From: Chao Yu <yuchao0@huawei.com> To: Jaegeuk Kim <jaegeuk@kernel.org>, Chao Yu <chao@kernel.org> Cc: <linux-f2fs-devel@lists.sourceforge.net>, <linux-kernel@vger.kernel.org> Subject: Re: [PATCH] f2fs: fix to avoid accessing uninitialized field of inode page in is_alive() Date: Mon, 9 Sep 2019 16:16:35 +0800 [thread overview] Message-ID: <873f4c07-5694-6554-5266-81812a6bd617@huawei.com> (raw) In-Reply-To: <79228eaa-776f-da89-89f8-a9b5a90034b6@huawei.com> On 2019/9/9 15:58, Chao Yu wrote: > On 2019/9/9 15:44, Jaegeuk Kim wrote: >> On 09/07, Chao Yu wrote: >>> On 2019-9-7 7:48, Jaegeuk Kim wrote: >>>> On 09/06, Chao Yu wrote: >>>>> If inode is newly created, inode page may not synchronize with inode cache, >>>>> so fields like .i_inline or .i_extra_isize could be wrong, in below call >>>>> path, we may access such wrong fields, result in failing to migrate valid >>>>> target block. >>>> >>>> If data is valid, how can we get new inode page? >> >> Let me rephrase the question. If inode is newly created, is this data block >> really valid to move in GC? > > I guess it's valid, let double check that. We can see inode page: - f2fs_create - f2fs_add_link - f2fs_add_dentry - f2fs_init_inode_metadata - f2fs_add_inline_entry - ipage = f2fs_new_inode_page - f2fs_put_page(ipage) <---- after this > >> >>> >>> is_alive() >>> { >>> ... >>> node_page = f2fs_get_node_page(sbi, nid); <--- inode page >> >> Aren't we seeing the below version warnings? >> >> if (sum->version != dni->version) { >> f2fs_warn(sbi, "%s: valid data with mismatched node version.", >> __func__); >> set_sbi_flag(sbi, SBI_NEED_FSCK); >> } The version of summary and dni are all zero. summary nid: 613, ofs: 111, ver: 0 blkaddr 2436 (blkaddr in node 0) expect: seg 10, ofs_in_seg: 54 real: seg 4294967295, ofs_in_seg: 0 ofs: 54, 0 node info ino:613, nid:613, nofs:0 ofs_in_addr: 0 Thanks, >> >>> >>> source_blkaddr = datablock_addr(NULL, node_page, ofs_in_node); >> >> So, we're getting this? Does this incur infinite loop in GC? >> >> if (!test_and_set_bit(segno, SIT_I(sbi)->invalid_segmap)) { >> f2fs_err(sbi, "mismatched blkaddr %u (source_blkaddr %u) in seg %u\n", >> f2fs_bug_on(sbi, 1); >> } > > Yes, I only get this with generic/269, rather than "valid data with mismatched > node version.". > > With this patch, generic/269 won't panic again. > > Thanks, > >> >>> ... >>> } >>> >>> datablock_addr() >>> { >>> ... >>> base = offset_in_addr(&raw_node->i); <--- the base could be wrong here due to >>> accessing uninitialized .i_inline of raw_node->i. >>> ... >>> } >>> >>> Thanks, >>> >>>> >>>>> >>>>> - gc_data_segment >>>>> - is_alive >>>>> - datablock_addr >>>>> - offset_in_addr >>>>> >>>>> Fixes: 7a2af766af15 ("f2fs: enhance on-disk inode structure scalability") >>>>> Signed-off-by: Chao Yu <yuchao0@huawei.com> >>>>> --- >>>>> fs/f2fs/dir.c | 3 +++ >>>>> 1 file changed, 3 insertions(+) >>>>> >>>>> diff --git a/fs/f2fs/dir.c b/fs/f2fs/dir.c >>>>> index 765f13354d3f..b1840852967e 100644 >>>>> --- a/fs/f2fs/dir.c >>>>> +++ b/fs/f2fs/dir.c >>>>> @@ -479,6 +479,9 @@ struct page *f2fs_init_inode_metadata(struct inode *inode, struct inode *dir, >>>>> if (IS_ERR(page)) >>>>> return page; >>>>> >>>>> + /* synchronize inode page's data from inode cache */ >>>>> + f2fs_update_inode(inode, page); >>>>> + >>>>> if (S_ISDIR(inode->i_mode)) { >>>>> /* in order to handle error case */ >>>>> get_page(page); >>>>> -- >>>>> 2.18.0.rc1 >> . >>
WARNING: multiple messages have this Message-ID (diff)
From: Chao Yu <yuchao0@huawei.com> To: Jaegeuk Kim <jaegeuk@kernel.org>, Chao Yu <chao@kernel.org> Cc: linux-kernel@vger.kernel.org, linux-f2fs-devel@lists.sourceforge.net Subject: Re: [f2fs-dev] [PATCH] f2fs: fix to avoid accessing uninitialized field of inode page in is_alive() Date: Mon, 9 Sep 2019 16:16:35 +0800 [thread overview] Message-ID: <873f4c07-5694-6554-5266-81812a6bd617@huawei.com> (raw) In-Reply-To: <79228eaa-776f-da89-89f8-a9b5a90034b6@huawei.com> On 2019/9/9 15:58, Chao Yu wrote: > On 2019/9/9 15:44, Jaegeuk Kim wrote: >> On 09/07, Chao Yu wrote: >>> On 2019-9-7 7:48, Jaegeuk Kim wrote: >>>> On 09/06, Chao Yu wrote: >>>>> If inode is newly created, inode page may not synchronize with inode cache, >>>>> so fields like .i_inline or .i_extra_isize could be wrong, in below call >>>>> path, we may access such wrong fields, result in failing to migrate valid >>>>> target block. >>>> >>>> If data is valid, how can we get new inode page? >> >> Let me rephrase the question. If inode is newly created, is this data block >> really valid to move in GC? > > I guess it's valid, let double check that. We can see inode page: - f2fs_create - f2fs_add_link - f2fs_add_dentry - f2fs_init_inode_metadata - f2fs_add_inline_entry - ipage = f2fs_new_inode_page - f2fs_put_page(ipage) <---- after this > >> >>> >>> is_alive() >>> { >>> ... >>> node_page = f2fs_get_node_page(sbi, nid); <--- inode page >> >> Aren't we seeing the below version warnings? >> >> if (sum->version != dni->version) { >> f2fs_warn(sbi, "%s: valid data with mismatched node version.", >> __func__); >> set_sbi_flag(sbi, SBI_NEED_FSCK); >> } The version of summary and dni are all zero. summary nid: 613, ofs: 111, ver: 0 blkaddr 2436 (blkaddr in node 0) expect: seg 10, ofs_in_seg: 54 real: seg 4294967295, ofs_in_seg: 0 ofs: 54, 0 node info ino:613, nid:613, nofs:0 ofs_in_addr: 0 Thanks, >> >>> >>> source_blkaddr = datablock_addr(NULL, node_page, ofs_in_node); >> >> So, we're getting this? Does this incur infinite loop in GC? >> >> if (!test_and_set_bit(segno, SIT_I(sbi)->invalid_segmap)) { >> f2fs_err(sbi, "mismatched blkaddr %u (source_blkaddr %u) in seg %u\n", >> f2fs_bug_on(sbi, 1); >> } > > Yes, I only get this with generic/269, rather than "valid data with mismatched > node version.". > > With this patch, generic/269 won't panic again. > > Thanks, > >> >>> ... >>> } >>> >>> datablock_addr() >>> { >>> ... >>> base = offset_in_addr(&raw_node->i); <--- the base could be wrong here due to >>> accessing uninitialized .i_inline of raw_node->i. >>> ... >>> } >>> >>> Thanks, >>> >>>> >>>>> >>>>> - gc_data_segment >>>>> - is_alive >>>>> - datablock_addr >>>>> - offset_in_addr >>>>> >>>>> Fixes: 7a2af766af15 ("f2fs: enhance on-disk inode structure scalability") >>>>> Signed-off-by: Chao Yu <yuchao0@huawei.com> >>>>> --- >>>>> fs/f2fs/dir.c | 3 +++ >>>>> 1 file changed, 3 insertions(+) >>>>> >>>>> diff --git a/fs/f2fs/dir.c b/fs/f2fs/dir.c >>>>> index 765f13354d3f..b1840852967e 100644 >>>>> --- a/fs/f2fs/dir.c >>>>> +++ b/fs/f2fs/dir.c >>>>> @@ -479,6 +479,9 @@ struct page *f2fs_init_inode_metadata(struct inode *inode, struct inode *dir, >>>>> if (IS_ERR(page)) >>>>> return page; >>>>> >>>>> + /* synchronize inode page's data from inode cache */ >>>>> + f2fs_update_inode(inode, page); >>>>> + >>>>> if (S_ISDIR(inode->i_mode)) { >>>>> /* in order to handle error case */ >>>>> get_page(page); >>>>> -- >>>>> 2.18.0.rc1 >> . >> _______________________________________________ Linux-f2fs-devel mailing list Linux-f2fs-devel@lists.sourceforge.net https://lists.sourceforge.net/lists/listinfo/linux-f2fs-devel
next prev parent reply other threads:[~2019-09-09 8:17 UTC|newest] Thread overview: 24+ messages / expand[flat|nested] mbox.gz Atom feed top 2019-09-06 10:54 [PATCH] f2fs: fix to avoid accessing uninitialized field of inode page in is_alive() Chao Yu 2019-09-06 10:54 ` [f2fs-dev] " Chao Yu 2019-09-06 23:48 ` Jaegeuk Kim 2019-09-06 23:48 ` [f2fs-dev] " Jaegeuk Kim 2019-09-07 1:23 ` Chao Yu 2019-09-07 1:23 ` [f2fs-dev] " Chao Yu 2019-09-09 7:44 ` Jaegeuk Kim 2019-09-09 7:44 ` [f2fs-dev] " Jaegeuk Kim 2019-09-09 7:58 ` Chao Yu 2019-09-09 7:58 ` [f2fs-dev] " Chao Yu 2019-09-09 8:16 ` Chao Yu [this message] 2019-09-09 8:16 ` Chao Yu 2019-09-09 8:37 ` Jaegeuk Kim 2019-09-09 8:37 ` [f2fs-dev] " Jaegeuk Kim 2019-09-09 9:18 ` Chao Yu 2019-09-09 9:18 ` [f2fs-dev] " Chao Yu 2019-09-09 9:33 ` Jaegeuk Kim 2019-09-09 9:33 ` [f2fs-dev] " Jaegeuk Kim 2019-09-09 11:05 ` Chao Yu 2019-09-09 11:05 ` [f2fs-dev] " Chao Yu 2019-09-09 14:37 ` Jaegeuk Kim 2019-09-09 14:37 ` [f2fs-dev] " Jaegeuk Kim 2019-09-10 0:59 ` Chao Yu 2019-09-10 0:59 ` [f2fs-dev] " Chao Yu
Reply instructions: You may reply publicly to this message via plain-text email using any one of the following methods: * Save the following mbox file, import it into your mail client, and reply-to-all from there: mbox Avoid top-posting and favor interleaved quoting: https://en.wikipedia.org/wiki/Posting_style#Interleaved_style * Reply using the --to, --cc, and --in-reply-to switches of git-send-email(1): git send-email \ --in-reply-to=873f4c07-5694-6554-5266-81812a6bd617@huawei.com \ --to=yuchao0@huawei.com \ --cc=chao@kernel.org \ --cc=jaegeuk@kernel.org \ --cc=linux-f2fs-devel@lists.sourceforge.net \ --cc=linux-kernel@vger.kernel.org \ /path/to/YOUR_REPLY https://kernel.org/pub/software/scm/git/docs/git-send-email.html * If your mail client supports setting the In-Reply-To header via mailto: links, try the mailto: linkBe sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes, see mirroring instructions on how to clone and mirror all data and code used by this external index.