linux-mtd.lists.infradead.org archive mirror
 help / color / mirror / Atom feed
* Oops when calling fsync on read-only file-system
@ 2011-04-12  1:32 Reuben Dowle
  2011-04-13  7:31 ` Artem Bityutskiy
  0 siblings, 1 reply; 2+ messages in thread
From: Reuben Dowle @ 2011-04-12  1:32 UTC (permalink / raw)
  To: linux-mtd

On my system, calling the fsync system call on any file in a UBI file-system that is mounted read-only leads to a kernel oops. Our system is running a customise version of 2.6.31, but as far as I can see (without testing which is not possible due to extensive vendor customisation of .31 kernel version), the current git branch also contains this bug.

I have created a patch against 2.6.31 that fixes the problem in my system. Perhaps someone could test on latest kernel version.

Signed-off-by: Reuben Dowle <reuben.dowle at navico.com>
---
--- linux-2.6.31.orig/fs/ubifs/io.c	2009-09-10 10:13:59.000000000 +1200
+++ linux-2.6.31/fs/ubifs/io.c	2011-04-11 15:43:50.026527002 +1200
@@ -916,6 +916,14 @@
 {
 	int i, err = 0;
 
+	/* If this is a read-only mount, write buffers will be null
+	 * Skip the sync, returning success (even though this is an invalid operation
+	 * on a read-only file-system, return success because all data on flash
+	 * is up to date)
+	 */
+	if(!c->jheads)
+		return 0;
+
 	for (i = 0; i < c->jhead_cnt; i++) {
 		struct ubifs_wbuf *wbuf = &c->jheads[i].wbuf;
 
---

^ permalink raw reply	[flat|nested] 2+ messages in thread

* Re: Oops when calling fsync on read-only file-system
  2011-04-12  1:32 Oops when calling fsync on read-only file-system Reuben Dowle
@ 2011-04-13  7:31 ` Artem Bityutskiy
  0 siblings, 0 replies; 2+ messages in thread
From: Artem Bityutskiy @ 2011-04-13  7:31 UTC (permalink / raw)
  To: Reuben Dowle; +Cc: linux-mtd

Hi,

thanks a lot for reporting this!
On Tue, 2011-04-12 at 13:32 +1200, Reuben Dowle wrote:
> On my system, calling the fsync system call on any file in a UBI
> file-system that is mounted read-only leads to a kernel oops. Our
> system is running a customise version of 2.6.31, but as far as I can
> see (without testing which is not possible due to extensive vendor
> customisation of .31 kernel version), the current git branch also
> contains this bug.
> 
> I have created a patch against 2.6.31 that fixes the problem in my
> system. Perhaps someone could test on latest kernel version.
> 
> Signed-off-by: Reuben Dowle <reuben.dowle at navico.com>

Wow! Shame on me for this bug! And it is funny that it is there for
several years already and there are product with this bug! Here is the
fix which I will merge upstream soon:


From: Artem Bityutskiy <Artem.Bityutskiy@nokia.com>
Subject: [PATCH] UBIFS: fix oops when R/O file-system is fsync'ed

This patch fixes severe UBIFS bug: UBIFS oopses when we 'fsync()' an
file on R/O-mounter file-system. We (the UBIFS authors) incorrectly
thought that VFS would not propagate 'fsync()' down to the file-system
if it is read-only, but this is not the case.

It is easy to exploit this bug using the following simple perl script:

use strict;
use File::Sync qw(fsync sync);

die "File path is not specified" if not defined $ARGV[0];
my $path = $ARGV[0];

open FILE, "<", "$path" or die "Cannot open $path: $!";
fsync(\*FILE) or die "cannot fsync $path: $!";
close FILE or die "Cannot close $path: $!";

Thanks to Reuben Dowle <Reuben.Dowle@navico.com> for reporting about this
issue.

Signed-off-by: Artem Bityutskiy <Artem.Bityutskiy@nokia.com>
Reported-by: Reuben Dowle <Reuben.Dowle@navico.com>
Cc: stable@kernel.org
---
 fs/ubifs/file.c |    3 +++
 1 files changed, 3 insertions(+), 0 deletions(-)

diff --git a/fs/ubifs/file.c b/fs/ubifs/file.c
index a2b5012..3594aae 100644
--- a/fs/ubifs/file.c
+++ b/fs/ubifs/file.c
@@ -1312,6 +1312,9 @@ int ubifs_fsync(struct file *file, int datasync)
 
 	dbg_gen("syncing inode %lu", inode->i_ino);
 
+	if (inode->i_sb->s_flags & MS_RDONLY)
+		return 0;
+
 	/*
 	 * VFS has already synchronized dirty pages for this inode. Synchronize
 	 * the inode unless this is a 'datasync()' call.
-- 
1.7.2.3

-- 
Best Regards,
Artem Bityutskiy (Артём Битюцкий)

^ permalink raw reply related	[flat|nested] 2+ messages in thread

end of thread, other threads:[~2011-04-13  7:34 UTC | newest]

Thread overview: 2+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2011-04-12  1:32 Oops when calling fsync on read-only file-system Reuben Dowle
2011-04-13  7:31 ` Artem Bityutskiy

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).