Donate to e Foundation | Murena handsets with /e/OS | Own a part of Murena! Learn more

Commit 67d73f41 authored by Eric Sandeen's avatar Eric Sandeen Committed by Greg Kroah-Hartman
Browse files

xfs: handle error if xfs_btree_get_bufs fails



commit 93e8befc17f6d6ea92b0aee3741ceac8bca4590f upstream.

Jason reported that a corrupted filesystem failed to replay
the log with a metadata block out of bounds warning:

XFS (dm-2): _xfs_buf_find: Block out of range: block 0x80270fff8, EOFS 0x9c40000

_xfs_buf_find() and xfs_btree_get_bufs() return NULL if
that happens, and then when xfs_alloc_fix_freelist() calls
xfs_trans_binval() on that NULL bp, we oops with:

BUG: unable to handle kernel NULL pointer dereference at 00000000000000f8

We don't handle _xfs_buf_find errors very well, every
caller higher up the stack gets to guess at why it failed.
But we should at least handle it somehow, so return
EFSCORRUPTED here.

Reported-by: default avatarJason L Tibbitts III <tibbs@math.uh.edu>
Signed-off-by: default avatarEric Sandeen <sandeen@redhat.com>
Reviewed-by: default avatarChristoph Hellwig <hch@lst.de>
Reviewed-by: default avatarDarrick J. Wong <darrick.wong@oracle.com>
Signed-off-by: default avatarDarrick J. Wong <darrick.wong@oracle.com>
Signed-off-by: default avatarGreg Kroah-Hartman <gregkh@linuxfoundation.org>
parent fee940a8
Loading
Loading
Loading
Loading
+8 −0
Original line number Diff line number Diff line
@@ -1579,6 +1579,10 @@ xfs_alloc_ag_vextent_small(

				bp = xfs_btree_get_bufs(args->mp, args->tp,
					args->agno, fbno, 0);
				if (!bp) {
					error = -EFSCORRUPTED;
					goto error0;
				}
				xfs_trans_binval(args->tp, bp);
			}
			args->len = 1;
@@ -2136,6 +2140,10 @@ xfs_alloc_fix_freelist(
		if (error)
			goto out_agbp_relse;
		bp = xfs_btree_get_bufs(mp, tp, args->agno, bno, 0);
		if (!bp) {
			error = -EFSCORRUPTED;
			goto out_agbp_relse;
		}
		xfs_trans_binval(tp, bp);
	}