From: Greg KH <gregkh@suse.de>
To: linux-kernel@vger.kernel.org, stable@kernel.org
Cc: stable-review@kernel.org, torvalds@linux-foundation.org,
akpm@linux-foundation.org, alan@lxorguk.ukuu.org.uk,
Namhyung Kim <namhyung@gmail.com>, NeilBrown <neilb@suse.de>
Subject: [84/89] md: check ->hot_remove_disk when removing disk
Date: Wed, 15 Jun 2011 17:00:47 -0700 [thread overview]
Message-ID: <20110616000237.210408182@clark.kroah.org> (raw)
In-Reply-To: <20110616000258.GA14529@kroah.com>
2.6.39-stable review patch. If anyone has any objections, please let us know.
------------------
From: Namhyung Kim <namhyung@gmail.com>
commit 01393f3d5836b7d62e925e6f4658a7eb22b83a11 upstream.
Check pers->hot_remove_disk instead of pers->hot_add_disk in slot_store()
during disk removal. The linear personality only has ->hot_add_disk and
no ->hot_remove_disk, so that removing disk in the array resulted to
following kernel bug:
$ sudo mdadm --create /dev/md0 --level=linear --raid-devices=4 /dev/loop[0-3]
$ echo none | sudo tee /sys/block/md0/md/dev-loop2/slot
BUG: unable to handle kernel NULL pointer dereference at (null)
IP: [< (null)>] (null)
PGD c9f5d067 PUD 8575a067 PMD 0
Oops: 0010 [#1] SMP
CPU 2
Modules linked in: linear loop bridge stp llc kvm_intel kvm asus_atk0110 sr_mod cdrom sg
Pid: 10450, comm: tee Not tainted 3.0.0-rc1-leonard+ #173 System manufacturer System Product Name/P5G41TD-M PRO
RIP: 0010:[<0000000000000000>] [< (null)>] (null)
RSP: 0018:ffff880085757df0 EFLAGS: 00010282
RAX: ffffffffa00168e0 RBX: ffff8800d1431800 RCX: 000000000000006e
RDX: 0000000000000001 RSI: 0000000000000002 RDI: ffff88008543c000
RBP: ffff880085757e48 R08: 0000000000000002 R09: 000000000000000a
R10: 0000000000000000 R11: ffff88008543c2e0 R12: 00000000ffffffff
R13: ffff8800b4641000 R14: 0000000000000005 R15: 0000000000000000
FS: 00007fe8c9e05700(0000) GS:ffff88011fa00000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 000000008005003b
CR2: 0000000000000000 CR3: 00000000b4502000 CR4: 00000000000406e0
DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
DR3: 0000000000000000 DR6: 00000000ffff0ff0 DR7: 0000000000000400
Process tee (pid: 10450, threadinfo ffff880085756000, task ffff8800c9f08000)
Stack:
ffffffff8138496a ffff8800b4641000 ffff88008543c268 0000000000000000
ffff8800b4641000 ffff88008543c000 ffff8800d1431868 ffffffff81a78a90
ffff8800b4641000 ffff88008543c000 ffff8800d1431800 ffff880085757e98
Call Trace:
[<ffffffff8138496a>] ? slot_store+0xaa/0x265
[<ffffffff81384bae>] rdev_attr_store+0x89/0xa8
[<ffffffff8115a96a>] sysfs_write_file+0x108/0x144
[<ffffffff81106b87>] vfs_write+0xb1/0x10d
[<ffffffff8106e6c0>] ? trace_hardirqs_on_caller+0x111/0x135
[<ffffffff81106cac>] sys_write+0x4d/0x77
[<ffffffff814fe702>] system_call_fastpath+0x16/0x1b
Code: Bad RIP value.
RIP [< (null)>] (null)
RSP <ffff880085757df0>
CR2: 0000000000000000
---[ end trace ba5fc64319a826fb ]---
Signed-off-by: Namhyung Kim <namhyung@gmail.com>
Signed-off-by: NeilBrown <neilb@suse.de>
Signed-off-by: Greg Kroah-Hartman <gregkh@suse.de>
---
drivers/md/md.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
--- a/drivers/md/md.c
+++ b/drivers/md/md.c
@@ -2462,7 +2462,7 @@ slot_store(mdk_rdev_t *rdev, const char
if (rdev->raid_disk == -1)
return -EEXIST;
/* personality does all needed checks */
- if (rdev->mddev->pers->hot_add_disk == NULL)
+ if (rdev->mddev->pers->hot_remove_disk == NULL)
return -EINVAL;
err = rdev->mddev->pers->
hot_remove_disk(rdev->mddev, rdev->raid_disk);
next prev parent reply other threads:[~2011-06-16 7:03 UTC|newest]
Thread overview: 80+ messages / expand[flat|nested] mbox.gz Atom feed top
2011-06-16 0:02 [00/89] 2.6.39.2-stable review Greg KH
2011-06-15 23:59 ` [01/89] lguest: fix timer interrupt setup Greg KH
2011-06-15 23:59 ` [02/89] intel-iommu: Flush unmaps at domain_exit Greg KH
2011-06-15 23:59 ` [03/89] intel-iommu: Only unlink device domains from iommu Greg KH
2011-06-15 23:59 ` [04/89] intel-iommu: Check for identity mapping candidate using Greg KH
2011-06-15 23:59 ` [05/89] intel-iommu: Speed up processing of the identity_mapping Greg KH
2011-06-15 23:59 ` [06/89] intel-iommu: Dont cache iova above 32bit Greg KH
2011-06-15 23:59 ` [07/89] intel-iommu: Use coherent DMA mask when requested Greg KH
2011-06-15 23:59 ` [08/89] intel-iommu: Remove Host Bridge devices from identity Greg KH
2011-06-15 23:59 ` [09/89] intel-iommu: Add domain check in domain_remove_one_dev_info Greg KH
2011-06-15 23:59 ` [10/89] powerpc/4xx: Fix regression in SMP on 476 Greg KH
2011-06-15 23:59 ` [11/89] arch/tile: allocate PCI IRQs later in boot Greg KH
2011-06-15 23:59 ` [12/89] UBIFS: fix shrinker object count reports Greg KH
2011-06-15 23:59 ` [13/89] UBIFS: fix memory leak on error path Greg KH
2011-06-15 23:59 ` [14/89] block: blkdev_get() should access ->bd_disk only after Greg KH
2011-06-15 23:59 ` [15/89] nbd: limit module parameters to a sane value Greg KH
2011-06-15 23:59 ` [16/89] [SCSI] Fix oops caused by queue refcounting failure Greg KH
2011-06-15 23:59 ` [17/89] ath9k: Reset chip on baseband hang Greg KH
2011-06-15 23:59 ` [18/89] ath9k: set 40 Mhz rate only if hw is configured in ht40 Greg KH
2011-06-15 23:59 ` [19/89] ath9k: fix two more bugs in tx power Greg KH
2011-06-15 23:59 ` [20/89] hwmon: (coretemp) Fix TjMax detection for older CPUs Greg KH
2011-06-15 23:59 ` [21/89] hwmon: (coretemp) Relax target temperature range check Greg KH
2011-06-15 23:59 ` [22/89] iwl4965: fix 5GHz operation Greg KH
2011-06-15 23:59 ` [23/89] iwl4965: correctly validate temperature value Greg KH
2011-06-15 23:59 ` [24/89] zd1211rw: fix to work on OHCI Greg KH
2011-06-15 23:59 ` [25/89] mm: fix ENOSPC returned by handle_mm_fault() Greg KH
2011-06-15 23:59 ` [26/89] serial: core, move termios handling to uart_startup Greg KH
2011-06-15 23:59 ` [27/89] serial: core, do not set DTR/RTS twice on startup Greg KH
2011-06-15 23:59 ` [28/89] serial: core, remove uart_update_termios Greg KH
2011-06-15 23:59 ` [29/89] PCI: Set PCIE maxpayload for card during hotplug insertion Greg KH
2011-06-15 23:59 ` [30/89] powerpc: Fix 32-bit SMP build Greg KH
2011-06-15 23:59 ` [31/89] asus-wmi: Remove __init from asus_wmi_platform_init Greg KH
2011-06-15 23:59 ` [32/89] nl80211: fix check for valid SSID size in scan operations Greg KH
2011-06-15 23:59 ` [33/89] block: export blk_{get,put}_queue() Greg KH
2011-06-15 23:59 ` [34/89] usbnet/cdc_ncm: add missing .reset_resume hook Greg KH
2011-06-15 23:59 ` [35/89] lockdep: Fix lock_is_held() on recursion Greg KH
2011-06-15 23:59 ` [36/89] drm/i915: Add a no lvds quirk for the Asus EeeBox PC EB1007 Greg KH
2011-06-16 0:00 ` [37/89] drm/radeon/kms: viewport height has to be even Greg KH
2011-06-16 0:00 ` [38/89] drm/radeon/kms: fix for radeon on systems >4GB without Greg KH
2011-06-16 0:00 ` [39/89] fat: Fix corrupt inode flags when remove ATTR_SYS flag Greg KH
2011-06-16 0:00 ` [40/89] xen: off by one errors in multicalls.c Greg KH
2011-06-16 0:00 ` [51/89] option: add Zoom 4597 modem USB IDs Greg KH
2011-06-16 0:00 ` [52/89] option: add Alcatel X200 to sendsetup blacklist Greg KH
2011-06-16 0:00 ` [53/89] option: add Prolink PH300 modem IDs Greg KH
2011-06-16 0:00 ` [54/89] USB: option Add blacklist for ZTE K3765-Z (19d2:2002) Greg KH
2011-06-16 0:00 ` [55/89] Revert "USB: option: add ID for ZTE MF 330" Greg KH
2011-06-16 0:00 ` [56/89] USB: core: Tolerate protocol stall during hub and port Greg KH
2011-06-16 0:00 ` [57/89] USB: serial: add another 4N-GALAXY.DE PID to ftdi_sio driver Greg KH
2011-06-16 0:00 ` [58/89] usb-storage: redo incorrect reads Greg KH
2011-06-16 0:00 ` [59/89] Revert "x86, efi: Retain boot service code until after switching to virtual mode" Greg KH
2011-06-16 0:00 ` [60/89] xhci: Add defines for hardcoded slot states Greg KH
2011-06-16 0:00 ` [61/89] xhci: Do not issue device reset when device is not setup Greg KH
2011-06-16 0:00 ` [62/89] xhci: Disable MSI for some Fresco Logic hosts Greg KH
2011-06-16 0:00 ` [63/89] USB: xhci - fix interval calculation for FS isoc endpoints Greg KH
2011-06-16 0:00 ` [64/89] AppArmor: Fix sleep in invalid context from task_setrlimit Greg KH
2011-06-16 0:00 ` [65/89] cifs: dont allow cifs_reconnect to exit with NULL socket Greg KH
2011-06-16 0:00 ` [66/89] ASoC: AD1836: Fix setting the PCM format Greg KH
2011-06-16 0:00 ` [67/89] ASoC: Fix WM8962 headphone volume update for use of advanced Greg KH
2011-06-16 0:00 ` [68/89] ASoC: WM8804 does not support sample rates below 32kHz Greg KH
2011-06-16 0:00 ` [69/89] ASoC: snd_soc_new_{mixer,mux,pga} make sure to use right Greg KH
2011-06-16 0:00 ` [70/89] ASoC: SAMSUNG: Fix the incorrect referencing of I2SCON Greg KH
2011-06-16 0:00 ` [71/89] ALSA: hda: Fix quirk for Dell Inspiron 910 Greg KH
2011-06-16 0:00 ` [72/89] oprofile: Free potentially owned tasks in case of errors Greg KH
2011-06-16 0:00 ` [73/89] oprofile: Fix locking dependency in sync_start() Greg KH
2011-06-16 0:00 ` [74/89] oprofile, dcookies: Fix possible circular locking dependency Greg KH
2011-06-16 0:00 ` [75/89] drm/radeon/kms: do bounds checking for 3D_LOAD_VBPNTR and Greg KH
2011-06-16 0:00 ` [76/89] iwlagn: use cts-to-self protection on 5000 adapters series Greg KH
2011-06-16 0:00 ` [77/89] iwl4965: set tx power after rxon_assoc Greg KH
2011-06-16 0:00 ` [78/89] igb: fix i350 SR-IOV failture Greg KH
2011-06-16 0:00 ` [79/89] mac80211: fix IBSS teardown race Greg KH
2011-06-16 0:00 ` [80/89] x86: devicetree: Add missing early_init_dt_setup_initrd_arch Greg KH
2011-06-16 0:00 ` [81/89] x86: cpu-hotplug: Prevent softirq wakeup on wrong CPU Greg KH
2011-06-16 0:00 ` [82/89] CPUFREQ: Remove cpufreq_stats sysfs entries on module unload Greg KH
2011-06-16 0:00 ` [83/89] TOMOYO: Fix oops in tomoyo_mount_acl() Greg KH
2011-06-16 0:00 ` Greg KH [this message]
2011-06-16 0:00 ` [85/89] md/raid5: fix raid5_set_bi_hw_segments Greg KH
2011-06-16 0:00 ` [86/89] md/raid5: fix FUA request handling in ops_run_io() Greg KH
2011-06-16 0:00 ` [87/89] iwlagn: send tx power command if defer cause by RXON not Greg KH
2011-06-16 0:00 ` [88/89] iwlagn: fix channel switch locking Greg KH
2011-06-16 0:00 ` [89/89] iwlegacy: " Greg KH
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20110616000237.210408182@clark.kroah.org \
--to=gregkh@suse.de \
--cc=akpm@linux-foundation.org \
--cc=alan@lxorguk.ukuu.org.uk \
--cc=linux-kernel@vger.kernel.org \
--cc=namhyung@gmail.com \
--cc=neilb@suse.de \
--cc=stable-review@kernel.org \
--cc=stable@kernel.org \
--cc=torvalds@linux-foundation.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®