* Oops when calling fsync on read-only file-system
@ 2011-04-12 1:32 Reuben Dowle
2011-04-13 7:31 ` Artem Bityutskiy
0 siblings, 1 reply; 2+ messages in thread
From: Reuben Dowle @ 2011-04-12 1:32 UTC (permalink / raw)
To: linux-mtd
On my system, calling the fsync system call on any file in a UBI file-system that is mounted read-only leads to a kernel oops. Our system is running a customise version of 2.6.31, but as far as I can see (without testing which is not possible due to extensive vendor customisation of .31 kernel version), the current git branch also contains this bug.
I have created a patch against 2.6.31 that fixes the problem in my system. Perhaps someone could test on latest kernel version.
Signed-off-by: Reuben Dowle <reuben.dowle at navico.com>
---
--- linux-2.6.31.orig/fs/ubifs/io.c 2009-09-10 10:13:59.000000000 +1200
+++ linux-2.6.31/fs/ubifs/io.c 2011-04-11 15:43:50.026527002 +1200
@@ -916,6 +916,14 @@
{
int i, err = 0;
+ /* If this is a read-only mount, write buffers will be null
+ * Skip the sync, returning success (even though this is an invalid operation
+ * on a read-only file-system, return success because all data on flash
+ * is up to date)
+ */
+ if(!c->jheads)
+ return 0;
+
for (i = 0; i < c->jhead_cnt; i++) {
struct ubifs_wbuf *wbuf = &c->jheads[i].wbuf;
---
^ permalink raw reply [flat|nested] 2+ messages in thread
* Re: Oops when calling fsync on read-only file-system
2011-04-12 1:32 Oops when calling fsync on read-only file-system Reuben Dowle
@ 2011-04-13 7:31 ` Artem Bityutskiy
0 siblings, 0 replies; 2+ messages in thread
From: Artem Bityutskiy @ 2011-04-13 7:31 UTC (permalink / raw)
To: Reuben Dowle; +Cc: linux-mtd
Hi,
thanks a lot for reporting this!
On Tue, 2011-04-12 at 13:32 +1200, Reuben Dowle wrote:
> On my system, calling the fsync system call on any file in a UBI
> file-system that is mounted read-only leads to a kernel oops. Our
> system is running a customise version of 2.6.31, but as far as I can
> see (without testing which is not possible due to extensive vendor
> customisation of .31 kernel version), the current git branch also
> contains this bug.
>
> I have created a patch against 2.6.31 that fixes the problem in my
> system. Perhaps someone could test on latest kernel version.
>
> Signed-off-by: Reuben Dowle <reuben.dowle at navico.com>
Wow! Shame on me for this bug! And it is funny that it is there for
several years already and there are product with this bug! Here is the
fix which I will merge upstream soon:
From: Artem Bityutskiy <Artem.Bityutskiy@nokia.com>
Subject: [PATCH] UBIFS: fix oops when R/O file-system is fsync'ed
This patch fixes severe UBIFS bug: UBIFS oopses when we 'fsync()' an
file on R/O-mounter file-system. We (the UBIFS authors) incorrectly
thought that VFS would not propagate 'fsync()' down to the file-system
if it is read-only, but this is not the case.
It is easy to exploit this bug using the following simple perl script:
use strict;
use File::Sync qw(fsync sync);
die "File path is not specified" if not defined $ARGV[0];
my $path = $ARGV[0];
open FILE, "<", "$path" or die "Cannot open $path: $!";
fsync(\*FILE) or die "cannot fsync $path: $!";
close FILE or die "Cannot close $path: $!";
Thanks to Reuben Dowle <Reuben.Dowle@navico.com> for reporting about this
issue.
Signed-off-by: Artem Bityutskiy <Artem.Bityutskiy@nokia.com>
Reported-by: Reuben Dowle <Reuben.Dowle@navico.com>
Cc: stable@kernel.org
---
fs/ubifs/file.c | 3 +++
1 files changed, 3 insertions(+), 0 deletions(-)
diff --git a/fs/ubifs/file.c b/fs/ubifs/file.c
index a2b5012..3594aae 100644
--- a/fs/ubifs/file.c
+++ b/fs/ubifs/file.c
@@ -1312,6 +1312,9 @@ int ubifs_fsync(struct file *file, int datasync)
dbg_gen("syncing inode %lu", inode->i_ino);
+ if (inode->i_sb->s_flags & MS_RDONLY)
+ return 0;
+
/*
* VFS has already synchronized dirty pages for this inode. Synchronize
* the inode unless this is a 'datasync()' call.
--
1.7.2.3
--
Best Regards,
Artem Bityutskiy (Артём Битюцкий)
^ permalink raw reply related [flat|nested] 2+ messages in thread
end of thread, other threads:[~2011-04-13 7:34 UTC | newest]
Thread overview: 2+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2011-04-12 1:32 Oops when calling fsync on read-only file-system Reuben Dowle
2011-04-13 7:31 ` Artem Bityutskiy
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).