From: Greg KH <gregkh@linuxfoundation.org>
To: linux-kernel@vger.kernel.org, stable@vger.kernel.org
Cc: torvalds@linux-foundation.org, akpm@linux-foundation.org,
alan@lxorguk.ukuu.org.uk, Jeff Moyer <jmoyer@redhat.com>,
Nick Piggin <npiggin@kernel.dk>, Jens Axboe <axboe@kernel.dk>
Subject: [ 04/94] block: dont mark buffers beyond end of disk as mapped
Date: Sun, 27 May 2012 10:04:27 +0900 [thread overview]
Message-ID: <20120527010424.356633491@linuxfoundation.org> (raw)
In-Reply-To: <20120527010332.GA11170@kroah.com>
3.3-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jeff Moyer <jmoyer@redhat.com>
commit 080399aaaf3531f5b8761ec0ac30ff98891e8686 upstream.
Hi,
We have a bug report open where a squashfs image mounted on ppc64 would
exhibit errors due to trying to read beyond the end of the disk. It can
easily be reproduced by doing the following:
[root@ibm-p750e-02-lp3 ~]# ls -l install.img
-rw-r--r-- 1 root root 142032896 Apr 30 16:46 install.img
[root@ibm-p750e-02-lp3 ~]# mount -o loop ./install.img /mnt/test
[root@ibm-p750e-02-lp3 ~]# dd if=/dev/loop0 of=/dev/null
dd: reading `/dev/loop0': Input/output error
277376+0 records in
277376+0 records out
142016512 bytes (142 MB) copied, 0.9465 s, 150 MB/s
In dmesg, you'll find the following:
squashfs: version 4.0 (2009/01/31) Phillip Lougher
[ 43.106012] attempt to access beyond end of device
[ 43.106029] loop0: rw=0, want=277410, limit=277408
[ 43.106039] Buffer I/O error on device loop0, logical block 138704
[ 43.106053] attempt to access beyond end of device
[ 43.106057] loop0: rw=0, want=277412, limit=277408
[ 43.106061] Buffer I/O error on device loop0, logical block 138705
[ 43.106066] attempt to access beyond end of device
[ 43.106070] loop0: rw=0, want=277414, limit=277408
[ 43.106073] Buffer I/O error on device loop0, logical block 138706
[ 43.106078] attempt to access beyond end of device
[ 43.106081] loop0: rw=0, want=277416, limit=277408
[ 43.106085] Buffer I/O error on device loop0, logical block 138707
[ 43.106089] attempt to access beyond end of device
[ 43.106093] loop0: rw=0, want=277418, limit=277408
[ 43.106096] Buffer I/O error on device loop0, logical block 138708
[ 43.106101] attempt to access beyond end of device
[ 43.106104] loop0: rw=0, want=277420, limit=277408
[ 43.106108] Buffer I/O error on device loop0, logical block 138709
[ 43.106112] attempt to access beyond end of device
[ 43.106116] loop0: rw=0, want=277422, limit=277408
[ 43.106120] Buffer I/O error on device loop0, logical block 138710
[ 43.106124] attempt to access beyond end of device
[ 43.106128] loop0: rw=0, want=277424, limit=277408
[ 43.106131] Buffer I/O error on device loop0, logical block 138711
[ 43.106135] attempt to access beyond end of device
[ 43.106139] loop0: rw=0, want=277426, limit=277408
[ 43.106143] Buffer I/O error on device loop0, logical block 138712
[ 43.106147] attempt to access beyond end of device
[ 43.106151] loop0: rw=0, want=277428, limit=277408
[ 43.106154] Buffer I/O error on device loop0, logical block 138713
[ 43.106158] attempt to access beyond end of device
[ 43.106162] loop0: rw=0, want=277430, limit=277408
[ 43.106166] attempt to access beyond end of device
[ 43.106169] loop0: rw=0, want=277432, limit=277408
...
[ 43.106307] attempt to access beyond end of device
[ 43.106311] loop0: rw=0, want=277470, limit=2774
Squashfs manages to read in the end block(s) of the disk during the
mount operation. Then, when dd reads the block device, it leads to
block_read_full_page being called with buffers that are beyond end of
disk, but are marked as mapped. Thus, it would end up submitting read
I/O against them, resulting in the errors mentioned above. I fixed the
problem by modifying init_page_buffers to only set the buffer mapped if
it fell inside of i_size.
Cheers,
Jeff
Signed-off-by: Jeff Moyer <jmoyer@redhat.com>
Acked-by: Nick Piggin <npiggin@kernel.dk>
--
Changes from v1->v2: re-used max_block, as suggested by Nick Piggin.
Signed-off-by: Jens Axboe <axboe@kernel.dk>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
fs/block_dev.c | 6 +++---
fs/buffer.c | 4 +++-
include/linux/fs.h | 1 +
3 files changed, 7 insertions(+), 4 deletions(-)
--- a/fs/block_dev.c
+++ b/fs/block_dev.c
@@ -69,7 +69,7 @@ static void bdev_inode_switch_bdi(struct
spin_unlock(&dst->wb.list_lock);
}
-static sector_t max_block(struct block_device *bdev)
+sector_t blkdev_max_block(struct block_device *bdev)
{
sector_t retval = ~((sector_t)0);
loff_t sz = i_size_read(bdev->bd_inode);
@@ -162,7 +162,7 @@ static int
blkdev_get_block(struct inode *inode, sector_t iblock,
struct buffer_head *bh, int create)
{
- if (iblock >= max_block(I_BDEV(inode))) {
+ if (iblock >= blkdev_max_block(I_BDEV(inode))) {
if (create)
return -EIO;
@@ -184,7 +184,7 @@ static int
blkdev_get_blocks(struct inode *inode, sector_t iblock,
struct buffer_head *bh, int create)
{
- sector_t end_block = max_block(I_BDEV(inode));
+ sector_t end_block = blkdev_max_block(I_BDEV(inode));
unsigned long max_blocks = bh->b_size >> inode->i_blkbits;
if ((iblock + max_blocks) > end_block) {
--- a/fs/buffer.c
+++ b/fs/buffer.c
@@ -921,6 +921,7 @@ init_page_buffers(struct page *page, str
struct buffer_head *head = page_buffers(page);
struct buffer_head *bh = head;
int uptodate = PageUptodate(page);
+ sector_t end_block = blkdev_max_block(I_BDEV(bdev->bd_inode));
do {
if (!buffer_mapped(bh)) {
@@ -929,7 +930,8 @@ init_page_buffers(struct page *page, str
bh->b_blocknr = block;
if (uptodate)
set_buffer_uptodate(bh);
- set_buffer_mapped(bh);
+ if (block < end_block)
+ set_buffer_mapped(bh);
}
block++;
bh = bh->b_this_page;
--- a/include/linux/fs.h
+++ b/include/linux/fs.h
@@ -2058,6 +2058,7 @@ extern void unregister_blkdev(unsigned i
extern struct block_device *bdget(dev_t);
extern struct block_device *bdgrab(struct block_device *bdev);
extern void bd_set_size(struct block_device *, loff_t size);
+extern sector_t blkdev_max_block(struct block_device *bdev);
extern void bd_forget(struct inode *inode);
extern void bdput(struct block_device *);
extern void invalidate_bdev(struct block_device *);
next prev parent reply other threads:[~2012-05-27 1:06 UTC|newest]
Thread overview: 107+ messages / expand[flat|nested] mbox.gz Atom feed top
2012-05-27 1:03 [ 00/94] 3.3.8-stable review Greg KH
2012-05-27 1:04 ` [ 01/94] tilegx: enable SYSCALL_WRAPPERS support Greg KH
2012-05-27 1:04 ` [ 02/94] bio allocation failure due to bio_get_nr_vecs() Greg KH
2012-05-27 1:04 ` [ 03/94] block: fix buffer overflow when printing partition UUIDs Greg KH
2012-05-27 1:04 ` Greg KH [this message]
2012-05-27 1:04 ` [ 05/94] PARISC: fix PA1.1 oops on boot Greg KH
2012-05-27 1:04 ` [ 06/94] PARISC: fix crash in flush_icache_page_asm on PA1.1 Greg KH
2012-05-27 1:04 ` [ 07/94] PARISC: fix panic on prefetch(NULL) on PA7300LC Greg KH
2012-05-27 1:04 ` [ 08/94] isdn/gigaset: ratelimit CAPI message dumps Greg KH
2012-05-27 1:04 ` [ 09/94] vfs: make AIO use the proper rw_verify_area() area helpers Greg KH
2012-05-27 1:04 ` [ 10/94] iwlwifi: use 6000G2B for 6030 device series Greg KH
2012-05-27 13:38 ` Ben Hutchings
2012-06-01 7:01 ` Greg KH
2012-05-27 1:04 ` [ 11/94] iwlwifi: use correct released ucode version Greg KH
2012-05-27 1:04 ` [ 12/94] net/wireless: ipw2200: Fix WARN_ON occurring in wiphy_register called by ipw_pci_probe Greg KH
2012-05-27 19:47 ` Herton Ronaldo Krzesinski
2012-06-01 6:58 ` Greg KH
2012-05-27 1:04 ` [ 13/94] cfg80211: warn if db.txt is empty with CONFIG_CFG80211_INTERNAL_REGDB Greg KH
2012-05-27 1:04 ` [ 14/94] regulator: core: Release regulator-regulator supplies on error Greg KH
2012-05-27 1:04 ` [ 15/94] Fix blocking allocations called very early during bootup Greg KH
2012-05-27 1:04 ` [ 16/94] s390/pfault: fix task state race Greg KH
2012-05-27 1:04 ` [ 17/94] SCSI: mpt2sas: Fix for panic happening because of improper memory allocation Greg KH
2012-05-27 1:04 ` [ 18/94] isci: fix oem parameter validation on single controller skus Greg KH
2012-05-27 1:04 ` [ 19/94] RDMA/cxgb4: Always wake up waiters in c4iw_peer_abort_intr() Greg KH
2012-05-27 1:04 ` [ 20/94] RDMA/cxgb4: Use dst parameter in import_ep() Greg KH
2012-05-27 1:04 ` [ 21/94] RDMA/cxgb4: Drop peer_abort when no endpoint found Greg KH
2012-05-27 1:04 ` [ 22/94] powerpc: Fix broken cpu_idle_wait() implementation Greg KH
2012-05-27 1:04 ` [ 23/94] KEYS: Use the compat keyctl() syscall wrapper on Sparc64 for Sparc32 compat Greg KH
2012-05-27 1:04 ` [ 24/94] SELinux: if sel_make_bools errors dont leave inconsistent state Greg KH
2012-05-27 1:04 ` [ 25/94] IB/core: Fix mismatch between locked and pinned pages Greg KH
2012-05-27 1:04 ` [ 26/94] drivers/staging/comedi/comedi_fops.c: add missing vfree Greg KH
2012-05-27 1:04 ` [ 27/94] perf/x86: Update event scheduling constraints for AMD family 15h models Greg KH
2012-05-27 1:04 ` [ 28/94] mtd: sm_ftl: fix typo in major number Greg KH
2012-05-27 1:04 ` [ 29/94] libata: forbid port runtime pm by default, fixing regression Greg KH
2012-05-27 1:04 ` [ 30/94] ahci: Detect Marvell 88SE9172 SATA controller Greg KH
2012-05-27 1:04 ` [ 31/94] HID: wiimote: Fix IR data parser Greg KH
2012-05-27 1:04 ` [ 32/94] usbhid: prevent deadlock during timeout Greg KH
2012-05-27 1:04 ` [ 33/94] HID: logitech: read all 32 bits of report type bitfield Greg KH
2012-05-27 1:04 ` [ 34/94] um: Fix __swp_type() Greg KH
2012-05-27 1:04 ` [ 35/94] um: Implement a custom pte_same() function Greg KH
2012-05-27 1:04 ` [ 36/94] docs: update HOWTO for 2.6.x -> 3.x versioning Greg KH
2012-05-27 1:05 ` [ 37/94] swap: dont do discard if no discard option added Greg KH
2012-05-27 1:05 ` [ 38/94] USB: cdc-wdm: sanitize error returns Greg KH
2012-05-27 1:05 ` [ 39/94] USB: cdc-wdm: poll must return POLLHUP if device is gone Greg KH
2012-05-27 1:05 ` [ 40/94] workqueue: skip nr_running sanity check in worker_enter_idle() if trustee is active Greg KH
2012-05-27 1:05 ` [ 41/94] mm: mempolicy: Let vma_merge and vma_split handle vma->vm_policy linkages Greg KH
2012-05-27 1:05 ` [ 42/94] md: using GFP_NOIO to allocate bio for flush request Greg KH
2012-05-27 1:05 ` [ 43/94] Add missing call to uart_update_timeout() Greg KH
2012-05-27 1:05 ` [ 44/94] 8250_pci: fix pch uart matching Greg KH
2012-05-27 1:05 ` [ 45/94] tty: Allow uart_register/unregister/register Greg KH
2012-05-27 1:05 ` [ 46/94] USB: ftdi-sio: add support for Physik Instrumente E-861 Greg KH
2012-05-27 1:05 ` [ 47/94] usb-storage: unusual_devs entry for Yarvik PMP400 MP4 player Greg KH
2012-05-27 1:05 ` [ 48/94] USB: ffs-test: fix length argument of out function call Greg KH
2012-05-27 1:05 ` [ 49/94] drivers/rtc/rtc-pl031.c: configure correct wday for 2000-01-01 Greg KH
2012-05-27 1:05 ` [ 50/94] SCSI: hpsa: Fix problem with MSA2xxx devices Greg KH
2012-05-27 1:05 ` [ 51/94] udlfb: fix hcd_buffer_free panic on unplug/replug Greg KH
2012-05-27 1:05 ` [ 52/94] usb: usbtest: two super speed fixes for usbtest Greg KH
2012-05-27 1:05 ` [ 53/94] USB: ohci-at91: add a reset function to fix race condition Greg KH
2012-05-27 1:05 ` [ 54/94] USB: Remove races in devio.c Greg KH
2012-05-27 1:05 ` [ 55/94] USB: serial: ti_usb_3410_5052: Add support for the FRI2 serial console Greg KH
2012-05-27 1:05 ` [ 56/94] usb: gadget: fsl_udc_core: dTDs next dtd pointer need to be updated once written Greg KH
2012-05-27 1:05 ` [ 57/94] usb: add USB_QUIRK_RESET_RESUME for M-Audio 88es Greg KH
2012-05-27 1:05 ` [ 58/94] xhci: Add Lynx Point to list of Intel switchable hosts Greg KH
2012-05-27 1:05 ` [ 59/94] xhci: Avoid dead ports when CONFIG_USB_XHCI_HCD=n Greg KH
2012-05-27 1:05 ` [ 60/94] usb-xhci: Handle COMP_TX_ERR for isoc tds Greg KH
2012-05-27 1:05 ` [ 61/94] xhci: Reset reserved command ring TRBs on cleanup Greg KH
2012-05-27 1:05 ` [ 62/94] xhci: Add new short TX quirk for Fresco Logic host Greg KH
2012-05-27 1:05 ` [ 63/94] USB: fix resource leak in xhci power loss path Greg KH
2012-05-27 1:05 ` [ 64/94] usbcore: enable USB2 LPM if port suspend fails Greg KH
2012-05-27 1:05 ` [ 65/94] gma500: Fix Poulsbo suspend/resume crash on devices with SDVO ports Greg KH
2012-05-27 1:05 ` [ 66/94] b43legacy: Fix error due to MMIO access with SSB unpowered Greg KH
2012-05-27 1:05 ` [ 67/94] drm/i915: Avoid a double-read of PCH_IIR during interrupt handling Greg KH
2012-05-27 1:05 ` [ 68/94] drm/i915: [GEN7] Use HW scheduler for fixed function shaders Greg KH
2012-05-27 1:05 ` [ 69/94] drm/i915: dont clobber the pipe param in sanitize_modesetting Greg KH
2012-05-27 1:05 ` [ 70/94] gpio: mpc8xxx: Prevent NULL pointer deref in demux handler Greg KH
2012-05-27 1:05 ` [ 71/94] spi/spi-fsl-spi: reference correct pdata in fsl_spi_cs_control Greg KH
2012-05-28 19:44 ` Herton Ronaldo Krzesinski
2012-06-01 7:05 ` Greg KH
2012-05-27 1:05 ` [ 72/94] xen: do not map the same GSI twice in PVHVM guests Greg KH
2012-05-27 1:05 ` [ 73/94] nouveau: nouveau_set_bo_placement takes TTM flags Greg KH
2012-05-27 1:05 ` [ 74/94] [media] smsusb: add autodetection support for USB ID 2040:c0a0 Greg KH
2012-05-27 1:05 ` [ 75/94] media: uvcvideo: Fix ENUMINPUT handling Greg KH
2012-05-27 1:05 ` [ 76/94] x86, realmode: 16-bit real-mode code support for relocs tool Greg KH
2012-05-27 16:37 ` Ben Hutchings
2012-05-27 20:02 ` Greg KH
2012-05-27 1:05 ` [ 77/94] x86, relocs: Workaround for binutils 2.22.52.0.1 section bug Greg KH
2012-05-27 1:05 ` [ 78/94] x86, relocs: When printing an error, say relative or absolute Greg KH
2012-05-27 1:05 ` [ 79/94] x86, relocs: Build clean fix Greg KH
2012-05-27 1:05 ` [ 80/94] x86-32, relocs: Whitelist more symbols for ld bug workaround Greg KH
2012-05-27 1:05 ` [ 81/94] x86, relocs: Add jiffies and jiffies_64 to the relative whitelist Greg KH
2012-05-27 1:05 ` [ 82/94] x86/mce: Fix check for processor context when machine check was taken Greg KH
2012-05-27 1:05 ` [ 83/94] mmc: sdio: avoid spurious calls to interrupt handlers Greg KH
2012-05-27 1:05 ` [ 84/94] mmc: cd-gpio: protect against NULL context in mmc_cd_gpio_free() Greg KH
2012-05-27 1:05 ` [ 85/94] mmc: omap_hsmmc: pass IRQF_ONESHOT to request_threaded_irq Greg KH
2012-05-27 1:05 ` [ 86/94] tile: fix bug where fls(0) was not returning 0 Greg KH
2012-05-27 1:05 ` [ 87/94] intel-iommu: Add device info into list before doing context mapping Greg KH
2012-05-27 1:05 ` [ 88/94] iommu: Fix off by one in dmar_get_fault_reason() Greg KH
2012-05-27 1:05 ` [ 89/94] rtlwifi: fix for race condition when firmware is cached Greg KH
2012-05-28 20:21 ` Herton Ronaldo Krzesinski
2012-05-28 21:59 ` Larry Finger
2012-06-01 7:06 ` Greg KH
2012-05-27 1:05 ` [ 90/94] ARM: 7365/1: drop unused parameter from flush_cache_user_range Greg KH
2012-05-27 1:05 ` [ 91/94] ARM: 7409/1: Do not call flush_cache_user_range with mmap_sem held Greg KH
2012-05-27 1:05 ` [ 92/94] MCE: Fix vm86 handling for 32bit mce handler Greg KH
2012-05-27 1:05 ` [ 93/94] i2c: davinci: Free requested IRQ in remove Greg KH
2012-05-27 1:05 ` [ 94/94] i2c: tegra: notify transfer-complete after clearing status Greg KH
2012-05-27 1:11 ` [ 00/94] 3.3.8-stable review Greg KH
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20120527010424.356633491@linuxfoundation.org \
--to=gregkh@linuxfoundation.org \
--cc=akpm@linux-foundation.org \
--cc=alan@lxorguk.ukuu.org.uk \
--cc=axboe@kernel.dk \
--cc=jmoyer@redhat.com \
--cc=linux-kernel@vger.kernel.org \
--cc=npiggin@kernel.dk \
--cc=stable@vger.kernel.org \
--cc=torvalds@linux-foundation.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.