_state;
>                 tail = bh;
>                 bh = bh->b_this_page;
>         } while (bh);
> 
> 
> turns out, alloc_page_buffers() can fail and return NULL (for AIO for
> example)... yet this code blindly dereferences the result, getting a
> predictable NULL pointer fault.
> 
> It's not directly clear what to do about... make this function return
> the failure to the caller?

isofs has a habit of returning impossible block sizes and the

	while ((offset -= size) >= 0) {

consequently loops zero times and alloc_page_buffers() returns null.

Someone was having a look at it - maybe Jan?

I assume that the kernloops.org records link back to the original
report somewhere but I can't find it?


^ permalink raw reply	[flat|nested] 4+ messages in thread

* Re: Kernel oops (bug) in fs/buffers.c:create_empty_buffers
  2008-07-06 20:31 ` Andrew Morton
@ 2008-07-06 21:27   ` Arjan van de Ven
  2008-07-09 22:46   ` Jan Kara
  1 sibling, 0 replies; 4+ messages in thread
From: Arjan van de Ven @ 2008-07-06 21:27 UTC (permalink / raw)
  To: Andrew Morton; +Cc: linux-kernel, Al Viro

On Sun, 6 Jul 2008 13:31:00 -0700
Andrew Morton <akpm@linux-foundation.org> wrote:

> isofs has a habit of returning impossible block sizes and the
> 
> 	while ((offset -= size) >= 0) {
> 
> consequently loops zero times and alloc_page_buffers() returns null.
> 
> Someone was having a look at it - maybe Jan?
> 
> I assume that the kernloops.org records link back to the original
> report somewhere but I can't find it?

http://www.kerneloops.org/search.php?search=create_empty_buffers
has two:

http://article.gmane.org/gmane.linux.kernel/696582
http://article.gmane.org/gmane.linux.ide/13658


-- 
If you want to reach me at my work email, use arjan@linux.intel.com
For development, discussion and tips for power savings, 
visit http://www.lesswatts.org

^ permalink raw reply	[flat|nested] 4+ messages in thread

* Re: Kernel oops (bug) in fs/buffers.c:create_empty_buffers
  2008-07-06 20:31 ` Andrew Morton
  2008-07-06 21:27   ` Arjan van de Ven
@ 2008-07-09 22:46   ` Jan Kara
  1 sibling, 0 replies; 4+ messages in thread
From: Jan Kara @ 2008-07-09 22:46 UTC (permalink / raw)
  To: Andrew Morton; +Cc: Arjan van de Ven, linux-kernel, Al Viro

> On Sun, 6 Jul 2008 13:23:02 -0700 Arjan van de Ven <arjan@infradead.org> wrote:
> > Hi,
> > 
> > caught this one on kerneloops.org: 
> > http://www.kerneloops.org/searchweek.php?search=create_empty_buffers
> > 
> > void create_empty_buffers(struct page *page,
> >                         unsigned long blocksize, unsigned long b_state)
> > {
> >         struct buffer_head *bh, *head, *tail;
> > 
> >         head = alloc_page_buffers(page, blocksize, 1);
> >         bh = head;
> >         do {
> >                 bh->b_state |= b_state;
> >                 tail = bh;
> >                 bh = bh->b_this_page;
> >         } while (bh);
> > 
> > 
> > turns out, alloc_page_buffers() can fail and return NULL (for AIO for
> > example)... yet this code blindly dereferences the result, getting a
> > predictable NULL pointer fault.
> > 
> > It's not directly clear what to do about... make this function return
> > the failure to the caller?
> 
> isofs has a habit of returning impossible block sizes and the
> 
> 	while ((offset -= size) >= 0) {
> 
> consequently loops zero times and alloc_page_buffers() returns null.
> 
> Someone was having a look at it - maybe Jan?
  Yes, I was looking at that. Actually, I've pinpointed the cause of
the Oopses I've seen to a bug in ide-cd driver. It happily sets blocksize
to whatever value the drive reported and some drives have a habit of
reporting bogus values when unreadable medium is inserted.
  Jens has actually cooked up a fix for this bug
(http://thread.gmane.org/gmane.linux.kernel/696582) and it fixes the
problem at least for me.

> I assume that the kernloops.org records link back to the original
> report somewhere but I can't find it?

								Honza
-- 
Jan Kara <jack@suse.cz>
SuSE CR Labs

^ permalink raw reply	[flat|nested] 4+ messages in thread

end of thread, other threads:[~2008-07-09 22:46 UTC | newest]

Thread overview: 4+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2008-07-06 20:23 Kernel oops (bug) in fs/buffers.c:create_empty_buffers Arjan van de Ven
2008-07-06 20:31 ` Andrew Morton
2008-07-06 21:27   ` Arjan van de Ven
2008-07-09 22:46   ` Jan Kara

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.