Commit 1200e551 authored by Hyeong-Jun Kim's avatar Hyeong-Jun Kim Committed by Zizhi Wo
Browse files

f2fs: invalidate META_MAPPING before IPU/DIO write

mainline inclusion
from mainline-v5.16-rc1
commit e3b49ea3
category: bugfix
bugzilla: https://gitee.com/src-openeuler/kernel/issues/I9HKE5
CVE: CVE-2024-26869

Reference: https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?id=e3b49ea36802053f312013fd4ccb6e59920a9f76



--------------------------------

Encrypted pages during GC are read and cached in META_MAPPING.
However, due to cached pages in META_MAPPING, there is an issue where
newly written pages are lost by IPU or DIO writes.

Thread A - f2fs_gc()            Thread B
/* phase 3 */
down_write(i_gc_rwsem)
ra_data_block()       ---- (a)
up_write(i_gc_rwsem)
                                f2fs_direct_IO() :
                                 - down_read(i_gc_rwsem)
                                 - __blockdev_direct_io()
                                 - get_data_block_dio_write()
                                 - f2fs_dio_submit_bio()  ---- (b)
                                 - up_read(i_gc_rwsem)
/* phase 4 */
down_write(i_gc_rwsem)
move_data_block()     ---- (c)
up_write(i_gc_rwsem)

(a) In phase 3 of f2fs_gc(), up-to-date page is read from storage and
    cached in META_MAPPING.
(b) In thread B, writing new data by IPU or DIO write on same blkaddr as
    read in (a). cached page in META_MAPPING become out-dated.
(c) In phase 4 of f2fs_gc(), out-dated page in META_MAPPING is copied to
    new blkaddr. In conclusion, the newly written data in (b) is lost.

To address this issue, invalidating pages in META_MAPPING before IPU or
DIO write.

Fixes: 6aa58d8a ("f2fs: readahead encrypted block during GC")
Signed-off-by: default avatarHyeong-Jun Kim <hj514.kim@samsung.com>
Reviewed-by: default avatarChao Yu <chao@kernel.org>
Signed-off-by: default avatarJaegeuk Kim <jaegeuk@kernel.org>

Conflicts:
	fs/f2fs/data.c
	fs/f2fs/segment.c
Signed-off-by: default avatarZizhi Wo <wozizhi@huawei.com>
parent fca9656c
Loading
Loading
Loading
Loading
+4 −1
Original line number Diff line number Diff line
@@ -1715,9 +1715,12 @@ int f2fs_map_blocks(struct inode *inode, struct f2fs_map_blocks *map,
sync_out:

	/* for hardware encryption, but to avoid potential issue in future */
	if (flag == F2FS_GET_BLOCK_DIO && map->m_flags & F2FS_MAP_MAPPED)
	if (flag == F2FS_GET_BLOCK_DIO && map->m_flags & F2FS_MAP_MAPPED) {
		f2fs_wait_on_block_writeback_range(inode,
						map->m_pblk, map->m_len);
		invalidate_mapping_pages(META_MAPPING(sbi),
						map->m_pblk, map->m_pblk);
	}

	if (flag == F2FS_GET_BLOCK_PRECACHE) {
		if (map->m_flags & F2FS_MAP_MAPPED) {
+3 −0
Original line number Diff line number Diff line
@@ -3554,6 +3554,9 @@ int f2fs_inplace_write_data(struct f2fs_io_info *fio)
		return -EFSCORRUPTED;
	}

	invalidate_mapping_pages(META_MAPPING(sbi),
				fio->new_blkaddr, fio->new_blkaddr);

	stat_inc_inplace_blocks(fio->sbi);

	if (fio->bio && !(SM_I(sbi)->ipu_policy & (1 << F2FS_IPU_NOCACHE)))