From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1751255AbWFSJLj (ORCPT ); Mon, 19 Jun 2006 05:11:39 -0400 Received: (majordomo@vger.kernel.org) by vger.kernel.org id S1751257AbWFSJLj (ORCPT ); Mon, 19 Jun 2006 05:11:39 -0400 Received: from 1wt.eu ([62.212.114.60]:62472 "EHLO 1wt.eu") by vger.kernel.org with ESMTP id S1751255AbWFSJLj (ORCPT ); Mon, 19 Jun 2006 05:11:39 -0400 Date: Mon, 19 Jun 2006 11:08:15 +0200 From: Willy Tarreau To: Grant Coady Cc: Marcelo Tosatti , linux-kernel@vger.kernel.org, Al Viro Subject: Re: Linux 2.4.33-rc1 Message-ID: <20060619090815.GB3472@1wt.eu> References: <20060616181419.GA15734@dmt> <20060618133718.GA2467@dmt> <20060618223736.GA4965@1wt.eu> <20060619040152.GB2678@1wt.eu> <20060619080651.GA3273@1wt.eu> Mime-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: User-Agent: Mutt/1.5.11 Sender: linux-kernel-owner@vger.kernel.org X-Mailing-List: linux-kernel@vger.kernel.org On Mon, Jun 19, 2006 at 06:53:31PM +1000, Grant Coady wrote: > On Mon, 19 Jun 2006 10:06:51 +0200, Willy Tarreau wrote: > > >Hi Grant, > > > >OK, it does *really* crash in vfs_unlink(), during the double_up on > >dentry->inode-i_zombie (dentry->inode = NULL). > > > >I suggest the following fix, I hope that it is correct and is not subject > >to any race condition : > > > >--- ./fs/namei.c.orig 2006-06-19 09:39:52.000000000 +0200 > >+++ ./fs/namei.c 2006-06-19 09:51:09.000000000 +0200 > >@@ -1478,12 +1478,14 @@ > > int vfs_unlink(struct inode *dir, struct dentry *dentry) > > { > > int error; > >+ struct inode *inode; > > > > error = may_delete(dir, dentry, 0); > > if (error) > > return error; > > > >- double_down(&dir->i_zombie, &dentry->d_inode->i_zombie); > >+ inode = dentry->d_inode; > >+ double_down(&dir->i_zombie, &inode->i_zombie); > > error = -EPERM; > > if (dir->i_op && dir->i_op->unlink) { > > DQUOT_INIT(dir); > >@@ -1495,7 +1497,7 @@ > > unlock_kernel(); > > } > > } > >- double_up(&dir->i_zombie, &dentry->d_inode->i_zombie); > >+ double_up(&dir->i_zombie, &inode->i_zombie); > > if (!error) { > > d_delete(dentry); > > inode_dir_notify(dir, DN_DELETE); > > > >I think it will *not* oops anymore with this fix, but I'd like someone to > >review it to ensure that it is valid. > > Hi Willy, > > Still corrupts a vim edit backup filename as previously reported, > instead of /etc/lilo.conf~ I get /etc/lilo.co~ :( Ok, thanks. At least we're making progress. Could you try on another file, with fewer chars after the dot ? I suspect that one particular error is reported to vim and that it retries with a shorter name, for instance to be compatible with 8.3. If this is the case, the problem might be in vfs_link() (but I don't see why). > Grant. Cheers, Willy