1 From cbddcc4fa3443fe8cfb2ff8e210deb1f6a0eea38 Mon Sep 17 00:00:00 2001
2 From: Tetsuo Handa <penguin-kernel@I-love.SAKURA.ne.jp>
3 Date: Tue, 20 Sep 2022 22:43:51 +0900
4 Subject: btrfs: set generation before calling btrfs_clean_tree_block in btrfs_init_new_buffer
6 From: Tetsuo Handa <penguin-kernel@I-love.SAKURA.ne.jp>
8 commit cbddcc4fa3443fe8cfb2ff8e210deb1f6a0eea38 upstream.
10 syzbot is reporting uninit-value in btrfs_clean_tree_block() [1], for
11 commit bc877d285ca3dba2 ("btrfs: Deduplicate extent_buffer init code")
12 missed that btrfs_set_header_generation() in btrfs_init_new_buffer() must
13 not be moved to after clean_tree_block() because clean_tree_block() is
14 calling btrfs_header_generation() since commit 55c69072d6bd5be1 ("Btrfs:
15 Fix extent_buffer usage when nodesize != leafsize").
17 Since memzero_extent_buffer() will reset "struct btrfs_header" part, we
18 can't move btrfs_set_header_generation() to before memzero_extent_buffer().
19 Just re-add btrfs_set_header_generation() before btrfs_clean_tree_block().
21 Link: https://syzkaller.appspot.com/bug?extid=fba8e2116a12609b6c59 [1]
22 Reported-by: syzbot <syzbot+fba8e2116a12609b6c59@syzkaller.appspotmail.com>
23 Fixes: bc877d285ca3dba2 ("btrfs: Deduplicate extent_buffer init code")
24 CC: stable@vger.kernel.org # 4.19+
25 Signed-off-by: Tetsuo Handa <penguin-kernel@I-love.SAKURA.ne.jp>
26 Signed-off-by: David Sterba <dsterba@suse.com>
27 Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
29 fs/btrfs/extent-tree.c | 3 +++
30 1 file changed, 3 insertions(+)
32 --- a/fs/btrfs/extent-tree.c
33 +++ b/fs/btrfs/extent-tree.c
34 @@ -4802,6 +4802,9 @@ btrfs_init_new_buffer(struct btrfs_trans
35 !test_bit(BTRFS_ROOT_RESET_LOCKDEP_CLASS, &root->state))
36 lockdep_owner = BTRFS_FS_TREE_OBJECTID;
38 + /* btrfs_clean_tree_block() accesses generation field. */
39 + btrfs_set_header_generation(buf, trans->transid);
42 * This needs to stay, because we could allocate a freed block from an
43 * old tree into a new tree, so we need to make sure this new block is