]> git.ipfire.org Git - thirdparty/kernel/stable-queue.git/commitdiff
3.18-stable patches
authorGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Wed, 13 Sep 2017 03:43:46 +0000 (20:43 -0700)
committerGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Wed, 13 Sep 2017 03:43:46 +0000 (20:43 -0700)
added patches:
xfs-xfs_is_realtime_inode-should-be-false-if-no-rt-device-present.patch

queue-3.18/series
queue-3.18/xfs-xfs_is_realtime_inode-should-be-false-if-no-rt-device-present.patch [new file with mode: 0644]

index 162f61ec2d58096c15967eceb3a6c5bc5ca927ba..dca829f6dba05a16f5175d9e351ba2c7263e4bda 100644 (file)
@@ -17,3 +17,4 @@ locktorture-fix-potential-memory-leak-with-rw-lock-test.patch
 alsa-msnd-optimize-harden-dsp-and-midi-loops.patch
 bluetooth-properly-check-l2cap-config-option-output-buffer-length.patch
 arm-8692-1-mm-abort-uaccess-retries-upon-fatal-signal.patch
+xfs-xfs_is_realtime_inode-should-be-false-if-no-rt-device-present.patch
diff --git a/queue-3.18/xfs-xfs_is_realtime_inode-should-be-false-if-no-rt-device-present.patch b/queue-3.18/xfs-xfs_is_realtime_inode-should-be-false-if-no-rt-device-present.patch
new file mode 100644 (file)
index 0000000..70f31b1
--- /dev/null
@@ -0,0 +1,71 @@
+From b31ff3cdf540110da4572e3e29bd172087af65cc Mon Sep 17 00:00:00 2001
+From: Richard Wareing <rwareing@fb.com>
+Date: Wed, 13 Sep 2017 09:09:35 +1000
+Subject: xfs: XFS_IS_REALTIME_INODE() should be false if no rt device present
+
+From: Richard Wareing <rwareing@fb.com>
+
+commit b31ff3cdf540110da4572e3e29bd172087af65cc upstream.
+
+If using a kernel with CONFIG_XFS_RT=y and we set the RHINHERIT flag on
+a directory in a filesystem that does not have a realtime device and
+create a new file in that directory, it gets marked as a real time file.
+When data is written and a fsync is issued, the filesystem attempts to
+flush a non-existent rt device during the fsync process.
+
+This results in a crash dereferencing a null buftarg pointer in
+xfs_blkdev_issue_flush():
+
+  BUG: unable to handle kernel NULL pointer dereference at 0000000000000008
+  IP: xfs_blkdev_issue_flush+0xd/0x20
+  .....
+  Call Trace:
+    xfs_file_fsync+0x188/0x1c0
+    vfs_fsync_range+0x3b/0xa0
+    do_fsync+0x3d/0x70
+    SyS_fsync+0x10/0x20
+    do_syscall_64+0x4d/0xb0
+    entry_SYSCALL64_slow_path+0x25/0x25
+
+Setting RT inode flags does not require special privileges so any
+unprivileged user can cause this oops to occur.  To reproduce, confirm
+kernel is compiled with CONFIG_XFS_RT=y and run:
+
+  # mkfs.xfs -f /dev/pmem0
+  # mount /dev/pmem0 /mnt/test
+  # mkdir /mnt/test/foo
+  # xfs_io -c 'chattr +t' /mnt/test/foo
+  # xfs_io -f -c 'pwrite 0 5m' -c fsync /mnt/test/foo/bar
+
+Or just run xfstests with MKFS_OPTIONS="-d rtinherit=1" and wait.
+
+Kernels built with CONFIG_XFS_RT=n are not exposed to this bug.
+
+Fixes: f538d4da8d52 ("[XFS] write barrier support")
+Signed-off-by: Richard Wareing <rwareing@fb.com>
+Signed-off-by: Dave Chinner <david@fromorbit.com>
+Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
+Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
+
+---
+ fs/xfs/libxfs/xfs_dinode.h |    9 ++++++++-
+ 1 file changed, 8 insertions(+), 1 deletion(-)
+
+--- a/fs/xfs/libxfs/xfs_dinode.h
++++ b/fs/xfs/libxfs/xfs_dinode.h
+@@ -228,7 +228,14 @@ static inline void xfs_dinode_put_rdev(s
+ #define XFS_DIFLAG_FILESTREAM    (1 << XFS_DIFLAG_FILESTREAM_BIT)
+ #ifdef CONFIG_XFS_RT
+-#define XFS_IS_REALTIME_INODE(ip) ((ip)->i_d.di_flags & XFS_DIFLAG_REALTIME)
++
++/*
++ * make sure we ignore the inode flag if the filesystem doesn't have a
++ * configured realtime device.
++ */
++#define XFS_IS_REALTIME_INODE(ip)                     \
++      (((ip)->i_d.di_flags & XFS_DIFLAG_REALTIME) &&  \
++       (ip)->i_mount->m_rtdev_targp)
+ #else
+ #define XFS_IS_REALTIME_INODE(ip) (0)
+ #endif