From mboxrd@z Thu Jan 1 00:00:00 1970 From: Bob Peterson Date: Mon, 3 Jul 2017 12:46:59 -0400 (EDT) Subject: [Cluster-devel] [GFS2 PATCH] GFS2: Prevent double brelse in gfs2_meta_indirect_buffer In-Reply-To: <1900718550.28426594.1499100383570.JavaMail.zimbra@redhat.com> Message-ID: <1874168289.28426650.1499100419665.JavaMail.zimbra@redhat.com> List-Id: To: cluster-devel.redhat.com MIME-Version: 1.0 Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: 7bit Hi, Before this patch, problems reading in indirect buffers would send an IO error back to the caller, and release the buffer_head with brelse() in function gfs2_meta_indirect_buffer, however, it would still return the address of the buffer_head it released. After the error was discovered, function gfs2_block_map would call function release_metapath to free all buffers. That checked: if (mp->mp_bh[i] == NULL) but since the value was set after the error, it was non-zero, so brelse was called a second time. This resulted in the following error: kernel: WARNING: at fs/buffer.c:1224 __brelse+0x3a/0x40() kernel: VFS: brelse: Trying to free free buffer This patch changes gfs2_meta_indirect_buffer so it only sets the buffer_head pointer in cases where it isn't released. Signed-off-by: Bob Peterson --- diff --git a/fs/gfs2/meta_io.c b/fs/gfs2/meta_io.c index 663ffc1..c7d2c76 100644 --- a/fs/gfs2/meta_io.c +++ b/fs/gfs2/meta_io.c @@ -419,8 +419,9 @@ int gfs2_meta_indirect_buffer(struct gfs2_inode *ip, int height, u64 num, if (ret == 0 && gfs2_metatype_check(sdp, bh, mtype)) { brelse(bh); ret = -EIO; + } else { + *bhp = bh; } - *bhp = bh; return ret; }