android_kernel_motorola_sm6375/fs/ext4
Repository files (latest commit first)
Filename Latest commit message Latest commit date
Baokun Li de8ada0236 ext4: prevent the normalized size from exceeding EXT_MAX_BLOCKS
commit 2dcf5fde6dffb312a4bfb8ef940cea2d1f402e32 upstream.

For files with logical blocks close to EXT_MAX_BLOCKS, the file size
predicted in ext4_mb_normalize_request() may exceed EXT_MAX_BLOCKS.
This can cause some blocks to be preallocated that will not be used.
And after [Fixes], the following issue may be triggered:

=========================================================
 kernel BUG at fs/ext4/mballoc.c:4653!
 Internal error: Oops - BUG: 00000000f2000800 [#1] SMP
 CPU: 1 PID: 2357 Comm: xfs_io 6.7.0-rc2-00195-g0f5cc96c367f
 Hardware name: linux,dummy-virt (DT)
 pc : ext4_mb_use_inode_pa+0x148/0x208
 lr : ext4_mb_use_inode_pa+0x98/0x208
 Call trace:
  ext4_mb_use_inode_pa+0x148/0x208
  ext4_mb_new_inode_pa+0x240/0x4a8
  ext4_mb_use_best_found+0x1d4/0x208
  ext4_mb_try_best_found+0xc8/0x110
  ext4_mb_regular_allocator+0x11c/0xf48
  ext4_mb_new_blocks+0x790/0xaa8
  ext4_ext_map_blocks+0x7cc/0xd20
  ext4_map_blocks+0x170/0x600
  ext4_iomap_begin+0x1c0/0x348
=========================================================

Here is a calculation when adjusting ac_b_ex in ext4_mb_new_inode_pa():

	ex.fe_logical = orig_goal_end - EXT4_C2B(sbi, ex.fe_len);
	if (ac->ac_o_ex.fe_logical >= ex.fe_logical)
		goto adjust_bex;

The problem is that when orig_goal_end is subtracted from ac_b_ex.fe_len
it is still greater than EXT_MAX_BLOCKS, which causes ex.fe_logical to
overflow to a very small value, which ultimately triggers a BUG_ON in
ext4_mb_new_inode_pa() because pa->pa_free < len.

The last logical block of an actual write request does not exceed
EXT_MAX_BLOCKS, so in ext4_mb_normalize_request() also avoids normalizing
the last logical block to exceed EXT_MAX_BLOCKS to avoid the above issue.

The test case in [Link] can reproduce the above issue with 64k block size.

Link: https://patchwork.kernel.org/project/fstests/list/?series=804003
Cc:  <stable@kernel.org> # 6.4
Fixes: 93cdf49f6eca ("ext4: Fix best extent lstart adjustment logic in ext4_mb_new_inode_pa()")
Signed-off-by: Baokun Li <libaokun1@huawei.com>
Reviewed-by: Jan Kara <jack@suse.cz>
Link: https://lore.kernel.org/r/20231127063313.3734294-1-libaokun1@huawei.com
Signed-off-by: Theodore Ts'o <tytso@mit.edu>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2023-12-20 15:41:24 +01:00
..
acl.c
acl.h ext4: apply umask if ACL support is disabled 2023-11-28 16:50:21 +00:00
balloc.c ext4: fix WARNING in mb_find_extent 2023-05-17 11:36:02 +02:00
bitmap.c
block_validity.c
dir.c
ext4.h ext4: change s_last_trim_minblks type to unsigned long 2023-10-10 21:46:36 +02:00
ext4_extents.h
ext4_jbd2.c
ext4_jbd2.h
extents.c ext4: move 'ix' sanity check to corrent position 2023-11-20 10:30:12 +01:00
extents_status.c ext4: make sure allocate pending entry not fail 2023-12-08 08:44:24 +01:00
extents_status.h
file.c ext4: avoid crash when inline data creation follows DIO write 2022-10-26 13:22:18 +02:00
fsmap.c ext4: rename journal_dev to s_journal_dev inside ext4_sb_info 2023-08-11 11:53:44 +02:00
fsmap.h
fsync.c
hash.c
ialloc.c ext4: make directory inode spreading reflect flexbg size 2022-09-28 11:04:11 +02:00
indirect.c ext4: only update i_reserved_data_blocks on successful block allocation 2023-07-27 08:37:35 +02:00
inline.c ext4: bail out of ext4_xattr_ibody_get() fails for any reason 2023-05-17 11:36:03 +02:00
inode.c ext4: only update i_reserved_data_blocks on successful block allocation 2023-07-27 08:37:35 +02:00
ioctl.c ext4: fix to check return value of freeze_bdev() in ext4_shutdown() 2023-08-11 11:53:47 +02:00
Kconfig
Makefile
mballoc.c ext4: prevent the normalized size from exceeding EXT_MAX_BLOCKS 2023-12-20 15:41:24 +01:00
mballoc.h ext4: add two helper functions extent_logical_end() and pa_logical_end() 2023-11-08 11:23:39 +01:00
migrate.c ext4: fix warning in 'ext4_da_release_space' 2022-11-10 17:57:56 +01:00
mmp.c
move_extent.c
namei.c ext4: fix rec_len verify error 2023-09-23 11:00:06 +02:00
page-io.c ext4: fix cgroup writeback accounting with fs-layer encryption 2023-03-22 13:28:03 +01:00
readpage.c
resize.c ext4: remove gdb backup copy for meta bg in setup_new_flex_group_blocks 2023-11-28 16:50:21 +00:00
super.c ext4: Fix reusing stale buffer heads from last failed mounting 2023-08-11 11:53:44 +02:00
symlink.c
sysfs.c ext4: Fix function prototype mismatch for ext4_feat_ktype 2023-02-25 11:53:27 +01:00
truncate.h
verity.c fs: ext4: initialize fsdata in pagecache_write() 2023-01-18 11:41:55 +01:00
xattr.c ext4: correct inline offset when handling xattrs in inode body 2023-07-27 08:37:41 +02:00
xattr.h ext4: remove duplicate definition of ext4_xattr_ibody_inline_set() 2023-04-26 11:24:05 +02:00
xattr_security.c
xattr_trusted.c
xattr_user.c