linux-mm.kvack.org archive mirror
 help / color / mirror / Atom feed
* [PATCH]  incorrect error handling inside generic_file_direct_write
@ 2006-12-11 13:34 Dmitriy Monakhov
  2006-12-11 12:38 ` [Devel] " Kirill Korotaev
  2006-12-11 20:40 ` Andrew Morton
  0 siblings, 2 replies; 14+ messages in thread
From: Dmitriy Monakhov @ 2006-12-11 13:34 UTC (permalink / raw)
  To: linux-kernel; +Cc: Linux Memory Management, devel

[-- Attachment #1: Type: text/plain, Size: 1260 bytes --]

OpenVZ team has discovered error inside generic_file_direct_write()
If generic_file_direct_IO() has fail (ENOSPC condition) it may have instantiated
a few blocks outside i_size. And fsck will complain about wrong i_size
(ext2, ext3 and reiserfs interpret i_size and biggest block difference as error),
after fsck will fix error i_size will be increased to the biggest block,
but this blocks contain gurbage from previous write attempt, this is not 
information leak, but its silence file data corruption. 
We need truncate any block beyond i_size after write have failed , do in simular
generic_file_buffered_write() error path.

Exampe:
open("mnt2/FILE3", O_WRONLY|O_CREAT|O_DIRECT, 0666) = 3
write(3, "aaaaaa"..., 4096) = -1 ENOSPC (No space left on device)

stat mnt2/FILE3
File: `mnt2/FILE3'
Size: 0               Blocks: 4          IO Block: 4096   regular empty file
>>>>>>>>>>>>>>>>>>>>>>^^^^^^^^^^ file size is less than biggest block idx
Device: 700h/1792d      Inode: 14          Links: 1
Access: (0644/-rw-r--r--)  Uid: (    0/    root)   Gid: (    0/    root)

fsck.ext2 -f -n  mnt1/fs_img
Pass 1: Checking inodes, blocks, and sizes
Inode 14, i_size is 0, should be 2048.  Fix? no

Signed-off-by: Dmitriy Monakhov <dmonakhov@openvz.org>
----------

[-- Attachment #2: diff-ms-dio_write-fix.2.6.19 --]
[-- Type: text/plain, Size: 482 bytes --]

diff --git a/mm/filemap.c b/mm/filemap.c
index 7b84dc8..bf7cf6c 100644
--- a/mm/filemap.c
+++ b/mm/filemap.c
@@ -2041,6 +2041,14 @@ generic_file_direct_write(struct kiocb *
 			mark_inode_dirty(inode);
 		}
 		*ppos = end;
+	} else if (written < 0) {
+		loff_t isize = i_size_read(inode);
+		/*
+		 * generic_file_direct_IO() may have instantiated a few blocks
+		 * outside i_size.  Trim these off again.
+		 */
+		if (pos + count > isize)
+			vmtruncate(inode, isize);
 	}
 
 	/*

^ permalink raw reply	[flat|nested] 14+ messages in thread

end of thread, other threads:[~2007-01-02 11:17 UTC | newest]

Thread overview: 14+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2006-12-11 13:34 [PATCH] incorrect error handling inside generic_file_direct_write Dmitriy Monakhov
2006-12-11 12:38 ` [Devel] " Kirill Korotaev
2006-12-11 20:40 ` Andrew Morton
2006-12-12  9:22   ` Dmitriy Monakhov
2006-12-12  6:36     ` Andrew Morton
2006-12-12 12:20   ` Dmitriy Monakhov
2006-12-12  9:52     ` Andrew Morton
2006-12-12 13:18       ` Dmitriy Monakhov
2006-12-12 10:40         ` Andrew Morton
2006-12-12 23:14           ` Dmitriy Monakhov
2006-12-13  2:43           ` Chen, Kenneth W
2006-12-15 10:43             ` 'Christoph Hellwig'
2006-12-15 18:53               ` Chen, Kenneth W
2007-01-02 11:17                 ` 'Christoph Hellwig'

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox