Bug 69571 - size overflow detected in function set_flexbg_block_bitmap
Summary: size overflow detected in function set_flexbg_block_bitmap
Status: NEW
Alias: None
Product: File System
Classification: Unclassified
Component: ext4 (show other bugs)
Hardware: x86-64 Linux
: P1 normal
Assignee: fs_ext4@kernel-bugs.osdl.org
URL:
Keywords:
Depends on:
Blocks:
 
Reported: 2014-01-28 11:27 UTC by bugzilla-kernel-org
Modified: 2016-03-23 18:11 UTC (History)
2 users (show)

See Also:
Kernel Version: 3.12.8 with grsecurity
Subsystem:
Regression: No
Bisected commit-id:


Attachments

Description bugzilla-kernel-org 2014-01-28 11:27:49 UTC
egid:0/0
[79925.398626] EXT4-fs (dm-4): resizing filesystem from 6553600 to 9175040 blocks
[79925.404744] PAX: size overflow detected in function set_flexbg_block_bitmap fs/ext4/resize.c:387 cicus.712_125 min, count: 22
[79925.404749] CPU: 1 PID: 20220 Comm: resize2fs Tainted: P         C O 3.12.8-grsec #2
[79925.404751] Hardware name: LENOVO 20184/INVALID, BIOS 5ECN92WW(V8.04) 09/14/2012
[79925.404753]  0000000000000008 ffff88013a28d918 ffffffff81524777 ffff88033f24efa8
[79925.404757]  ffffffffffffffff ffff88013a28d928 ffffffff8119b7a4 ffff88013a28d9c8
[79925.404760]  ffffffffa0335d51 0000000000000000 ffff88031eed2198 ffffffff00640000
[79925.404763] Call Trace:
[79925.404771]  [<ffffffff81524777>] dump_stack+0x46/0x58
[79925.404776]  [<ffffffff8119b7a4>] report_size_overflow+0x24/0x30
[79925.404802]  [<ffffffffa0335d51>] set_flexbg_block_bitmap+0x351/0x3b0 [ext4]
[79925.404814]  [<ffffffffa0336c71>] setup_new_flex_group_blocks+0x761/0x840 [ext4]
[79925.404818]  [<ffffffff811cb120>] ? do_thaw_one+0x80/0x80
[79925.404828]  [<ffffffffa0336dfc>] ext4_flex_group_add+0xac/0x12b0 [ext4]
[79925.404833]  [<ffffffff81086be9>] ? wake_up_bit+0x29/0x40
[79925.404836]  [<ffffffff811b30e2>] ? unlock_new_inode+0x42/0x70
[79925.404840]  [<ffffffff8117d16e>] ? __kmalloc+0x1ce/0x200
[79925.404850]  [<ffffffffa033806e>] ? alloc_flex_gd+0x6e/0xa0 [ext4]
[79925.404860]  [<ffffffffa0309e2d>] ? ext4_bg_num_gdb+0x7d/0x90 [ext4]
[79925.404870]  [<ffffffffa0339412>] ext4_resize_fs+0xa02/0x1250 [ext4]
[79925.404874]  [<ffffffff811a75fc>] ? do_last+0x60c/0x1020
[79925.404878]  [<ffffffff811b8572>] ? __mnt_want_write+0x42/0x60
[79925.404888]  [<ffffffffa031a682>] ext4_ioctl+0xe72/0x1340 [ext4]
[79925.404892]  [<ffffffff81090cae>] ? __wake_up+0x4e/0x70
[79925.404895]  [<ffffffff811a8d2e>] ? do_filp_open+0x3e/0xa0
[79925.404898]  [<ffffffff811aade7>] do_vfs_ioctl+0x97/0x750
[79925.404901]  [<ffffffff811a35c1>] ? final_putname+0x21/0x50
[79925.404904]  [<ffffffff811a37b4>] ? putname+0x24/0x40
[79925.404907]  [<ffffffff811ab531>] SyS_ioctl+0x91/0xb0
[79925.404922]  [<ffffffff81531ab5>] system_call_fastpath+0x16/0x1b
[80096.811231] ------------[ cut here ]------------
[80096.811243] WARNING: CPU: 7 PID: 20351 at fs/namespace.c:890 mntput_no_expire+0xf9/0x130()
[80096.811245] Modules linked in: pci_stub vboxpci(O) vboxnetadp(O) vboxnetflt(O) vboxdrv(O) tun ip6table_filter ip6_tables xt_REDIRECT xt_owner xt_tcpudp xt_state xt_mark iptable_nat nf_conntrack_ipv4 nf_defrag_ipv4 nf_nat_ipv4 nf_nat nf_conntrack nfnetlink_queue nfnetlink xt_NFQUEUE fuse btrfs raid6_pq xor ufs qnx4 hfsplus hfs minix ntfs vfat msdos fat jfs xfs libcrc32c reiserfs michael_mic arc4 ecb lib80211_crypt_tkip wl(PO) lib80211 ppp_deflate bsd_comp ppp_async crc_ccitt ppp_generic slhc option usb_wwan usbserial usb_storage hid_generic hidp hid xt_multiport iptable_filter ip_tables x_tables parport_pc ppdev lp parport rfcomm bnep binfmt_misc nfsd auth_rpcgss oid_registry nfs_acl nfs lockd fscache sunrpc loop joydev uvcvideo videobuf2_vmalloc videobuf2_memops videobuf2_core videodev media snd_hda_codec_hdmi snd_hda_codec_conexant rts5139(C) btusb bluetooth snd_hda_intel snd_hda_codec snd_hwdep i915 snd_pcm psmouse snd_page_alloc x86_pkg_temp_thermal intel_powerclamp drm_kms_helper snd_seq mei_me drm i2c_i801 i2c_algo_bit coretemp kvm_intel kvm iTCO_wdt iTCO_vendor_support snd_seq_device ideapad_laptop lpc_ich snd_timer mei snd ehci_pci mfd_core evdev i2c_core pcspkr sparse_keymap ac processor battery serio_raw soundcore ehci_hcd rfkill button video ext4 crc16 mbcache jbd2 dm_crypt dm_mod sg sr_mod sd_mod cdrom crc_t10dif crct10dif_pclmul crct10dif_common crc32_pclmul crc32c_intel ghash_clmulni_intel ahci libahci libata thermal thermal_sys aesni_intel aes_x86_64 glue_helper ablk_helper scsi_mod alx mdio xhci_hcd usbcore usb_common [last unloaded: bcma]
[80096.811387] CPU: 7 PID: 20351 Comm: umount Tainted: P         C O 3.12.8-grsec #2
[80096.811390] Hardware name: LENOVO 20184/INVALID, BIOS 5ECN92WW(V8.04) 09/14/2012
[80096.811392]  0000000000000009 ffff88032d7b1e38 ffffffff81524777 0000000000000007
[80096.811397]  0000000000000000 ffff88032d7b1e78 ffffffff8105fdf7 ffff88032d7b1e68
[80096.811401]  ffff88032dcb2ec0 ffff88032d331800 ffff88032dcb2ee0 ffff88032dcb2ec0
[80096.811406] Call Trace:
[80096.811415]  [<ffffffff81524777>] dump_stack+0x46/0x58
[80096.811420]  [<ffffffff8105fdf7>] warn_slowpath_common+0x87/0xb0
[80096.811424]  [<ffffffff8105fe35>] warn_slowpath_null+0x15/0x20
[80096.811429]  [<ffffffff811b8199>] mntput_no_expire+0xf9/0x130
[80096.811433]  [<ffffffff811b91a7>] SyS_umount+0x97/0x3b0
[80096.811438]  [<ffffffff81531ab5>] system_call_fastpath+0x16/0x1b
[80096.811440] ---[ end trace a951a5e0bfdd5872 ]---
[80125.276277] INFO: task jbd2/dm-4-8:1722 blocked for more than 120 seconds.
[80125.276285]       Tainted: P        WC O 3.12.8-grsec #2
[80125.276286] "echo 0 > /proc/sys/kernel/hung_task_timeout_secs" disables this message.
[80125.276288] jbd2/dm-4-8     D ffff88033f291040     0  1722      2 0x00000000
[80125.276294]  ffff88032ee25c48 0000000000000046 ffff88032ea9ebf0 ffff88032ea9f0a0
[80125.276298]  ffff88032ea9f0a0 ffff88032ea9f0a0 ffff88032f92a100 ffff88032ea9ebf0
[80125.276302]  0000000200000001 ffff88032ee25d88 ffff88032adef0b8 ffff88032ea9ebf0
[80125.276306] Call Trace:
[80125.276316]  [<ffffffff81528f04>] schedule+0x24/0x70
[80125.276354]  [<ffffffffa02d4499>] jbd2_journal_commit_transaction+0x299/0x1bc0 [jbd2]
[80125.276360]  [<ffffffff8101a549>] ? sched_clock+0x9/0x10
[80125.276366]  [<ffffffff810115df>] ? __switch_to+0x18f/0x500
[80125.276371]  [<ffffffff81086c00>] ? wake_up_bit+0x40/0x40
[80125.276375]  [<ffffffff8106dac3>] ? lock_timer_base.isra.35+0x33/0x60
[80125.276379]  [<ffffffff8106ea7a>] ? try_to_del_timer_sync+0x4a/0x60
[80125.276391]  [<ffffffffa02dae43>] kjournald2+0xc3/0x270 [jbd2]
[80125.276394]  [<ffffffff81086c00>] ? wake_up_bit+0x40/0x40
[80125.276406]  [<ffffffffa02dad80>] ? jbd2_journal_clear_err+0x50/0x50 [jbd2]
[80125.276410]  [<ffffffff810864fb>] kthread+0xbb/0xc0
[80125.276413]  [<ffffffff81086440>] ? flush_kthread_worker+0x70/0x70
[80125.276418]  [<ffffffff81531a04>] ret_from_fork+0x74/0xa0
[80125.276421]  [<ffffffff81086440>] ? flush_kthread_worker+0x70/0x70

Note You need to log in before you can comment on or make changes to this bug.