From: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
To: linux-kernel@vger.kernel.org
Cc: Greg Kroah-Hartman <gregkh@linuxfoundation.org>,
stable@vger.kernel.org, Junxiao Bi <junxiao.bi@oracle.com>,
Wengang Wang <wen.gang.wang@oracle.com>,
Sunil Mushran <sunil.mushran@gmail.com>,
Srinivas Eeda <srinivas.eeda@oracle.com>,
Joel Becker <jlbec@evilplan.org>, Mark Fasheh <mfasheh@suse.com>,
Andrew Morton <akpm@linux-foundation.org>,
Linus Torvalds <torvalds@linux-foundation.org>
Subject: [PATCH 3.10 81/86] ocfs2: dlm: fix lock migration crash
Date: Sun, 4 May 2014 11:41:56 -0400 [thread overview]
Message-ID: <20140504154151.450775598@linuxfoundation.org> (raw)
In-Reply-To: <20140504154140.444932005@linuxfoundation.org>
3.10-stable review patch. If anyone has any objections, please let me know.
------------------
From: Junxiao Bi <junxiao.bi@oracle.com>
commit 34aa8dac482f1358d59110d5e3a12f4351f6acaa upstream.
This issue was introduced by commit 800deef3f6f8 ("ocfs2: use
list_for_each_entry where benefical") in 2007 where it replaced
list_for_each with list_for_each_entry. The variable "lock" will point
to invalid data if "tmpq" list is empty and a panic will be triggered
due to this. Sunil advised reverting it back, but the old version was
also not right. At the end of the outer for loop, that
list_for_each_entry will also set "lock" to an invalid data, then in the
next loop, if the "tmpq" list is empty, "lock" will be an stale invalid
data and cause the panic. So reverting the list_for_each back and reset
"lock" to NULL to fix this issue.
Another concern is that this seemes can not happen because the "tmpq"
list should not be empty. Let me describe how.
old lock resource owner(node 1): migratation target(node 2):
image there's lockres with a EX lock from node 2 in
granted list, a NR lock from node x with convert_type
EX in converting list.
dlm_empty_lockres() {
dlm_pick_migration_target() {
pick node 2 as target as its lock is the first one
in granted list.
}
dlm_migrate_lockres() {
dlm_mark_lockres_migrating() {
res->state |= DLM_LOCK_RES_BLOCK_DIRTY;
wait_event(dlm->ast_wq, !dlm_lockres_is_dirty(dlm, res));
//after the above code, we can not dirty lockres any more,
// so dlm_thread shuffle list will not run
downconvert lock from EX to NR
upconvert lock from NR to EX
<<< migration may schedule out here, then
<<< node 2 send down convert request to convert type from EX to
<<< NR, then send up convert request to convert type from NR to
<<< EX, at this time, lockres granted list is empty, and two locks
<<< in the converting list, node x up convert lock followed by
<<< node 2 up convert lock.
// will set lockres RES_MIGRATING flag, the following
// lock/unlock can not run
dlm_lockres_release_ast(dlm, res);
}
dlm_send_one_lockres()
dlm_process_recovery_data()
for (i=0; i<mres->num_locks; i++)
if (ml->node == dlm->node_num)
for (j = DLM_GRANTED_LIST; j <= DLM_BLOCKED_LIST; j++) {
list_for_each_entry(lock, tmpq, list)
if (lock) break; <<< lock is invalid as grant list is empty.
}
if (lock->ml.node != ml->node)
BUG() >>> crash here
}
I see the above locks status from a vmcore of our internal bug.
Signed-off-by: Junxiao Bi <junxiao.bi@oracle.com>
Reviewed-by: Wengang Wang <wen.gang.wang@oracle.com>
Cc: Sunil Mushran <sunil.mushran@gmail.com>
Reviewed-by: Srinivas Eeda <srinivas.eeda@oracle.com>
Cc: Joel Becker <jlbec@evilplan.org>
Cc: Mark Fasheh <mfasheh@suse.com>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
fs/ocfs2/dlm/dlmrecovery.c | 14 ++++++++------
1 file changed, 8 insertions(+), 6 deletions(-)
--- a/fs/ocfs2/dlm/dlmrecovery.c
+++ b/fs/ocfs2/dlm/dlmrecovery.c
@@ -1751,13 +1751,13 @@ static int dlm_process_recovery_data(str
struct dlm_migratable_lockres *mres)
{
struct dlm_migratable_lock *ml;
- struct list_head *queue;
+ struct list_head *queue, *iter;
struct list_head *tmpq = NULL;
struct dlm_lock *newlock = NULL;
struct dlm_lockstatus *lksb = NULL;
int ret = 0;
int i, j, bad;
- struct dlm_lock *lock = NULL;
+ struct dlm_lock *lock;
u8 from = O2NM_MAX_NODES;
unsigned int added = 0;
__be64 c;
@@ -1792,14 +1792,16 @@ static int dlm_process_recovery_data(str
/* MIGRATION ONLY! */
BUG_ON(!(mres->flags & DLM_MRES_MIGRATION));
+ lock = NULL;
spin_lock(&res->spinlock);
for (j = DLM_GRANTED_LIST; j <= DLM_BLOCKED_LIST; j++) {
tmpq = dlm_list_idx_to_ptr(res, j);
- list_for_each_entry(lock, tmpq, list) {
- if (lock->ml.cookie != ml->cookie)
- lock = NULL;
- else
+ list_for_each(iter, tmpq) {
+ lock = list_entry(iter,
+ struct dlm_lock, list);
+ if (lock->ml.cookie == ml->cookie)
break;
+ lock = NULL;
}
if (lock)
break;
next prev parent reply other threads:[~2014-05-04 15:41 UTC|newest]
Thread overview: 95+ messages / expand[flat|nested] mbox.gz Atom feed top
2014-05-04 15:40 [PATCH 3.10 00/86] 3.10.39-stable review Greg Kroah-Hartman
2014-05-04 15:40 ` [PATCH 3.10 01/86] arm64: Do not synchronise I and D caches for special ptes Greg Kroah-Hartman
2014-05-04 15:40 ` [PATCH 3.10 02/86] arm64: Make DMA coherent and strongly ordered mappings not executable Greg Kroah-Hartman
2014-05-04 15:40 ` [PATCH 3.10 03/86] ASoC: cs42l51: Fix SOC_DOUBLE_R_SX_TLV shift values for ADC, PCM, and Analog kcontrols Greg Kroah-Hartman
2014-05-04 15:40 ` [PATCH 3.10 04/86] ASoC: cs42l52: Fix mask bits for SOC_VALUE_ENUM_SINGLE Greg Kroah-Hartman
2014-05-04 15:40 ` [PATCH 3.10 05/86] ASoC: cs42l73: " Greg Kroah-Hartman
2014-05-04 15:40 ` [PATCH 3.10 06/86] ARM: OMAP2+: INTC: Acknowledge stuck active interrupts Greg Kroah-Hartman
2014-05-04 15:40 ` [PATCH 3.10 07/86] ARM: OMAP4: Fix definition of IS_PM44XX_ERRATUM Greg Kroah-Hartman
2014-05-04 15:40 ` [PATCH 3.10 08/86] ARM: OMAP3: hwmod data: Correct clock domains for USB modules Greg Kroah-Hartman
2014-05-04 15:40 ` [PATCH 3.10 09/86] ARM: dts: Keep G3D regulator always on for exynos5250-arndale Greg Kroah-Hartman
2014-05-04 15:40 ` [PATCH 3.10 10/86] ARM: 7954/1: mm: remove remaining domain support from ARMv6 Greg Kroah-Hartman
2014-05-04 15:40 ` [PATCH 3.10 11/86] ARM: 8007/1: Remove extraneous kcmp syscall ignore Greg Kroah-Hartman
2014-05-04 15:40 ` [PATCH 3.10 12/86] ARM: 8027/1: fix do_div() bug in big-endian systems Greg Kroah-Hartman
2014-05-04 15:40 ` [PATCH 3.10 13/86] ARM: 8030/1: ARM : kdump : add arch_crash_save_vmcoreinfo Greg Kroah-Hartman
2014-05-04 15:40 ` [PATCH 3.10 14/86] ARM: mvebu: ensure the mdio node has a clock reference on Armada 370/XP Greg Kroah-Hartman
2014-05-04 15:40 ` [PATCH 3.10 15/86] ARM: 7728/1: mm: Use phys_addr_t properly for ioremap functions Greg Kroah-Hartman
2014-05-04 15:40 ` [PATCH 3.10 16/86] ALSA: hda - Enable beep for ASUS 1015E Greg Kroah-Hartman
2014-05-04 15:40 ` [PATCH 3.10 17/86] ALSA: ice1712: Fix boundary checks in PCM pointer ops Greg Kroah-Hartman
2014-05-04 15:40 ` [PATCH 3.10 18/86] ALSA: hda - Fix silent speaker output due to mute LED fixup Greg Kroah-Hartman
2014-05-04 15:40 ` [PATCH 3.10 19/86] ALSA: hda/realtek - Add support of ALC288 codec Greg Kroah-Hartman
2014-05-04 15:40 ` [PATCH 3.10 20/86] s390/cio: fix driver callback initialization for ccw consoles Greg Kroah-Hartman
2014-05-04 15:40 ` [PATCH 3.10 21/86] mei: me: do not load the driver if the FW doesnt support MEI interface Greg Kroah-Hartman
2014-05-04 15:40 ` [PATCH 3.10 22/86] mfd: sec-core: Fix possible NULL pointer dereference when i2c_new_dummy error Greg Kroah-Hartman
2014-05-04 15:40 ` [PATCH 3.10 23/86] mfd: 88pm860x: Fix possible NULL pointer dereference on " Greg Kroah-Hartman
2014-05-04 15:40 ` [PATCH 3.10 24/86] mfd: 88pm860x: Fix I2C device resource leak on regmap init fail Greg Kroah-Hartman
2014-05-04 15:41 ` [PATCH 3.10 25/86] mfd: max77686: Fix possible NULL pointer dereference on i2c_new_dummy error Greg Kroah-Hartman
2014-05-04 15:41 ` [PATCH 3.10 26/86] mfd: max77693: " Greg Kroah-Hartman
2014-05-04 15:41 ` [PATCH 3.10 27/86] mfd: max8925: " Greg Kroah-Hartman
2014-05-04 15:41 ` [PATCH 3.10 28/86] mfd: max8998: " Greg Kroah-Hartman
2014-05-04 15:41 ` [PATCH 3.10 29/86] mfd: max8997: " Greg Kroah-Hartman
2014-05-04 15:41 ` [PATCH 3.10 30/86] mfd: tps65910: Fix possible invalid pointer dereference on regmap_add_irq_chip fail Greg Kroah-Hartman
2014-05-04 15:41 ` [PATCH 3.10 31/86] w1: fix w1_send_slave dropping a slave id Greg Kroah-Hartman
2014-05-04 15:41 ` [PATCH 3.10 32/86] staging:serqt_usb2: Fix sparse warning restricted __le16 degrades to integer Greg Kroah-Hartman
2014-05-04 15:41 ` [PATCH 3.10 33/86] staging: r8712u: Fix case where ethtype was never obtained and always be checked against 0 Greg Kroah-Hartman
2014-05-04 15:41 ` [PATCH 3.10 34/86] xfs: fix directory hash ordering bug Greg Kroah-Hartman
2014-05-04 15:41 ` [PATCH 3.10 35/86] ftrace/x86: One more missing sync after fixup of function modification failure Greg Kroah-Hartman
2014-05-04 15:41 ` [PATCH 3.10 36/86] x86-64, modify_ldt: Ban 16-bit segments on 64-bit kernels Greg Kroah-Hartman
2014-05-04 15:41 ` [PATCH 3.10 37/86] USB: fix crash during hotplug of PCI USB controller card Greg Kroah-Hartman
2014-05-04 15:41 ` [PATCH 3.10 38/86] iio: querying buffer scan_mask should return 0/1 Greg Kroah-Hartman
2014-05-04 15:41 ` [PATCH 3.10 39/86] nfsd4: session needs room for following op to error out Greg Kroah-Hartman
2014-05-04 15:41 ` [PATCH 3.10 40/86] nfsd4: buffer-length check for SUPPATTR_EXCLCREAT Greg Kroah-Hartman
2014-05-04 15:41 ` [PATCH 3.10 41/86] nfsd4: fix test_stateid error reply encoding Greg Kroah-Hartman
2014-05-04 15:41 ` [PATCH 3.10 42/86] nfsd: notify_change needs elevated write count Greg Kroah-Hartman
2014-05-04 15:41 ` [PATCH 3.10 43/86] nfsd: check passed sockets net matches NFSd superblocks one Greg Kroah-Hartman
2014-05-04 15:41 ` [PATCH 3.10 44/86] nfsd4: fix setclientid encode size Greg Kroah-Hartman
2014-05-04 15:41 ` [PATCH 3.10 45/86] NFSD: Traverse unconfirmed client through hash-table Greg Kroah-Hartman
2014-05-04 15:41 ` [PATCH 3.10 46/86] nfsd: set timeparms.to_maxval in setup_callback_client Greg Kroah-Hartman
2014-05-04 15:41 ` [PATCH 3.10 47/86] IB/ipath: Fix potential buffer overrun in sending diag packet routine Greg Kroah-Hartman
2014-05-04 15:41 ` [PATCH 3.10 48/86] IB/nes: Return an error on ib_copy_from_udata() failure instead of NULL Greg Kroah-Hartman
2014-05-04 15:41 ` [PATCH 3.10 49/86] IB/mthca: Return an error on ib_copy_to_udata() failure Greg Kroah-Hartman
2014-05-04 15:41 ` [PATCH 3.10 50/86] IB/ehca: Returns " Greg Kroah-Hartman
2014-05-04 15:41 ` [PATCH 3.10 51/86] ib_srpt: Use correct ib_sg_dma primitives Greg Kroah-Hartman
2014-05-04 15:41 ` [PATCH 3.10 52/86] SCSI: qla2xxx: fix error handling of qla2x00_mem_alloc() Greg Kroah-Hartman
2014-05-04 15:41 ` [PATCH 3.10 53/86] SCSI: arcmsr: upper 32 of dma address lost Greg Kroah-Hartman
2014-05-04 15:41 ` [PATCH 3.10 54/86] iscsi-target: Fix ERL=2 ASYNC_EVENT connection pointer bug Greg Kroah-Hartman
2014-05-04 15:41 ` [PATCH 3.10 55/86] target/tcm_fc: Fix use-after-free of ft_tpg Greg Kroah-Hartman
2014-05-04 15:41 ` [PATCH 3.10 56/86] x86/efi: Correct EFI boot stub use of code32_start Greg Kroah-Hartman
2014-05-04 15:41 ` [PATCH 3.10 57/86] reiserfs: fix race in readdir Greg Kroah-Hartman
2014-05-04 15:41 ` [PATCH 3.10 58/86] usb: gadget: tcm_usb_gadget: stop format strings Greg Kroah-Hartman
2014-05-04 15:41 ` [PATCH 3.10 59/86] usb: gadget: zero: Fix SuperSpeed enumeration for alternate setting 1 Greg Kroah-Hartman
2014-05-04 15:41 ` [PATCH 3.10 60/86] xhci: Prevent runtime pm from autosuspending during initialization Greg Kroah-Hartman
2014-05-04 15:41 ` [PATCH 3.10 61/86] xhci: extend quirk for Renesas cards Greg Kroah-Hartman
2014-05-04 15:41 ` [PATCH 3.10 62/86] usb/xhci: fix compilation warning when !CONFIG_PCI && !CONFIG_PM Greg Kroah-Hartman
2014-05-04 15:41 ` [PATCH 3.10 63/86] media: uvcvideo: Do not use usb_set_interface on bulk EP Greg Kroah-Hartman
2014-05-04 15:41 ` [PATCH 3.10 64/86] media: v4l2-compat-ioctl32: fix wrong VIDIOC_SUBDEV_G/S_EDID32 support Greg Kroah-Hartman
2014-05-04 15:41 ` [PATCH 3.10 65/86] media: m88rs2000: prevent frontend crash on continuous transponder scans Greg Kroah-Hartman
2014-05-04 15:41 ` [PATCH 3.10 66/86] media: m88rs2000: add caps FE_CAN_INVERSION_AUTO Greg Kroah-Hartman
2014-05-04 15:41 ` [PATCH 3.10 67/86] media: em28xx: fix PCTV 290e LNA oops Greg Kroah-Hartman
2014-05-04 15:41 ` [PATCH 3.10 68/86] media: saa7134: fix WARN_ON during resume Greg Kroah-Hartman
2014-05-04 15:41 ` [PATCH 3.10 69/86] media: omap3isp: preview: Fix the crop margins Greg Kroah-Hartman
2014-05-04 15:41 ` [PATCH 3.10 70/86] media: media: gspca: sn9c20x: add ID for Genius Look 1320 V2 Greg Kroah-Hartman
2014-05-04 15:41 ` [PATCH 3.10 71/86] usb: dwc3: fix wrong bit mask in dwc3_event_devt Greg Kroah-Hartman
2014-05-04 15:41 ` [PATCH 3.10 72/86] usb: musb: avoid NULL pointer dereference Greg Kroah-Hartman
2014-05-04 15:41 ` [PATCH 3.10 73/86] hvc: ensure hvc_init is only ever called once in hvc_console.c Greg Kroah-Hartman
2014-05-04 15:41 ` [PATCH 3.10 74/86] usb: phy: Add ulpi IDs for SMSC USB3320 and TI TUSB1210 Greg Kroah-Hartman
2014-05-04 15:41 ` [PATCH 3.10 75/86] USB: unbind all interfaces before rebinding any Greg Kroah-Hartman
2014-05-04 15:41 ` [PATCH 3.10 76/86] mtip32xx: Set queue bounce limit Greg Kroah-Hartman
2014-05-04 15:41 ` [PATCH 3.10 77/86] sh: fix format string bug in stack tracer Greg Kroah-Hartman
2014-05-04 15:41 ` [PATCH 3.10 78/86] mm: try_to_unmap_cluster() should lock_page() before mlocking Greg Kroah-Hartman
2014-05-04 15:41 ` [PATCH 3.10 79/86] mm: hugetlb: fix softlockup when a large number of hugepages are freed Greg Kroah-Hartman
2014-05-04 15:41 ` [PATCH 3.10 80/86] hung_task: check the value of "sysctl_hung_task_timeout_sec" Greg Kroah-Hartman
2014-05-04 15:41 ` Greg Kroah-Hartman [this message]
2014-05-04 15:41 ` [PATCH 3.10 82/86] ocfs2: dlm: fix recovery hung Greg Kroah-Hartman
2014-05-04 15:41 ` [PATCH 3.10 83/86] ocfs2: do not put bh when buffer_uptodate failed Greg Kroah-Hartman
2014-05-04 15:41 ` [PATCH 3.10 84/86] ext4: fix jbd2 warning under heavy xattr load Greg Kroah-Hartman
2014-05-04 15:42 ` [PATCH 3.10 85/86] ext4: use i_size_read in ext4_unaligned_aio() Greg Kroah-Hartman
2014-05-04 15:42 ` [PATCH 3.10 86/86] USB: pl2303: add ids for Hewlett-Packard HP POS pole displays Greg Kroah-Hartman
2014-05-04 18:15 ` [PATCH 3.10 00/86] 3.10.39-stable review Guenter Roeck
2014-05-05 20:43 ` Greg Kroah-Hartman
2014-05-06 0:09 ` Guenter Roeck
2014-05-06 0:28 ` Greg Kroah-Hartman
2014-05-06 1:14 ` Guenter Roeck
2014-05-05 15:49 ` Guenter Roeck
2014-05-05 20:44 ` Greg Kroah-Hartman
2014-05-06 14:55 ` Shuah Khan
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20140504154151.450775598@linuxfoundation.org \
--to=gregkh@linuxfoundation.org \
--cc=akpm@linux-foundation.org \
--cc=jlbec@evilplan.org \
--cc=junxiao.bi@oracle.com \
--cc=linux-kernel@vger.kernel.org \
--cc=mfasheh@suse.com \
--cc=srinivas.eeda@oracle.com \
--cc=stable@vger.kernel.org \
--cc=sunil.mushran@gmail.com \
--cc=torvalds@linux-foundation.org \
--cc=wen.gang.wang@oracle.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).