All of lore.kernel.org
 help / color / mirror / Atom feed
From: Pavel Machek <pavel@denx.de>
To: Sasha Levin <sashal@kernel.org>
Cc: linux-kernel@vger.kernel.org, stable@vger.kernel.org,
	Andreas Gruenbacher <agruenba@redhat.com>,
	gfs2@lists.linux.dev
Subject: Re: [PATCH AUTOSEL 4.19 11/12] gfs2: Refcounting fix in gfs2_thaw_super
Date: Tue, 16 Jan 2024 21:46:54 +0100	[thread overview]
Message-ID: <ZabrPnsVr6WHz2lM@duo.ucw.cz> (raw)
In-Reply-To: <20240116002817.216837-11-sashal@kernel.org>

[-- Attachment #1: Type: text/plain, Size: 1371 bytes --]

Hi!

> From: Andreas Gruenbacher <agruenba@redhat.com>
> 
> [ Upstream commit 4e58543e7da4859c4ba61d15493e3522b6ad71fd ]
> 
> It turns out that the .freeze_super and .thaw_super operations require
> the filesystem to manage the superblock refcount itself.  We are using
> the freeze_super() and thaw_super() helpers to mostly take care of that
> for us, but this means that the superblock may no longer be around by
> when thaw_super() returns, and gfs2_thaw_super() will then access freed
> memory.  Take an extra superblock reference in gfs2_thaw_super() to fix
> that.

Patch was broken during backport.

> +++ b/fs/gfs2/super.c
> @@ -1013,6 +1013,7 @@ static int gfs2_freeze(struct super_block *sb)
>  		goto out;
>  	}
>  
> +	atomic_inc(&sb->s_active);
>  	for (;;) {
>  		error = gfs2_lock_fs_check_clean(sdp, &sdp->sd_freeze_gh);
>  		if (!error)
> @@ -1034,6 +1035,7 @@ static int gfs2_freeze(struct super_block *sb)
>  	error = 0;
>  out:
>  	mutex_unlock(&sdp->sd_freeze_mutex);
> +	deactivate_super(sb);
>  	return error;
>  }

Notice the goto out? That now jumps around the atomic_inc, but we
still do decrease. This will break 4.19, please fix or drop.

BR,
								Pavel
-- 
DENX Software Engineering GmbH,        Managing Director: Erika Unter
HRB 165235 Munich, Office: Kirchenstr.5, D-82194 Groebenzell, Germany

[-- Attachment #2: signature.asc --]
[-- Type: application/pgp-signature, Size: 195 bytes --]

  reply	other threads:[~2024-01-16 20:46 UTC|newest]

Thread overview: 17+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2024-01-16  0:27 [PATCH AUTOSEL 4.19 01/12] FS:JFS:UBSAN:array-index-out-of-bounds in dbAdjTree Sasha Levin
2024-01-16  0:27 ` [PATCH AUTOSEL 4.19 02/12] UBSAN: array-index-out-of-bounds in dtSplitRoot Sasha Levin
2024-01-16  0:27 ` [PATCH AUTOSEL 4.19 03/12] jfs: fix slab-out-of-bounds Read in dtSearch Sasha Levin
2024-01-16  0:27 ` [PATCH AUTOSEL 4.19 04/12] jfs: fix array-index-out-of-bounds in dbAdjTree Sasha Levin
2024-01-16  0:27 ` [PATCH AUTOSEL 4.19 05/12] jfs: fix uaf in jfs_evict_inode Sasha Levin
2024-01-16  0:27 ` [PATCH AUTOSEL 4.19 06/12] jfs: fix shift-out-of-bounds in dbJoin Sasha Levin
2024-01-16  0:28 ` [PATCH AUTOSEL 4.19 07/12] pstore/ram: Fix crash when setting number of cpus to an odd number Sasha Levin
2024-01-16  0:28   ` Sasha Levin
2024-01-16  0:28 ` [PATCH AUTOSEL 4.19 08/12] crypto: stm32/crc32 - fix parsing list of devices Sasha Levin
2024-01-16  0:28   ` Sasha Levin
2024-01-16  0:28 ` [PATCH AUTOSEL 4.19 09/12] afs: fix the usage of read_seqbegin_or_lock() in afs_find_server*() Sasha Levin
2024-01-16  0:28 ` [PATCH AUTOSEL 4.19 10/12] rxrpc_find_service_conn_rcu: fix the usage of read_seqbegin_or_lock() Sasha Levin
2024-01-16  0:28 ` [PATCH AUTOSEL 4.19 11/12] gfs2: Refcounting fix in gfs2_thaw_super Sasha Levin
2024-01-16 20:46   ` Pavel Machek [this message]
2024-01-18 11:50     ` Andreas Gruenbacher
2024-01-30 21:16       ` Sasha Levin
2024-01-16  0:28 ` [PATCH AUTOSEL 4.19 12/12] jfs: fix array-index-out-of-bounds in diNewExt Sasha Levin

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=ZabrPnsVr6WHz2lM@duo.ucw.cz \
    --to=pavel@denx.de \
    --cc=agruenba@redhat.com \
    --cc=gfs2@lists.linux.dev \
    --cc=linux-kernel@vger.kernel.org \
    --cc=sashal@kernel.org \
    --cc=stable@vger.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.