mirror of
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git
synced 2026-07-22 02:17:36 -04:00
Merge tag 'gfs2-for-7.2' of git://git.kernel.org/pub/scm/linux/kernel/git/gfs2/linux-gfs2
Pull gfs2 updates from Andreas Gruenbacher: - fix page poisoning not handled correctly when growing files - quota initialization / destruction fixes: sleeping under a bitlock in PREEMPT_RT, broken quota_init error recovery, missing RCU synchronization * tag 'gfs2-for-7.2' of git://git.kernel.org/pub/scm/linux/kernel/git/gfs2/linux-gfs2: gfs2: page poisoning fix gfs2: Remove unused fallocate_chunk argument gfs2: fix use-after-free in gfs2_qd_dealloc gfs2: move quota_init qc iterator increment gfs2: fix quota init duplicate scan
This commit is contained in:
@@ -1322,6 +1322,19 @@ static int gfs2_block_zero_range(struct inode *inode, loff_t from, loff_t length
|
||||
&gfs2_iomap_write_ops, NULL);
|
||||
}
|
||||
|
||||
int gfs2_clear_beyond_eof(struct inode *inode, loff_t end)
|
||||
{
|
||||
loff_t isize = i_size_read(inode);
|
||||
unsigned int len = isize & ~PAGE_MASK;
|
||||
|
||||
if (!len || isize >= end)
|
||||
return 0;
|
||||
len = PAGE_SIZE - len;
|
||||
if (end - isize < len)
|
||||
len = end - isize;
|
||||
return gfs2_block_zero_range(inode, isize, len);
|
||||
}
|
||||
|
||||
#define GFS2_JTRUNC_REVOKES 8192
|
||||
|
||||
/**
|
||||
@@ -2097,6 +2110,12 @@ static int do_grow(struct inode *inode, u64 size)
|
||||
unstuff = 1;
|
||||
}
|
||||
|
||||
if (!unstuff) {
|
||||
error = gfs2_clear_beyond_eof(inode, size);
|
||||
if (error)
|
||||
goto do_grow_qunlock;
|
||||
}
|
||||
|
||||
error = gfs2_trans_begin(sdp, RES_DINODE + RES_STATFS + RES_RG_BIT +
|
||||
(unstuff &&
|
||||
gfs2_is_jdata(ip) ? RES_JDATA : 0) +
|
||||
|
||||
@@ -58,6 +58,7 @@ int gfs2_get_extent(struct inode *inode, u64 lblock, u64 *dblock,
|
||||
unsigned int *extlen);
|
||||
int gfs2_alloc_extent(struct inode *inode, u64 lblock, u64 *dblock,
|
||||
unsigned *extlen, bool *new);
|
||||
int gfs2_clear_beyond_eof(struct inode *inode, loff_t end);
|
||||
int gfs2_setattr_size(struct inode *inode, u64 size);
|
||||
int gfs2_truncatei_resume(struct gfs2_inode *ip);
|
||||
int gfs2_file_dealloc(struct gfs2_inode *ip);
|
||||
|
||||
@@ -1057,6 +1057,10 @@ static ssize_t gfs2_file_buffered_write(struct kiocb *iocb,
|
||||
goto out_unlock;
|
||||
}
|
||||
|
||||
ret = gfs2_clear_beyond_eof(inode, iocb->ki_pos);
|
||||
if (ret)
|
||||
goto out_unlock;
|
||||
|
||||
pagefault_disable();
|
||||
ret = iomap_file_buffered_write(iocb, from, &gfs2_iomap_ops,
|
||||
&gfs2_iomap_write_ops, NULL);
|
||||
@@ -1173,8 +1177,7 @@ static ssize_t gfs2_file_write_iter(struct kiocb *iocb, struct iov_iter *from)
|
||||
return ret;
|
||||
}
|
||||
|
||||
static int fallocate_chunk(struct inode *inode, loff_t offset, loff_t len,
|
||||
int mode)
|
||||
static int fallocate_chunk(struct inode *inode, loff_t offset, loff_t len)
|
||||
{
|
||||
struct super_block *sb = inode->i_sb;
|
||||
struct gfs2_inode *ip = GFS2_I(inode);
|
||||
@@ -1266,6 +1269,12 @@ static long __gfs2_fallocate(struct file *file, int mode, loff_t offset, loff_t
|
||||
|
||||
next = (next + 1) << sdp->sd_sb.sb_bsize_shift;
|
||||
|
||||
if (!(mode & FALLOC_FL_KEEP_SIZE)) {
|
||||
error = gfs2_clear_beyond_eof(inode, offset + len);
|
||||
if (error)
|
||||
return error;
|
||||
}
|
||||
|
||||
offset &= bsize_mask;
|
||||
|
||||
len = next - offset;
|
||||
@@ -1336,7 +1345,7 @@ static long __gfs2_fallocate(struct file *file, int mode, loff_t offset, loff_t
|
||||
if (error)
|
||||
goto out_trans_fail;
|
||||
|
||||
error = fallocate_chunk(inode, offset, max_bytes, mode);
|
||||
error = fallocate_chunk(inode, offset, max_bytes);
|
||||
gfs2_trans_end(sdp);
|
||||
|
||||
if (error)
|
||||
|
||||
@@ -254,9 +254,13 @@ static struct gfs2_quota_data *qd_alloc(unsigned hash, struct gfs2_sbd *sdp, str
|
||||
return NULL;
|
||||
}
|
||||
|
||||
static struct gfs2_quota_data *gfs2_qd_search_bucket(unsigned int hash,
|
||||
const struct gfs2_sbd *sdp,
|
||||
struct kqid qid)
|
||||
/*
|
||||
* Lookup variant for callers which already hold qd_lock + bucket lock.
|
||||
*/
|
||||
static struct gfs2_quota_data *
|
||||
gfs2_qd_search_bucket_noref(unsigned int hash,
|
||||
const struct gfs2_sbd *sdp,
|
||||
struct kqid qid)
|
||||
{
|
||||
struct gfs2_quota_data *qd;
|
||||
struct hlist_bl_node *h;
|
||||
@@ -264,12 +268,22 @@ static struct gfs2_quota_data *gfs2_qd_search_bucket(unsigned int hash,
|
||||
hlist_bl_for_each_entry_rcu(qd, h, &qd_hash_table[hash], qd_hlist) {
|
||||
if (!qid_eq(qd->qd_id, qid))
|
||||
continue;
|
||||
if (qd->qd_sbd != sdp)
|
||||
continue;
|
||||
if (lockref_get_not_dead(&qd->qd_lockref)) {
|
||||
list_lru_del_obj(&gfs2_qd_lru, &qd->qd_lru);
|
||||
if (qd->qd_sbd == sdp)
|
||||
return qd;
|
||||
}
|
||||
}
|
||||
|
||||
return NULL;
|
||||
}
|
||||
|
||||
static struct gfs2_quota_data *
|
||||
gfs2_qd_search_bucket(unsigned int hash, const struct gfs2_sbd *sdp, struct kqid qid)
|
||||
{
|
||||
struct gfs2_quota_data *qd;
|
||||
|
||||
qd = gfs2_qd_search_bucket_noref(hash, sdp, qid);
|
||||
if (qd && lockref_get_not_dead(&qd->qd_lockref)) {
|
||||
list_lru_del_obj(&gfs2_qd_lru, &qd->qd_lru);
|
||||
return qd;
|
||||
}
|
||||
|
||||
return NULL;
|
||||
@@ -1433,7 +1447,7 @@ int gfs2_quota_init(struct gfs2_sbd *sdp)
|
||||
|
||||
qc = (struct gfs2_quota_change *)(bh->b_data + sizeof(struct gfs2_meta_header));
|
||||
for (y = 0; y < sdp->sd_qc_per_block && slot < sdp->sd_quota_slots;
|
||||
y++, slot++) {
|
||||
y++, slot++, qc++) {
|
||||
struct gfs2_quota_data *old_qd, *qd;
|
||||
s64 qc_change = be64_to_cpu(qc->qc_change);
|
||||
u32 qc_flags = be32_to_cpu(qc->qc_flags);
|
||||
@@ -1441,7 +1455,6 @@ int gfs2_quota_init(struct gfs2_sbd *sdp)
|
||||
USRQUOTA : GRPQUOTA;
|
||||
struct kqid qc_id = make_kqid(&init_user_ns, qtype,
|
||||
be32_to_cpu(qc->qc_id));
|
||||
qc++;
|
||||
if (!qc_change)
|
||||
continue;
|
||||
|
||||
@@ -1458,7 +1471,7 @@ int gfs2_quota_init(struct gfs2_sbd *sdp)
|
||||
|
||||
spin_lock(&qd_lock);
|
||||
spin_lock_bucket(hash);
|
||||
old_qd = gfs2_qd_search_bucket(hash, sdp, qc_id);
|
||||
old_qd = gfs2_qd_search_bucket_noref(hash, sdp, qc_id);
|
||||
if (old_qd) {
|
||||
fs_err(sdp, "Corruption found in quota_change%u"
|
||||
"file: duplicate identifier in "
|
||||
@@ -1467,7 +1480,6 @@ int gfs2_quota_init(struct gfs2_sbd *sdp)
|
||||
|
||||
spin_unlock_bucket(hash);
|
||||
spin_unlock(&qd_lock);
|
||||
qd_put(old_qd);
|
||||
|
||||
gfs2_glock_put(qd->qd_gl);
|
||||
kmem_cache_free(gfs2_quotad_cachep, qd);
|
||||
|
||||
@@ -643,6 +643,7 @@ static void gfs2_put_super(struct super_block *sb)
|
||||
gfs2_delete_debugfs_file(sdp);
|
||||
|
||||
gfs2_sys_fs_del(sdp);
|
||||
rcu_barrier();
|
||||
free_sbd(sdp);
|
||||
}
|
||||
|
||||
|
||||
Reference in New Issue
Block a user