1 From 62dc45979f3f8cb0ea67302a93bff686f0c46c5a Mon Sep 17 00:00:00 2001
2 From: Gao Xiang <gaoxiang25@huawei.com>
3 Date: Mon, 18 Feb 2019 15:19:04 +0800
4 Subject: staging: erofs: fix race of initializing xattrs of a inode at the same time
6 From: Gao Xiang <gaoxiang25@huawei.com>
8 commit 62dc45979f3f8cb0ea67302a93bff686f0c46c5a upstream.
10 In real scenario, there could be several threads accessing xattrs
11 of the same xattr-uninitialized inode, and init_inode_xattrs()
12 almost at the same time.
14 That's actually an unexpected behavior, this patch closes the race.
16 Fixes: b17500a0fdba ("staging: erofs: introduce xattr & acl support")
17 Cc: <stable@vger.kernel.org> # 4.19+
18 Reviewed-by: Chao Yu <yuchao0@huawei.com>
19 Signed-off-by: Gao Xiang <gaoxiang25@huawei.com>
20 Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
23 drivers/staging/erofs/internal.h | 11 +++++++---
24 drivers/staging/erofs/xattr.c | 41 +++++++++++++++++++++++++++------------
25 2 files changed, 37 insertions(+), 15 deletions(-)
27 --- a/drivers/staging/erofs/internal.h
28 +++ b/drivers/staging/erofs/internal.h
29 @@ -354,12 +354,17 @@ static inline erofs_off_t iloc(struct er
30 return blknr_to_addr(sbi->meta_blkaddr) + (nid << sbi->islotbits);
33 -#define inode_set_inited_xattr(inode) (EROFS_V(inode)->flags |= 1)
34 -#define inode_has_inited_xattr(inode) (EROFS_V(inode)->flags & 1)
35 +/* atomic flag definitions */
36 +#define EROFS_V_EA_INITED_BIT 0
38 +/* bitlock definitions (arranged in reverse order) */
39 +#define EROFS_V_BL_XATTR_BIT (BITS_PER_LONG - 1)
45 + /* atomic flags (including bitlocks) */
46 + unsigned long flags;
48 unsigned char data_mapping_mode;
49 /* inline size in bytes */
50 --- a/drivers/staging/erofs/xattr.c
51 +++ b/drivers/staging/erofs/xattr.c
52 @@ -44,18 +44,25 @@ static inline void xattr_iter_end_final(
54 static int init_inode_xattrs(struct inode *inode)
56 + struct erofs_vnode *const vi = EROFS_V(inode);
59 struct erofs_xattr_ibody_header *ih;
60 struct super_block *sb;
61 struct erofs_sb_info *sbi;
62 - struct erofs_vnode *vi;
66 - if (likely(inode_has_inited_xattr(inode)))
67 + /* the most case is that xattrs of this inode are initialized. */
68 + if (test_bit(EROFS_V_EA_INITED_BIT, &vi->flags))
71 - vi = EROFS_V(inode);
72 + if (wait_on_bit_lock(&vi->flags, EROFS_V_BL_XATTR_BIT, TASK_KILLABLE))
73 + return -ERESTARTSYS;
75 + /* someone has initialized xattrs for us? */
76 + if (test_bit(EROFS_V_EA_INITED_BIT, &vi->flags))
80 * bypass all xattr operations if ->xattr_isize is not greater than
81 @@ -68,13 +75,16 @@ static int init_inode_xattrs(struct inod
82 if (vi->xattr_isize == sizeof(struct erofs_xattr_ibody_header)) {
83 errln("xattr_isize %d of nid %llu is not supported yet",
84 vi->xattr_isize, vi->nid);
88 } else if (vi->xattr_isize < sizeof(struct erofs_xattr_ibody_header)) {
89 if (unlikely(vi->xattr_isize)) {
91 - return -EIO; /* xattr ondisk layout error */
93 + goto out_unlock; /* xattr ondisk layout error */
101 @@ -83,8 +93,10 @@ static int init_inode_xattrs(struct inod
102 it.ofs = erofs_blkoff(iloc(sbi, vi->nid) + vi->inode_isize);
104 it.page = erofs_get_inline_page(inode, it.blkaddr);
105 - if (IS_ERR(it.page))
106 - return PTR_ERR(it.page);
107 + if (IS_ERR(it.page)) {
108 + ret = PTR_ERR(it.page);
112 /* read in shared xattr array (non-atomic, see kmalloc below) */
113 it.kaddr = kmap(it.page);
114 @@ -97,7 +109,8 @@ static int init_inode_xattrs(struct inod
115 sizeof(uint), GFP_KERNEL);
116 if (vi->xattr_shared_xattrs == NULL) {
117 xattr_iter_end(&it, atomic_map);
123 /* let's skip ibody header */
124 @@ -114,7 +127,8 @@ static int init_inode_xattrs(struct inod
125 if (IS_ERR(it.page)) {
126 kfree(vi->xattr_shared_xattrs);
127 vi->xattr_shared_xattrs = NULL;
128 - return PTR_ERR(it.page);
129 + ret = PTR_ERR(it.page);
133 it.kaddr = kmap_atomic(it.page);
134 @@ -127,8 +141,11 @@ static int init_inode_xattrs(struct inod
136 xattr_iter_end(&it, atomic_map);
138 - inode_set_inited_xattr(inode);
140 + set_bit(EROFS_V_EA_INITED_BIT, &vi->flags);
143 + clear_and_wake_up_bit(EROFS_V_BL_XATTR_BIT, &vi->flags);