]> git.ipfire.org Git - thirdparty/kernel/stable.git/commitdiff
gfs2: Fix NULL pointer dereference in gfs2_log_flush
authorAndreas Gruenbacher <agruenba@redhat.com>
Wed, 28 Jan 2026 03:17:52 +0000 (11:17 +0800)
committerGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Fri, 6 Feb 2026 15:44:23 +0000 (16:44 +0100)
[ Upstream commit 35264909e9d1973ab9aaa2a1b07cda70f12bb828 ]

In gfs2_jindex_free(), set sdp->sd_jdesc to NULL under the log flush
lock to provide exclusion against gfs2_log_flush().

In gfs2_log_flush(), check if sdp->sd_jdesc is non-NULL before
dereferencing it.  Otherwise, we could run into a NULL pointer
dereference when outstanding glock work races with an unmount
(glock_work_func -> run_queue -> do_xmote -> inode_go_sync ->
gfs2_log_flush).

Signed-off-by: Andreas Gruenbacher <agruenba@redhat.com>
[ The context change is due to the commit 4d927b03a688
("gfs2: Rename gfs2_withdrawn to gfs2_withdrawing_or_withdrawn") in v6.8
which is irrelevant to the logic of this patch. ]
Signed-off-by: Rahul Sharma <black.hawk@163.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
fs/gfs2/log.c
fs/gfs2/super.c

index 8fd8bb860486905867902e707db4b33819901c80..45f519ececd97aab34eef2596375eca36b366081 100644 (file)
@@ -1102,7 +1102,8 @@ repeat:
        lops_before_commit(sdp, tr);
        if (gfs2_withdrawn(sdp))
                goto out_withdraw;
-       gfs2_log_submit_bio(&sdp->sd_jdesc->jd_log_bio, REQ_OP_WRITE);
+       if (sdp->sd_jdesc)
+               gfs2_log_submit_bio(&sdp->sd_jdesc->jd_log_bio, REQ_OP_WRITE);
        if (gfs2_withdrawn(sdp))
                goto out_withdraw;
 
index 8d90a5e48147cc38a64f933d087815ee4d5591c7..14b3f66938ea8ec3f51f134152fd9732c6ed7026 100644 (file)
@@ -67,9 +67,13 @@ void gfs2_jindex_free(struct gfs2_sbd *sdp)
        sdp->sd_journals = 0;
        spin_unlock(&sdp->sd_jindex_spin);
 
+       down_write(&sdp->sd_log_flush_lock);
        sdp->sd_jdesc = NULL;
+       up_write(&sdp->sd_log_flush_lock);
+
        while (!list_empty(&list)) {
                jd = list_first_entry(&list, struct gfs2_jdesc, jd_list);
+               BUG_ON(jd->jd_log_bio);
                gfs2_free_journal_extents(jd);
                list_del(&jd->jd_list);
                iput(jd->jd_inode);