]> git.baikalelectronics.ru Git - kernel.git/commit
dm integrity: fix a crash due to BUG_ON in __journal_read_write()
authorMikulas Patocka <mpatocka@redhat.com>
Sat, 10 Aug 2019 16:30:27 +0000 (12:30 -0400)
committerMike Snitzer <snitzer@redhat.com>
Thu, 15 Aug 2019 20:01:57 +0000 (16:01 -0400)
commit2d304f34cf8123ec1e06a279ecf1cdb05d50c8e0
treee55a928df0896753c7c228569f4cf58bf01ba855
parente3a7e6fdae66f22aefae7ade6c4d47a582815dbf
dm integrity: fix a crash due to BUG_ON in __journal_read_write()

Fix a crash that was introduced by the commit f46fa52a89c5. The crash is
reported here: https://gitlab.com/cryptsetup/cryptsetup/issues/468

When reading from the integrity device, the function
dm_integrity_map_continue calls find_journal_node to find out if the
location to read is present in the journal. Then, it calculates how many
sectors are consecutively stored in the journal. Then, it locks the range
with add_new_range and wait_and_add_new_range.

The problem is that during wait_and_add_new_range, we hold no locks (we
don't hold ic->endio_wait.lock and we don't hold a range lock), so the
journal may change arbitrarily while wait_and_add_new_range sleeps.

The code then goes to __journal_read_write and hits
BUG_ON(journal_entry_get_sector(je) != logical_sector); because the
journal has changed.

In order to fix this bug, we need to re-check the journal location after
wait_and_add_new_range. We restrict the length to one block in order to
not complicate the code too much.

Fixes: f46fa52a89c5 ("dm integrity: implement fair range locks")
Cc: stable@vger.kernel.org # v4.19+
Signed-off-by: Mikulas Patocka <mpatocka@redhat.com>
Signed-off-by: Mike Snitzer <snitzer@redhat.com>
drivers/md/dm-integrity.c