Skip to content

Commit 570b9d9

Browse files
committed
dm table: fix upgrade mode race
upgrade_mode() sets bdev to NULL temporarily, and does not have any locking to exclude anything from seeing that NULL. In dm_table_any_congested() bdev_get_queue() can dereference that NULL and cause a reported oops. Fix this by not changing that field during the mode upgrade. Cc: [email protected] Cc: Neil Brown <[email protected]> Signed-off-by: Alasdair G Kergon <[email protected]>
1 parent aea9058 commit 570b9d9

File tree

1 file changed

+14
-12
lines changed

1 file changed

+14
-12
lines changed

drivers/md/dm-table.c

Lines changed: 14 additions & 12 deletions
Original file line numberDiff line numberDiff line change
@@ -399,28 +399,30 @@ static int check_device_area(struct dm_dev_internal *dd, sector_t start,
399399
}
400400

401401
/*
402-
* This upgrades the mode on an already open dm_dev. Being
402+
* This upgrades the mode on an already open dm_dev, being
403403
* careful to leave things as they were if we fail to reopen the
404-
* device.
404+
* device and not to touch the existing bdev field in case
405+
* it is accessed concurrently inside dm_table_any_congested().
405406
*/
406407
static int upgrade_mode(struct dm_dev_internal *dd, fmode_t new_mode,
407408
struct mapped_device *md)
408409
{
409410
int r;
410-
struct dm_dev_internal dd_copy;
411-
dev_t dev = dd->dm_dev.bdev->bd_dev;
411+
struct dm_dev_internal dd_new, dd_old;
412412

413-
dd_copy = *dd;
413+
dd_new = dd_old = *dd;
414+
415+
dd_new.dm_dev.mode |= new_mode;
416+
dd_new.dm_dev.bdev = NULL;
417+
418+
r = open_dev(&dd_new, dd->dm_dev.bdev->bd_dev, md);
419+
if (r)
420+
return r;
414421

415422
dd->dm_dev.mode |= new_mode;
416-
dd->dm_dev.bdev = NULL;
417-
r = open_dev(dd, dev, md);
418-
if (!r)
419-
close_dev(&dd_copy, md);
420-
else
421-
*dd = dd_copy;
423+
close_dev(&dd_old, md);
422424

423-
return r;
425+
return 0;
424426
}
425427

426428
/*

0 commit comments

Comments
 (0)