From: Sasha Levin <sashal@kernel.org>
To: Andreas Gruenbacher <agruenba@redhat.com>
Cc: Pavel Machek <pavel@denx.de>,
linux-kernel@vger.kernel.org, stable@vger.kernel.org,
gfs2@lists.linux.dev
Subject: Re: [PATCH AUTOSEL 4.19 11/12] gfs2: Refcounting fix in gfs2_thaw_super
Date: Tue, 30 Jan 2024 16:16:09 -0500 [thread overview]
Message-ID: <ZblnGTNLbufz4gZx@sashalap> (raw)
In-Reply-To: <CAHc6FU70RD8fktBp=Srv6xeq3qXoLCdT8pi6y=1Y7bMHFK-mtQ@mail.gmail.com>
On Thu, Jan 18, 2024 at 12:50:37PM +0100, Andreas Gruenbacher wrote:
>On Tue, Jan 16, 2024 at 9:53 PM Pavel Machek <pavel@denx.de> wrote:
>> Hi!
>>
>> > From: Andreas Gruenbacher <agruenba@redhat.com>
>> >
>> > [ Upstream commit 4e58543e7da4859c4ba61d15493e3522b6ad71fd ]
>> >
>> > It turns out that the .freeze_super and .thaw_super operations require
>> > the filesystem to manage the superblock refcount itself. We are using
>> > the freeze_super() and thaw_super() helpers to mostly take care of that
>> > for us, but this means that the superblock may no longer be around by
>> > when thaw_super() returns, and gfs2_thaw_super() will then access freed
>> > memory. Take an extra superblock reference in gfs2_thaw_super() to fix
>> > that.
>>
>> Patch was broken during backport.
>>
>> > +++ b/fs/gfs2/super.c
>> > @@ -1013,6 +1013,7 @@ static int gfs2_freeze(struct super_block *sb)
>> > goto out;
>> > }
>> >
>> > + atomic_inc(&sb->s_active);
>> > for (;;) {
>> > error = gfs2_lock_fs_check_clean(sdp, &sdp->sd_freeze_gh);
>> > if (!error)
>> > @@ -1034,6 +1035,7 @@ static int gfs2_freeze(struct super_block *sb)
>> > error = 0;
>> > out:
>> > mutex_unlock(&sdp->sd_freeze_mutex);
>> > + deactivate_super(sb);
>> > return error;
>> > }
>>
>> Notice the goto out? That now jumps around the atomic_inc, but we
>> still do decrease. This will break 4.19, please fix or drop.
>
>Thanks, Pavel.
>
>Sasha, you don't want that fix without "gfs2: Rework freeze / thaw
>logic" and the follow-up fixes, and backporting that probably isn't
>going to be worth it.
I'll drop it, thanks!
--
Thanks,
Sasha
next prev parent reply other threads:[~2024-01-30 21:16 UTC|newest]
Thread overview: 17+ messages / expand[flat|nested] mbox.gz Atom feed top
2024-01-16 0:27 [PATCH AUTOSEL 4.19 01/12] FS:JFS:UBSAN:array-index-out-of-bounds in dbAdjTree Sasha Levin
2024-01-16 0:27 ` [PATCH AUTOSEL 4.19 02/12] UBSAN: array-index-out-of-bounds in dtSplitRoot Sasha Levin
2024-01-16 0:27 ` [PATCH AUTOSEL 4.19 03/12] jfs: fix slab-out-of-bounds Read in dtSearch Sasha Levin
2024-01-16 0:27 ` [PATCH AUTOSEL 4.19 04/12] jfs: fix array-index-out-of-bounds in dbAdjTree Sasha Levin
2024-01-16 0:27 ` [PATCH AUTOSEL 4.19 05/12] jfs: fix uaf in jfs_evict_inode Sasha Levin
2024-01-16 0:27 ` [PATCH AUTOSEL 4.19 06/12] jfs: fix shift-out-of-bounds in dbJoin Sasha Levin
2024-01-16 0:28 ` [PATCH AUTOSEL 4.19 07/12] pstore/ram: Fix crash when setting number of cpus to an odd number Sasha Levin
2024-01-16 0:28 ` Sasha Levin
2024-01-16 0:28 ` [PATCH AUTOSEL 4.19 08/12] crypto: stm32/crc32 - fix parsing list of devices Sasha Levin
2024-01-16 0:28 ` Sasha Levin
2024-01-16 0:28 ` [PATCH AUTOSEL 4.19 09/12] afs: fix the usage of read_seqbegin_or_lock() in afs_find_server*() Sasha Levin
2024-01-16 0:28 ` [PATCH AUTOSEL 4.19 10/12] rxrpc_find_service_conn_rcu: fix the usage of read_seqbegin_or_lock() Sasha Levin
2024-01-16 0:28 ` [PATCH AUTOSEL 4.19 11/12] gfs2: Refcounting fix in gfs2_thaw_super Sasha Levin
2024-01-16 20:46 ` Pavel Machek
2024-01-18 11:50 ` Andreas Gruenbacher
2024-01-30 21:16 ` Sasha Levin [this message]
2024-01-16 0:28 ` [PATCH AUTOSEL 4.19 12/12] jfs: fix array-index-out-of-bounds in diNewExt Sasha Levin
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=ZblnGTNLbufz4gZx@sashalap \
--to=sashal@kernel.org \
--cc=agruenba@redhat.com \
--cc=gfs2@lists.linux.dev \
--cc=linux-kernel@vger.kernel.org \
--cc=pavel@denx.de \
--cc=stable@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.