mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* [PATCH] autofs - fix lockref lookup
@ 2014-04-23  5:20 Ian Kent
  2014-04-23 21:46 ` Andrew Morton
  0 siblings, 1 reply; 3+ messages in thread
From: Ian Kent @ 2014-04-23  5:20 UTC (permalink / raw)
  To: Andrew Morton; +Cc: autofs mailing list, Kernel Mailing List

autofs needs to be able to see private data dentry flags for
its dentrys that are being created but not yet hashed and for
its dentys that have been rmdir()ed but not yet freed. It
needs to do this so it can block processes in these states
until a status has been returned to indicate the given
operation is complete.

It does this by keeping two lists, active and expring, of
dentrys in this state and uses ->d_release() to keep them
stable while it checks the reference count to determine
if they should be used.

But with the recent lockref changes dentrys being freed
sometimes don't transition to a reference count of 0 before
being freed so autofs can occassionally use a dentry that
is invalid which can lead to a panic.

Signed-off-by: Ian Kent <raven@themaw.net>
---
 fs/autofs4/root.c |    4 ++--
 1 file changed, 2 insertions(+), 2 deletions(-)

diff --git a/fs/autofs4/root.c b/fs/autofs4/root.c
index 2caf36a..cc87c1a 100644
--- a/fs/autofs4/root.c
+++ b/fs/autofs4/root.c
@@ -179,7 +179,7 @@ static struct dentry *autofs4_lookup_active(struct dentry *dentry)
 		spin_lock(&active->d_lock);
 
 		/* Already gone? */
-		if (!d_count(active))
+		if ((int) d_count(active) <= 0)
 			goto next;
 
 		qstr = &active->d_name;
@@ -230,7 +230,7 @@ static struct dentry *autofs4_lookup_expiring(struct dentry *dentry)
 
 		spin_lock(&expiring->d_lock);
 
-		/* Bad luck, we've already been dentry_iput */
+		/* We've already been dentry_iput or unlinked */
 		if (!expiring->d_inode)
 			goto next;
 


^ permalink raw reply	[flat|nested] 3+ messages in thread

* Re: [PATCH] autofs - fix lockref lookup
  2014-04-23  5:20 [PATCH] autofs - fix lockref lookup Ian Kent
@ 2014-04-23 21:46 ` Andrew Morton
  2014-04-24  4:10   ` Ian Kent
  0 siblings, 1 reply; 3+ messages in thread
From: Andrew Morton @ 2014-04-23 21:46 UTC (permalink / raw)
  To: Ian Kent; +Cc: autofs mailing list, Kernel Mailing List

On Wed, 23 Apr 2014 13:20:36 +0800 Ian Kent <raven@themaw.net> wrote:

> autofs needs to be able to see private data dentry flags for
> its dentrys that are being created but not yet hashed and for
> its dentys that have been rmdir()ed but not yet freed. It
> needs to do this so it can block processes in these states
> until a status has been returned to indicate the given
> operation is complete.
> 
> It does this by keeping two lists, active and expring, of
> dentrys in this state and uses ->d_release() to keep them
> stable while it checks the reference count to determine
> if they should be used.
> 
> But with the recent lockref changes dentrys being freed
> sometimes don't transition to a reference count of 0 before
> being freed so autofs can occassionally use a dentry that
> is invalid which can lead to a panic.

What's the value of "recent"?  I assume 3.14 is OK?

^ permalink raw reply	[flat|nested] 3+ messages in thread

* Re: [PATCH] autofs - fix lockref lookup
  2014-04-23 21:46 ` Andrew Morton
@ 2014-04-24  4:10   ` Ian Kent
  0 siblings, 0 replies; 3+ messages in thread
From: Ian Kent @ 2014-04-24  4:10 UTC (permalink / raw)
  To: Andrew Morton; +Cc: autofs mailing list, Kernel Mailing List

On Wed, 2014-04-23 at 14:46 -0700, Andrew Morton wrote:
> On Wed, 23 Apr 2014 13:20:36 +0800 Ian Kent <raven@themaw.net> wrote:
> 
> > autofs needs to be able to see private data dentry flags for
> > its dentrys that are being created but not yet hashed and for
> > its dentys that have been rmdir()ed but not yet freed. It
> > needs to do this so it can block processes in these states
> > until a status has been returned to indicate the given
> > operation is complete.
> > 
> > It does this by keeping two lists, active and expring, of
> > dentrys in this state and uses ->d_release() to keep them
> > stable while it checks the reference count to determine
> > if they should be used.
> > 
> > But with the recent lockref changes dentrys being freed
> > sometimes don't transition to a reference count of 0 before
> > being freed so autofs can occassionally use a dentry that
> > is invalid which can lead to a panic.
> 
> What's the value of "recent"?  I assume 3.14 is OK?

I'll need to look again but from memory it's broken from 3.12 onward.

The breakage happened when lockref_mark_dead() was introduced because it
sets lockref->count = -128 instead of reducing count by one as was done
previously.

Ian
  



^ permalink raw reply	[flat|nested] 3+ messages in thread

end of thread, other threads:[~2014-04-24  4:10 UTC | newest]

Thread overview: 3+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2014-04-23  5:20 [PATCH] autofs - fix lockref lookup Ian Kent
2014-04-23 21:46 ` Andrew Morton
2014-04-24  4:10   ` Ian Kent

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®