Skip to content

Commit b466340

Browse files
icb-linuxgregkh
authored andcommitted
ocfs2: fix missing metadata reservation for large xattrs
commit 0cdc7dd upstream. [BUG] lsetxattr() panics the kernel when setting a large xattr value on a fragmented filesystem where the file already has an external xattr block. [CAUSE] ocfs2_calc_xattr_set_need() never reserves metadata blocks for a new xattr value's extent tree when the file already has an external xattr block. The not_found path leaves meta_add at zero, so meta_ac is NULL when ocfs2_xattr_extend_allocation() runs. A new value root has room for a single extent record. On a fragmented filesystem, the allocator cannot satisfy the xattr value in one contiguous run, so each non-contiguous run requires its own extent record. When the value root's extent list is full and meta_ac is NULL, ocfs2_add_clusters_in_btree() returns RESTART_META, and ocfs2_xattr_extend_allocation() hits BUG_ON(why == RESTART_META). [FIX] The case where no xattr block exists yet already calls ocfs2_extend_meta_needed(&def_xv.xv.xr_list) to reserve value tree metadata. Add the same reservation to the case where an xattr block already exists, making the two cases consistent. Replace the BUG_ON with a -ENOSPC return so that if RESTART_META is returned despite the reservation, the error propagates to userspace instead of panicking the kernel. Link: https://lore.kernel.org/amLwn3i9tET8yhG7@dev Fixes: a78f9f4 ("ocfs2: make xattr extension work with new local alloc reservation.") Signed-off-by: Ian Bridges <icb@fastmail.org> Reported-by: syzbot+e538032956b1157914a3@syzkaller.appspotmail.com Closes: https://syzkaller.appspot.com/bug?extid=e538032956b1157914a3 Reviewed-by: Joseph Qi <joseph.qi@linux.alibaba.com> Cc: Mark Fasheh <mark@fasheh.com> Cc: Joel Becker <jlbec@evilplan.org> Cc: Junxiao Bi <junxiao.bi@oracle.com> Cc: Changwei Ge <gechangwei@live.cn> Cc: Jun Piao <piaojun@huawei.com> Cc: Heming Zhao <heming.zhao@suse.com> Cc: <stable@vger.kernel.org> Signed-off-by: Andrew Morton <akpm@linux-foundation.org> Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
1 parent 4d0892a commit b466340

1 file changed

Lines changed: 12 additions & 6 deletions

File tree

fs/ocfs2/xattr.c

Lines changed: 12 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -740,12 +740,10 @@ static int ocfs2_xattr_extend_allocation(struct inode *inode,
740740
prev_clusters;
741741

742742
if (why != RESTART_NONE && clusters_to_add) {
743-
/*
744-
* We can only fail in case the alloc file doesn't give
745-
* up enough clusters.
746-
*/
747-
BUG_ON(why == RESTART_META);
748-
743+
if (why == RESTART_META) {
744+
status = -ENOSPC;
745+
break;
746+
}
749747
credits = ocfs2_calc_extend_credits(inode->i_sb,
750748
&vb->vb_xv->xr_list);
751749
status = ocfs2_extend_trans(handle, credits);
@@ -3214,6 +3212,14 @@ static int ocfs2_calc_xattr_set_need(struct inode *inode,
32143212
} else
32153213
credits += OCFS2_SUBALLOC_ALLOC + 1;
32163214

3215+
/*
3216+
* Reserve metadata for the new xattr's value extent tree.
3217+
* The not_found path above adds credits for this tree but
3218+
* omits meta_add, leaving meta_ac NULL for large values.
3219+
*/
3220+
if (xi->xi_value_len > OCFS2_XATTR_INLINE_SIZE)
3221+
meta_add += ocfs2_extend_meta_needed(&def_xv.xv.xr_list);
3222+
32173223
/*
32183224
* This cluster will be used either for new bucket or for
32193225
* new xattr block.

0 commit comments

Comments
 (0)