From patchwork Wed Apr 7 13:51:46 2010 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Subject: ext4: BUG_ON could be triggered in ext4_mb_normalize_request() Date: Wed, 07 Apr 2010 03:51:46 -0000 From: jing zhang X-Patchwork-Id: 49607 Message-Id: To: linux-ext4 Cc: "Theodore Ts'o" , Andreas Dilger , Dave Kleikamp , "Aneesh Kumar K. V" From: Jing Zhang Date: Wed Apr 7 21:34:48 2010 BUG_ON at [line: 2912] could be triggered, if (pa->pa_deleted == 0 && pa->pa_free == 0) as checked at [line: 3111] and [line: 3122]. It is bypassed by adding check for pa_free. Cc: Theodore Ts'o Cc: Andreas Dilger Cc: Dave Kleikamp Cc: Aneesh Kumar K. V Signed-off-by: Jing Zhang --- -- To unsubscribe from this list: send the line "unsubscribe linux-ext4" in the body of a message to majordomo@vger.kernel.org More majordomo info at http://vger.kernel.org/majordomo-info.html --- linux-2.6.32/fs/ext4/mballoc.c 2009-12-03 11:51:22.000000000 +0800 +++ ext4_mm_leak/mballoc-16.c 2010-04-07 20:20:26.000000000 +0800 @@ -2901,7 +2901,7 @@ ext4_mb_normalize_request(struct ext4_al if (pa->pa_deleted) continue; spin_lock(&pa->pa_lock); - if (pa->pa_deleted) { + if (pa->pa_deleted || 0 == pa->pa_free) { spin_unlock(&pa->pa_lock); continue; }