Nikolay Borisov
670f6b3867
btrfs: fix memory ordering between normal and ordered work functions
...
commit 45da9c1767ac31857df572f0a909fbe88fd5a7e9 upstream.
Ordered work functions aren't guaranteed to be handled by the same thread
which executed the normal work functions. The only way execution between
normal/ordered functions is synchronized is via the WORK_DONE_BIT,
unfortunately the used bitops don't guarantee any ordering whatsoever.
This manifested as seemingly inexplicable crashes on ARM64, where
async_chunk::inode is seen as non-null in async_cow_submit which causes
submit_compressed_extents to be called and crash occurs because
async_chunk::inode suddenly became NULL. The call trace was similar to:
pc : submit_compressed_extents+0x38/0x3d0
lr : async_cow_submit+0x50/0xd0
sp : ffff800015d4bc20
<registers omitted for brevity>
Call trace:
submit_compressed_extents+0x38/0x3d0
async_cow_submit+0x50/0xd0
run_ordered_work+0xc8/0x280
btrfs_work_helper+0x98/0x250
process_one_work+0x1f0/0x4ac
worker_thread+0x188/0x504
kthread+0x110/0x114
ret_from_fork+0x10/0x18
Fix this by adding respective barrier calls which ensure that all
accesses preceding setting of WORK_DONE_BIT are strictly ordered before
setting the flag. At the same time add a read barrier after reading of
WORK_DONE_BIT in run_ordered_work which ensures all subsequent loads
would be strictly ordered after reading the bit. This in turn ensures
are all accesses before WORK_DONE_BIT are going to be strictly ordered
before any access that can occur in ordered_func.
Reported-by: Chris Murphy <lists@colorremedies.com>
Fixes: 08a9ff3264 ("btrfs: Added btrfs_workqueue_struct implemented ordered execution based on kernel workqueue")
CC: stable@vger.kernel.org # 4.4+
Link: https://bugzilla.redhat.com/show_bug.cgi?id=2011928
Reviewed-by: Josef Bacik <josef@toxicpanda.com>
Tested-by: Chris Murphy <chris@colorremedies.com>
Signed-off-by: Nikolay Borisov <nborisov@suse.com>
Signed-off-by: David Sterba <dsterba@suse.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2021-11-26 10:47:21 +01:00
..
9p
adfs
affs
fs/affs: release old buffer head on error path
2021-03-04 10:26:48 +01:00
afs
afs: Fix incorrect triggering of sillyrename on 3rd-party invalidation
2021-09-30 10:09:22 +02:00
autofs
befs
bfs
btrfs
btrfs: fix memory ordering between normal and ordered work functions
2021-11-26 10:47:21 +01:00
cachefiles
ceph
ceph: fix handling of "meta" errors
2021-10-27 09:54:27 +02:00
cifs
cifs: fix a sign extension bug
2021-09-30 10:09:24 +02:00
coda
configfs
configfs: fix memleak in configfs_release_bin_file
2021-07-14 16:53:46 +02:00
cramfs
crypto
fscrypt: add fscrypt_symlink_getattr() for computing st_size
2021-09-12 08:56:38 +02:00
debugfs
debugfs: debugfs_create_file_size(): use IS_ERR to check for error
2021-10-06 15:42:35 +02:00
devpts
dlm
fs: dlm: fix memory leak when fenced
2021-07-14 16:53:17 +02:00
ecryptfs
Revert "ecryptfs: replace BUG_ON with error handling code"
2021-05-26 12:05:19 +02:00
efivarfs
efs
erofs
erofs: fix unsafe pagevec reuse of hooked pclusters
2021-11-21 13:38:51 +01:00
exportfs
ext2
ext2: fix sleeping in atomic bugs on error
2021-10-09 14:39:49 +02:00
ext4
ext4: fix lazy initialization next schedule time computation in more granular unit
2021-11-21 13:38:50 +01:00
f2fs
f2fs: should use GFP_NOFS for directory inodes
2021-11-17 09:48:49 +01:00
fat
freevxfs
fscache
fscache: Fix cookie key hashing
2021-09-22 12:26:25 +02:00
fuse
fuse: fix page stealing
2021-11-17 09:48:19 +01:00
gfs2
gfs2: Don't call dlm after protocol is unmounted
2021-09-22 12:26:33 +02:00
hfs
hfs: add lock nesting notation to hfs_find_init
2021-07-31 08:19:38 +02:00
hfsplus
hfsplus: prevent corruption in shrinking truncate
2021-05-19 10:08:29 +02:00
hostfs
hostfs: fix memory handling in follow_link()
2021-04-14 08:24:14 +02:00
hpfs
hugetlbfs
hugetlbfs: fix mount mode command line processing
2021-07-28 13:31:01 +02:00
iomap
mm/swap: consider max pages in iomap_swapfile_add_extent
2021-09-15 09:47:35 +02:00
isofs
isofs: Fix out of bound access for corrupted isofs image
2021-11-12 14:43:03 +01:00
jbd2
jffs2
jffs2: check the validity of dstlen in jffs2_zlib_compress()
2021-05-11 14:04:16 +02:00
jfs
JFS: fix memleak in jfs_mount
2021-11-17 09:48:42 +01:00
kernfs
lockd
lockd: lockd server-side shouldn't set fl_ops
2021-09-22 12:26:34 +02:00
minix
nfs
NFSv4: Fix a regression in nfs_set_open_stateid_locked()
2021-11-17 09:48:46 +01:00
nfs_common
nfsd
NFSD: Keep existing listeners on portlist error
2021-10-27 09:54:25 +02:00
nilfs2
nilfs2: fix memory leak in nilfs_sysfs_delete_snapshot_group
2021-09-26 14:07:13 +02:00
nls
notify
ntfs
ntfs: fix validity check for file name attribute
2021-07-14 16:53:01 +02:00
ocfs2
ocfs2: fix data corruption on truncate
2021-11-17 09:48:17 +01:00
omfs
openpromfs
orangefs
fs: orangefs: fix error return code of orangefs_revalidate_lookup()
2021-11-17 09:48:45 +01:00
overlayfs
ovl: fix deadlock in splice write
2021-11-17 09:48:49 +01:00
proc
mm, oom: make the calculation of oom badness more accurate
2021-09-03 10:08:12 +02:00
pstore
pstore: Fix typo in compression option name
2021-03-04 10:26:45 +01:00
qnx4
qnx4: work around gcc false positive warning bug
2021-09-30 10:09:26 +02:00
qnx6
quota
quota: correct error number in free_dqentry()
2021-11-17 09:48:26 +01:00
ramfs
reiserfs
reiserfs: check directory items on read from disk
2021-08-12 13:21:05 +02:00
romfs
squashfs
squashfs: fix divide error in calculate_skip()
2021-05-19 10:08:29 +02:00
sysfs
sysfs: Add sysfs_emit and sysfs_emit_at to format sysfs output
2021-03-07 12:20:48 +01:00
sysv
tracefs
tracefs: Have tracefs directories not set OTH permission bits by default
2021-11-17 09:48:30 +01:00
ubifs
ubifs: report correct st_size for encrypted symlinks
2021-09-12 08:56:39 +02:00
udf
udf: Fix crash after seekdir
2021-11-26 10:47:21 +01:00
ufs
unicode
verity
fs-verity: fix signed integer overflow with i_size near S64_MAX
2021-10-06 15:42:30 +02:00
xfs
xfs: Fix assert failure in xfs_setattr_size()
2021-03-07 12:20:42 +01:00
aio.c
anon_inodes.c
attr.c
bad_inode.c
binfmt_aout.c
binfmt_elf.c
elf: don't use MAP_FIXED_NOREPLACE for elf interpreter mappings
2021-10-06 15:42:35 +02:00
binfmt_elf_fdpic.c
binfmt_em86.c
binfmt_flat.c
binfmt_misc.c
binfmt_misc: fix possible deadlock in bm_register_write
2021-03-17 17:03:57 +01:00
binfmt_script.c
block_dev.c
block: reexpand iov_iter after read/write
2021-05-22 11:38:29 +02:00
buffer.c
char_dev.c
compat.c
compat_binfmt_elf.c
compat_ioctl.c
coredump.c
d_path.c
dax.c
dax: fix ENOMEM handling in grab_mapping_entry()
2021-07-14 16:53:25 +02:00
dcache.c
dcookies.c
direct-io.c
fs: direct-io: fix missing sdio->boundary
2021-04-14 08:24:11 +02:00
drop_caches.c
eventfd.c
eventpoll.c
exec.c
vfs: check fd has read access in kernel_read_file_from_fd()
2021-10-27 09:54:27 +02:00
fcntl.c
fcntl: fix potential deadlock for &fasync_struct.fa_lock
2021-09-15 09:47:28 +02:00
fhandle.c
file.c
file_table.c
filesystems.c
fs-writeback.c
writeback: fix obtain a reference to a freeing memcg css
2021-07-14 16:53:35 +02:00
fs_context.c
fs_parser.c
fs_pin.c
fs_struct.c
fs_types.c
fsopen.c
inode.c
internal.h
cgroup1: fix leaked context root causing sporadic NULL deref in LTP
2021-07-31 08:19:37 +02:00
io_uring.c
io_uring: Fix current->fs handling in io_sq_wq_submit_work()
2021-01-30 13:54:10 +01:00
ioctl.c
Kconfig
Kconfig.binfmt
libfs.c
locks.c
Makefile
mbcache.c
mount.h
mpage.c
namei.c
namespace.c
fs: warn about impending deprecation of mandatory locks
2021-08-26 08:36:22 -04:00
no-block.c
nsfs.c
open.c
pipe.c
pipe: increase minimum default pipe size to 2 pages
2021-08-12 13:21:02 +02:00
pnode.c
pnode.h
mount: fix mounting of detached mounts onto targets that reside on shared mounts
2021-03-17 17:03:33 +01:00
posix_acl.c
proc_namespace.c
read_write.c
readdir.c
readdir: make sure to verify directory entry for legacy interfaces too
2021-04-21 12:56:16 +02:00
select.c
kernel, fs: Introduce and use set_restart_fn() and arch_set_restart_data()
2021-03-24 11:26:44 +01:00
seq_file.c
seq_file: disallow extremely large seq buffer allocations
2021-07-20 16:10:54 +02:00
signalfd.c
splice.c
stack.c
stat.c
statfs.c
super.c
sync.c
timerfd.c
userfaultfd.c
userfaultfd: prevent concurrent API initialization
2021-09-22 12:26:26 +02:00
utimes.c
xattr.c