Commit 40a9abce authored by Josef Bacik's avatar Josef Bacik Committed by Baokun Li
Browse files

btrfs: clean up our handling of refs == 0 in snapshot delete

stable inclusion
from stable-v5.10.226
commit c60676b81fab456b672796830f6d8057058f029c
category: bugfix
bugzilla: https://gitee.com/src-openeuler/kernel/issues/IAU9NE
CVE: CVE-2024-46840

Reference: https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?id=c60676b81fab456b672796830f6d8057058f029c



--------------------------------

[ Upstream commit b8ccef048354074a548f108e51d0557d6adfd3a3 ]

In reada we BUG_ON(refs == 0), which could be unkind since we aren't
holding a lock on the extent leaf and thus could get a transient
incorrect answer.  In walk_down_proc we also BUG_ON(refs == 0), which
could happen if we have extent tree corruption.  Change that to return
-EUCLEAN.  In do_walk_down() we catch this case and handle it correctly,
however we return -EIO, which -EUCLEAN is a more appropriate error code.
Finally in walk_up_proc we have the same BUG_ON(refs == 0), so convert
that to proper error handling.  Also adjust the error message so we can
actually do something with the information.

Signed-off-by: default avatarJosef Bacik <josef@toxicpanda.com>
Reviewed-by: default avatarDavid Sterba <dsterba@suse.com>
Signed-off-by: default avatarDavid Sterba <dsterba@suse.com>
Signed-off-by: default avatarSasha Levin <sashal@kernel.org>

Conflicts:
        fs/btrfs/extent-tree.c
[Context difference.]
Signed-off-by: default avatarBaokun Li <libaokun1@huawei.com>
parent 7e10ffab
Loading
Loading
Loading
Loading
+23 −5
Original line number Diff line number Diff line
@@ -4808,7 +4808,15 @@ static noinline void reada_walk_down(struct btrfs_trans_handle *trans,
		/* We don't care about errors in readahead. */
		if (ret < 0)
			continue;
		BUG_ON(refs == 0);

		/*
		 * This could be racey, it's conceivable that we raced and end
		 * up with a bogus refs count, if that's the case just skip, if
		 * we are actually corrupt we will notice when we look up
		 * everything again with our locks.
		 */
		if (refs == 0)
			continue;

		if (wc->stage == DROP_REFERENCE) {
			if (refs == 1)
@@ -4874,7 +4882,11 @@ static noinline int walk_down_proc(struct btrfs_trans_handle *trans,
					       &wc->flags[level]);
		if (ret)
			return ret;
		BUG_ON(wc->refs[level] == 0);
		if (unlikely(wc->refs[level] == 0)) {
			btrfs_err(fs_info, "bytenr %llu has 0 references, expect > 0",
				  eb->start);
			return -EUCLEAN;
		}
	}

	if (wc->stage == DROP_REFERENCE) {
@@ -5007,8 +5019,9 @@ static noinline int do_walk_down(struct btrfs_trans_handle *trans,
		goto out_unlock;

	if (unlikely(wc->refs[level - 1] == 0)) {
		btrfs_err(fs_info, "Missing references.");
		ret = -EIO;
		btrfs_err(fs_info, "bytenr %llu has 0 references, expect > 0",
			  bytenr);
		ret = -EUCLEAN;
		goto out_unlock;
	}
	*lookup_info = 0;
@@ -5210,7 +5223,12 @@ static noinline int walk_up_proc(struct btrfs_trans_handle *trans,
				path->locks[level] = 0;
				return ret;
			}
			BUG_ON(wc->refs[level] == 0);
			if (unlikely(wc->refs[level] == 0)) {
				btrfs_tree_unlock_rw(eb, path->locks[level]);
				btrfs_err(fs_info, "bytenr %llu has 0 references, expect > 0",
					  eb->start);
				return -EUCLEAN;
			}
			if (wc->refs[level] == 1) {
				btrfs_tree_unlock_rw(eb, path->locks[level]);
				path->locks[level] = 0;