]> git.ipfire.org Git - thirdparty/kernel/stable.git/commit
ext4: fix crashes in dioread_nolock mode
authorJan Kara <jack@suse.cz>
Fri, 19 Feb 2016 05:33:21 +0000 (00:33 -0500)
committerSasha Levin <sasha.levin@oracle.com>
Fri, 4 Mar 2016 15:25:45 +0000 (10:25 -0500)
commit62adae8f26b918f4403129e355d81301a629b6a2
tree4e1e6a5ef2e1182cc9ad586b85b3f8cd01e3c1de
parent5d0e8394db90caa6d06477f68cbdb48fe65f468d
ext4: fix crashes in dioread_nolock mode

[ Upstream commit 74dae4278546b897eb81784fdfcce872ddd8b2b8 ]

Competing overwrite DIO in dioread_nolock mode will just overwrite
pointer to io_end in the inode. This may result in data corruption or
extent conversion happening from IO completion interrupt because we
don't properly set buffer_defer_completion() when unlocked DIO races
with locked DIO to unwritten extent.

Since unlocked DIO doesn't need io_end for anything, just avoid
allocating it and corrupting pointer from inode for locked DIO.
A cleaner fix would be to avoid these games with io_end pointer from the
inode but that requires more intrusive changes so we leave that for
later.

Cc: stable@vger.kernel.org
Signed-off-by: Jan Kara <jack@suse.cz>
Signed-off-by: Theodore Ts'o <tytso@mit.edu>
Signed-off-by: Sasha Levin <sasha.levin@oracle.com>
fs/ext4/inode.c