aboutsummaryrefslogtreecommitdiffstats
path: root/fs/ext4/inode.c
diff options
context:
space:
mode:
authorEric Sandeen <sandeen@redhat.com>2014-10-11 19:51:17 -0400
committerTheodore Ts'o <tytso@mit.edu>2014-10-11 19:51:17 -0400
commit0ff8947fc5f700172b37cbca811a38eb9cb81e08 (patch)
tree528f48fb5ee9fbb0bce73aae1b2b78528824069e /fs/ext4/inode.c
parentf4bb2981024fc91b23b4d09a8817c415396dbabb (diff)
ext4: fix reservation overflow in ext4_da_write_begin
Delalloc write journal reservations only reserve 1 credit, to update the inode if necessary. However, it may happen once in a filesystem's lifetime that a file will cross the 2G threshold, and require the LARGE_FILE feature to be set in the superblock as well, if it was not set already. This overruns the transaction reservation, and can be demonstrated simply on any ext4 filesystem without the LARGE_FILE feature already set: dd if=/dev/zero of=testfile bs=1 seek=2147483646 count=1 \ conv=notrunc of=testfile sync dd if=/dev/zero of=testfile bs=1 seek=2147483647 count=1 \ conv=notrunc of=testfile leads to: EXT4-fs: ext4_do_update_inode:4296: aborting transaction: error 28 in __ext4_handle_dirty_super EXT4-fs error (device loop0) in ext4_do_update_inode:4301: error 28 EXT4-fs error (device loop0) in ext4_reserve_inode_write:4757: Readonly filesystem EXT4-fs error (device loop0) in ext4_dirty_inode:4876: error 28 EXT4-fs error (device loop0) in ext4_da_write_end:2685: error 28 Adjust the number of credits based on whether the flag is already set, and whether the current write may extend past the LARGE_FILE limit. Signed-off-by: Eric Sandeen <sandeen@redhat.com> Signed-off-by: Theodore Ts'o <tytso@mit.edu> Reviewed-by: Andreas Dilger <adilger@dilger.ca> Cc: stable@vger.kernel.org
Diffstat (limited to 'fs/ext4/inode.c')
-rw-r--r--fs/ext4/inode.c17
1 files changed, 16 insertions, 1 deletions
diff --git a/fs/ext4/inode.c b/fs/ext4/inode.c
index e204d8aabe7d..0dd9150c0c04 100644
--- a/fs/ext4/inode.c
+++ b/fs/ext4/inode.c
@@ -2495,6 +2495,20 @@ static int ext4_nonda_switch(struct super_block *sb)
2495 return 0; 2495 return 0;
2496} 2496}
2497 2497
2498/* We always reserve for an inode update; the superblock could be there too */
2499static int ext4_da_write_credits(struct inode *inode, loff_t pos, unsigned len)
2500{
2501 if (likely(EXT4_HAS_RO_COMPAT_FEATURE(inode->i_sb,
2502 EXT4_FEATURE_RO_COMPAT_LARGE_FILE)))
2503 return 1;
2504
2505 if (pos + len <= 0x7fffffffULL)
2506 return 1;
2507
2508 /* We might need to update the superblock to set LARGE_FILE */
2509 return 2;
2510}
2511
2498static int ext4_da_write_begin(struct file *file, struct address_space *mapping, 2512static int ext4_da_write_begin(struct file *file, struct address_space *mapping,
2499 loff_t pos, unsigned len, unsigned flags, 2513 loff_t pos, unsigned len, unsigned flags,
2500 struct page **pagep, void **fsdata) 2514 struct page **pagep, void **fsdata)
@@ -2545,7 +2559,8 @@ retry_grab:
2545 * of file which has an already mapped buffer. 2559 * of file which has an already mapped buffer.
2546 */ 2560 */
2547retry_journal: 2561retry_journal:
2548 handle = ext4_journal_start(inode, EXT4_HT_WRITE_PAGE, 1); 2562 handle = ext4_journal_start(inode, EXT4_HT_WRITE_PAGE,
2563 ext4_da_write_credits(inode, pos, len));
2549 if (IS_ERR(handle)) { 2564 if (IS_ERR(handle)) {
2550 page_cache_release(page); 2565 page_cache_release(page);
2551 return PTR_ERR(handle); 2566 return PTR_ERR(handle);