This is a note to let you know that I've just added the patch titled xfs: handle racy AIO in xfs_reflink_end_cow to the 4.9-stable tree which can be found at: http://www.kernel.org/git/?p=linux/kernel/git/stable/stable-queue.git;a=summary The filename of the patch is: xfs-handle-racy-aio-in-xfs_reflink_end_cow.patch and it can be found in the queue-4.9 subdirectory. If you, or anyone else, feels it should not be added to the stable tree, please let <stable@xxxxxxxxxxxxxxx> know about it. >From e12199f85d0ad1b04ce6c425ad93cd847fe930bb Mon Sep 17 00:00:00 2001 From: Christoph Hellwig <hch@xxxxxx> Date: Tue, 3 Oct 2017 08:58:33 -0700 Subject: xfs: handle racy AIO in xfs_reflink_end_cow From: Christoph Hellwig <hch@xxxxxx> commit e12199f85d0ad1b04ce6c425ad93cd847fe930bb upstream. If we got two AIO writes into a COW area the second one might not have any COW extents left to convert. Handle that case gracefully instead of triggering an assert or accessing beyond the bounds of the extent list. Signed-off-by: Christoph Hellwig <hch@xxxxxx> Reviewed-by: Darrick J. Wong <darrick.wong@xxxxxxxxxx> Signed-off-by: Darrick J. Wong <darrick.wong@xxxxxxxxxx> Signed-off-by: Greg Kroah-Hartman <gregkh@xxxxxxxxxxxxxxxxxxx> --- fs/xfs/xfs_reflink.c | 9 ++++++++- 1 file changed, 8 insertions(+), 1 deletion(-) --- a/fs/xfs/xfs_reflink.c +++ b/fs/xfs/xfs_reflink.c @@ -767,7 +767,13 @@ xfs_reflink_end_cow( /* If there is a hole at end_fsb - 1 go to the previous extent */ if (eof || got.br_startoff > end_fsb) { - ASSERT(idx > 0); + /* + * In case of racing, overlapping AIO writes no COW extents + * might be left by the time I/O completes for the loser of + * the race. In that case we are done. + */ + if (idx <= 0) + goto out_cancel; xfs_bmbt_get_all(xfs_iext_get_ext(ifp, --idx), &got); } @@ -841,6 +847,7 @@ next_extent: out_defer: xfs_defer_cancel(&dfops); +out_cancel: xfs_trans_cancel(tp); xfs_iunlock(ip, XFS_ILOCK_EXCL); out: Patches currently in stable-queue which might be from hch@xxxxxx are queue-4.9/xfs-don-t-unconditionally-clear-the-reflink-flag-on-zero-block-files.patch queue-4.9/xfs-report-zeroed-or-not-correctly-in-xfs_zero_range.patch queue-4.9/xfs-handle-error-if-xfs_btree_get_bufs-fails.patch queue-4.9/xfs-update-i_size-after-unwritten-conversion-in-dio-completion.patch queue-4.9/xfs-handle-racy-aio-in-xfs_reflink_end_cow.patch queue-4.9/xfs-evict-cow-fork-extents-when-performing-finsert-fcollapse.patch queue-4.9/fs-xfs-use-ps-printk-format-for-direct-addresses.patch queue-4.9/xfs-always-swap-the-cow-forks-when-swapping-extents.patch