* [BUG] general protection fault in orangefs_writepages
@ 2026-08-28 5:45 Farhad Alemi
2026-09-02 0:41 ` Mike Marshall
2026-09-08 15:41 ` [PATCH] orangefs: don't continue on to gpf if client dies on write hubcap
0 siblings, 2 replies; 3+ messages in thread
From: Farhad Alemi @ 2026-08-28 5:45 UTC (permalink / raw)
To: Mike Marshall, Alexander Viro, Christian Brauner
Cc: falemi, devel, linux-fsdevel, linux-kernel
Hello,
As part of the kernel research at ASU's SEFCOM
lab, we hit the crash below. Crash reports can be found here:
https://github.com/farhad-alemi/public_bug_reports/tree/main/176-general-protection-fault-in-orangefs-writepages/
Oops: general protection fault, probably for non-canonical address
0xdffffc0000000002: 0000 [#1] SMP KASAN NOPTI
KASAN: null-ptr-deref in range [0x0000000000000010-0x0000000000000017]
RIP: 0010:orangefs_writepages_callback fs/orangefs/inode.c:144 [inline]
RIP: 0010:orangefs_writepages+0x642/0xc60 fs/orangefs/inode.c:205
Call Trace:
orangefs_writepages+0x642/0xc60 fs/orangefs/inode.c:205
do_writepages+0x328/0x550 mm/page-writeback.c:2571
filemap_write_and_wait_range+0x332/0x3f0 mm/filemap.c:685
orangefs_flush+0x44/0x60 fs/orangefs/file.c:566
filp_flush+0xbd/0x190 fs/open.c:1467
filp_close+0x1d/0x40 fs/open.c:1480
close_files fs/file.c:494 [inline]
put_files_struct+0x1b6/0x340 fs/file.c:509
do_exit+0x6a8/0x2360 kernel/exit.c:971
Our reproducer.c is available upon request.
Happy to test a patch if that would help.
Regards,
^ permalink raw reply [flat|nested] 3+ messages in thread
* Re: [BUG] general protection fault in orangefs_writepages
2026-08-28 5:45 [BUG] general protection fault in orangefs_writepages Farhad Alemi
@ 2026-09-02 0:41 ` Mike Marshall
2026-09-08 15:41 ` [PATCH] orangefs: don't continue on to gpf if client dies on write hubcap
1 sibling, 0 replies; 3+ messages in thread
From: Mike Marshall @ 2026-09-02 0:41 UTC (permalink / raw)
To: Farhad Alemi
Cc: Alexander Viro, Christian Brauner, falemi, devel, linux-fsdevel,
linux-kernel, Mike Marshall
Thanks for the oops report. I have a potential patch. Please
send your reproducer program.
-Mike
On Fri, Aug 28, 2026 at 2:11 AM Farhad Alemi <farhad.alemi@berkeley.edu> wrote:
>
> Hello,
>
> As part of the kernel research at ASU's SEFCOM
> lab, we hit the crash below. Crash reports can be found here:
>
> https://github.com/farhad-alemi/public_bug_reports/tree/main/176-general-protection-fault-in-orangefs-writepages/
>
> Oops: general protection fault, probably for non-canonical address
> 0xdffffc0000000002: 0000 [#1] SMP KASAN NOPTI
> KASAN: null-ptr-deref in range [0x0000000000000010-0x0000000000000017]
> RIP: 0010:orangefs_writepages_callback fs/orangefs/inode.c:144 [inline]
> RIP: 0010:orangefs_writepages+0x642/0xc60 fs/orangefs/inode.c:205
> Call Trace:
> orangefs_writepages+0x642/0xc60 fs/orangefs/inode.c:205
> do_writepages+0x328/0x550 mm/page-writeback.c:2571
> filemap_write_and_wait_range+0x332/0x3f0 mm/filemap.c:685
> orangefs_flush+0x44/0x60 fs/orangefs/file.c:566
> filp_flush+0xbd/0x190 fs/open.c:1467
> filp_close+0x1d/0x40 fs/open.c:1480
> close_files fs/file.c:494 [inline]
> put_files_struct+0x1b6/0x340 fs/file.c:509
> do_exit+0x6a8/0x2360 kernel/exit.c:971
>
> Our reproducer.c is available upon request.
>
> Happy to test a patch if that would help.
>
> Regards,
>
^ permalink raw reply [flat|nested] 3+ messages in thread
* [PATCH] orangefs: don't continue on to gpf if client dies on write.
2026-08-28 5:45 [BUG] general protection fault in orangefs_writepages Farhad Alemi
2026-09-02 0:41 ` Mike Marshall
@ 2026-09-08 15:41 ` hubcap
1 sibling, 0 replies; 3+ messages in thread
From: hubcap @ 2026-09-08 15:41 UTC (permalink / raw)
To: linux-fsdevel; +Cc: Mike Marshall, devel, farhad.alemi, viro, brauner
From: Mike Marshall <hubcap@omnibond.com>
I got a message from Farhad Alemi (farhad.alemi@berkeley.edu)
showing that this can happen:
Oops: general protection fault, probably for non-canonical address
0xdffffc0000000002: 0000 [#1] SMP KASAN NOPTI
KASAN: null-ptr-deref in range [0x0000000000000010-0x0000000000000017]
RIP: 0010:orangefs_writepages_callback fs/orangefs/inode.c:144 [inline]
RIP: 0010:orangefs_writepages+0x642/0xc60 fs/orangefs/inode.c:205
Call Trace:
orangefs_writepages+0x642/0xc60 fs/orangefs/inode.c:205
do_writepages+0x328/0x550 mm/page-writeback.c:2571
filemap_write_and_wait_range+0x332/0x3f0 mm/filemap.c:685
orangefs_flush+0x44/0x60 fs/orangefs/file.c:566
filp_flush+0xbd/0x190 fs/open.c:1467
filp_close+0x1d/0x40 fs/open.c:1480
close_files fs/file.c:494 [inline]
put_files_struct+0x1b6/0x340 fs/file.c:509
do_exit+0x6a8/0x2360 kernel/exit.c:971
With the help of Grok I created a reproducer program that
causes a gpf on the same line: "ow->folios[ow->nfolios++] = folio;"
in orangefs_writepages_callback. The reproducer program flows into
this new code after this patch.
Signed-off-by: Mike Marshall <hubcap@omnibond.com>
---
fs/orangefs/inode.c | 21 ++++++++++++++++++++-
1 file changed, 20 insertions(+), 1 deletion(-)
diff --git a/fs/orangefs/inode.c b/fs/orangefs/inode.c
index cd3273c88e03..c088a02e8215 100644
--- a/fs/orangefs/inode.c
+++ b/fs/orangefs/inode.c
@@ -181,8 +181,27 @@ static int orangefs_writepages(struct address_space *mapping,
{
struct orangefs_writepages *ow;
struct blk_plug plug;
- int error;
+ int error = 0;
struct folio *folio = NULL;
+ int maxpages;
+
+ maxpages = orangefs_bufmap_size_query() / PAGE_SIZE;
+ if (maxpages < 1) {
+ /*
+ * Probably the client is dead and there's no bufmap.
+ * Walk writeback_iter anyway so each dirty folio is unlocked
+ * and writeback is ended. wait_for_direct_io will fail; the
+ * data is not written.
+ */
+ gossip_err("%s: maxpages < 1. \n", __func__);
+ while ((folio = writeback_iter(mapping, wbc, folio, &error))) {
+ error = orangefs_writepage_locked(folio, wbc);
+ mapping_set_error(mapping, error);
+ folio_unlock(folio);
+ folio_end_writeback(folio);
+ }
+ return error;
+ }
ow = kzalloc_obj(struct orangefs_writepages);
if (!ow)
--
2.55.0
^ permalink raw reply related [flat|nested] 3+ messages in thread
end of thread, other threads:[~2026-09-08 15:42 UTC | newest]
Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-08-28 5:45 [BUG] general protection fault in orangefs_writepages Farhad Alemi
2026-09-02 0:41 ` Mike Marshall
2026-09-08 15:41 ` [PATCH] orangefs: don't continue on to gpf if client dies on write hubcap
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox