Path: blob/main/website/static/security/patches/EN-15:07/zfs.patch
18096 views
Index: sys/cddl/contrib/opensolaris/uts/common/fs/zfs/arc.c1===================================================================2--- sys/cddl/contrib/opensolaris/uts/common/fs/zfs/arc.c (revision 284174)3+++ sys/cddl/contrib/opensolaris/uts/common/fs/zfs/arc.c (working copy)4@@ -344,6 +344,7 @@ typedef struct arc_stats {5kstat_named_t arcstat_l2_evict_lock_retry;6kstat_named_t arcstat_l2_evict_reading;7kstat_named_t arcstat_l2_free_on_write;8+ kstat_named_t arcstat_l2_cdata_free_on_write;9kstat_named_t arcstat_l2_abort_lowmem;10kstat_named_t arcstat_l2_cksum_bad;11kstat_named_t arcstat_l2_io_error;12@@ -421,6 +422,7 @@ static arc_stats_t arc_stats = {13{ "l2_evict_lock_retry", KSTAT_DATA_UINT64 },14{ "l2_evict_reading", KSTAT_DATA_UINT64 },15{ "l2_free_on_write", KSTAT_DATA_UINT64 },16+ { "l2_cdata_free_on_write", KSTAT_DATA_UINT64 },17{ "l2_abort_lowmem", KSTAT_DATA_UINT64 },18{ "l2_cksum_bad", KSTAT_DATA_UINT64 },19{ "l2_io_error", KSTAT_DATA_UINT64 },20@@ -1629,6 +1631,21 @@ arc_buf_add_ref(arc_buf_t *buf, void* tag)21data, metadata, hits);22}2324+static void25+arc_buf_free_on_write(void *data, size_t size,26+ void (*free_func)(void *, size_t))27+{28+ l2arc_data_free_t *df;29+30+ df = kmem_alloc(sizeof (l2arc_data_free_t), KM_SLEEP);31+ df->l2df_data = data;32+ df->l2df_size = size;33+ df->l2df_func = free_func;34+ mutex_enter(&l2arc_free_on_write_mtx);35+ list_insert_head(l2arc_free_on_write, df);36+ mutex_exit(&l2arc_free_on_write_mtx);37+}38+39/*40* Free the arc data buffer. If it is an l2arc write in progress,41* the buffer is placed on l2arc_free_on_write to be freed later.42@@ -1639,14 +1656,7 @@ arc_buf_data_free(arc_buf_t *buf, void (*free_func43arc_buf_hdr_t *hdr = buf->b_hdr;4445if (HDR_L2_WRITING(hdr)) {46- l2arc_data_free_t *df;47- df = kmem_alloc(sizeof (l2arc_data_free_t), KM_SLEEP);48- df->l2df_data = buf->b_data;49- df->l2df_size = hdr->b_size;50- df->l2df_func = free_func;51- mutex_enter(&l2arc_free_on_write_mtx);52- list_insert_head(l2arc_free_on_write, df);53- mutex_exit(&l2arc_free_on_write_mtx);54+ arc_buf_free_on_write(buf->b_data, hdr->b_size, free_func);55ARCSTAT_BUMP(arcstat_l2_free_on_write);56} else {57free_func(buf->b_data, hdr->b_size);58@@ -1658,6 +1668,23 @@ arc_buf_data_free(arc_buf_t *buf, void (*free_func59* arc_buf_t off of the the arc_buf_hdr_t's list and free it.60*/61static void62+arc_buf_l2_cdata_free(arc_buf_hdr_t *hdr)63+{64+ l2arc_buf_hdr_t *l2hdr = hdr->b_l2hdr;65+66+ ASSERT(MUTEX_HELD(&l2arc_buflist_mtx));67+68+ if (l2hdr->b_tmp_cdata == NULL)69+ return;70+71+ ASSERT(HDR_L2_WRITING(hdr));72+ arc_buf_free_on_write(l2hdr->b_tmp_cdata, hdr->b_size,73+ zio_data_buf_free);74+ ARCSTAT_BUMP(arcstat_l2_cdata_free_on_write);75+ l2hdr->b_tmp_cdata = NULL;76+}77+78+static void79arc_buf_destroy(arc_buf_t *buf, boolean_t recycle, boolean_t remove)80{81arc_buf_t **bufp;82@@ -1756,6 +1783,7 @@ arc_hdr_destroy(arc_buf_hdr_t *hdr)83trim_map_free(l2hdr->b_dev->l2ad_vdev, l2hdr->b_daddr,84hdr->b_size, 0);85list_remove(l2hdr->b_dev->l2ad_buflist, hdr);86+ arc_buf_l2_cdata_free(hdr);87ARCSTAT_INCR(arcstat_l2_size, -hdr->b_size);88ARCSTAT_INCR(arcstat_l2_asize, -l2hdr->b_asize);89vdev_space_update(l2hdr->b_dev->l2ad_vdev,90@@ -3605,6 +3633,7 @@ arc_release(arc_buf_t *buf, void *tag)91l2hdr = hdr->b_l2hdr;92if (l2hdr) {93mutex_enter(&l2arc_buflist_mtx);94+ arc_buf_l2_cdata_free(hdr);95hdr->b_l2hdr = NULL;96list_remove(l2hdr->b_dev->l2ad_buflist, hdr);97}98@@ -4895,6 +4924,11 @@ top:99ARCSTAT_INCR(arcstat_l2_asize, -abl2->b_asize);100bytes_evicted += abl2->b_asize;101ab->b_l2hdr = NULL;102+ /*103+ * We are destroying l2hdr, so ensure that104+ * its compressed buffer, if any, is not leaked.105+ */106+ ASSERT(abl2->b_tmp_cdata == NULL);107kmem_free(abl2, sizeof (l2arc_buf_hdr_t));108ARCSTAT_INCR(arcstat_l2_size, -ab->b_size);109}110@@ -5133,6 +5167,14 @@ l2arc_write_buffers(spa_t *spa, l2arc_dev_t *dev,111buf_data = l2hdr->b_tmp_cdata;112buf_sz = l2hdr->b_asize;113114+ /*115+ * If the data has not been compressed, then clear b_tmp_cdata116+ * to make sure that it points only to a temporary compression117+ * buffer.118+ */119+ if (!L2ARC_IS_VALID_COMPRESS(l2hdr->b_compress))120+ l2hdr->b_tmp_cdata = NULL;121+122/* Compression may have squashed the buffer to zero length. */123if (buf_sz != 0) {124uint64_t buf_p_sz;125@@ -5323,7 +5365,8 @@ l2arc_release_cdata_buf(arc_buf_hdr_t *ab)126{127l2arc_buf_hdr_t *l2hdr = ab->b_l2hdr;128129- if (l2hdr->b_compress == ZIO_COMPRESS_LZ4) {130+ ASSERT(L2ARC_IS_VALID_COMPRESS(l2hdr->b_compress));131+ if (l2hdr->b_compress != ZIO_COMPRESS_EMPTY) {132/*133* If the data was compressed, then we've allocated a134* temporary buffer for it, so now we need to release it.135@@ -5330,8 +5373,10 @@ l2arc_release_cdata_buf(arc_buf_hdr_t *ab)136*/137ASSERT(l2hdr->b_tmp_cdata != NULL);138zio_data_buf_free(l2hdr->b_tmp_cdata, ab->b_size);139+ l2hdr->b_tmp_cdata = NULL;140+ } else {141+ ASSERT(l2hdr->b_tmp_cdata == NULL);142}143- l2hdr->b_tmp_cdata = NULL;144}145146/*147Index: sys/cddl/contrib/opensolaris/uts/common/fs/zfs/trim_map.c148===================================================================149--- sys/cddl/contrib/opensolaris/uts/common/fs/zfs/trim_map.c (revision 284174)150+++ sys/cddl/contrib/opensolaris/uts/common/fs/zfs/trim_map.c (working copy)151@@ -155,11 +155,9 @@ trim_map_create(vdev_t *vd)152{153trim_map_t *tm;154155- ASSERT(vd->vdev_ops->vdev_op_leaf);156+ ASSERT(zfs_trim_enabled && !vd->vdev_notrim &&157+ vd->vdev_ops->vdev_op_leaf);158159- if (!zfs_trim_enabled)160- return;161-162tm = kmem_zalloc(sizeof (*tm), KM_SLEEP);163mutex_init(&tm->tm_lock, NULL, MUTEX_DEFAULT, NULL);164list_create(&tm->tm_head, sizeof (trim_seg_t),165Index: sys/cddl/contrib/opensolaris/uts/common/fs/zfs/vdev.c166===================================================================167--- sys/cddl/contrib/opensolaris/uts/common/fs/zfs/vdev.c (revision 284174)168+++ sys/cddl/contrib/opensolaris/uts/common/fs/zfs/vdev.c (working copy)169@@ -1214,6 +1214,7 @@ vdev_open(vdev_t *vd)170vd->vdev_stat.vs_aux = VDEV_AUX_NONE;171vd->vdev_cant_read = B_FALSE;172vd->vdev_cant_write = B_FALSE;173+ vd->vdev_notrim = B_FALSE;174vd->vdev_min_asize = vdev_get_min_asize(vd);175176/*177@@ -1283,10 +1284,8 @@ vdev_open(vdev_t *vd)178if (vd->vdev_ishole || vd->vdev_ops == &vdev_missing_ops)179return (0);180181- if (vd->vdev_ops->vdev_op_leaf) {182- vd->vdev_notrim = B_FALSE;183+ if (zfs_trim_enabled && !vd->vdev_notrim && vd->vdev_ops->vdev_op_leaf)184trim_map_create(vd);185- }186187for (int c = 0; c < vd->vdev_children; c++) {188if (vd->vdev_child[c]->vdev_state != VDEV_STATE_HEALTHY) {189Index: sys/cddl/contrib/opensolaris/uts/common/fs/zfs/vdev_disk.c190===================================================================191--- sys/cddl/contrib/opensolaris/uts/common/fs/zfs/vdev_disk.c (revision 284174)192+++ sys/cddl/contrib/opensolaris/uts/common/fs/zfs/vdev_disk.c (working copy)193@@ -796,6 +796,8 @@ vdev_disk_io_start(zio_t *zio)194return (ZIO_PIPELINE_STOP);195}196197+ ASSERT(zio->io_type == ZIO_TYPE_READ || zio->io_type == ZIO_TYPE_WRITE);198+199vb = kmem_alloc(sizeof (vdev_buf_t), KM_SLEEP);200201vb->vb_io = zio;202Index: sys/cddl/contrib/opensolaris/uts/common/fs/zfs/vdev_file.c203===================================================================204--- sys/cddl/contrib/opensolaris/uts/common/fs/zfs/vdev_file.c (revision 284174)205+++ sys/cddl/contrib/opensolaris/uts/common/fs/zfs/vdev_file.c (working copy)206@@ -129,6 +129,8 @@ skip_open:207return (error);208}209210+ vd->vdev_notrim = B_TRUE;211+212*max_psize = *psize = vattr.va_size;213*logical_ashift = SPA_MINBLOCKSHIFT;214*physical_ashift = SPA_MINBLOCKSHIFT;215@@ -185,6 +187,8 @@ vdev_file_io_start(zio_t *zio)216return (ZIO_PIPELINE_STOP);217}218219+ ASSERT(zio->io_type == ZIO_TYPE_READ || zio->io_type == ZIO_TYPE_WRITE);220+221zio->io_error = vn_rdwr(zio->io_type == ZIO_TYPE_READ ?222UIO_READ : UIO_WRITE, vp, zio->io_data, zio->io_size,223zio->io_offset, UIO_SYSSPACE, 0, RLIM64_INFINITY, kcred, &resid);224Index: sys/cddl/contrib/opensolaris/uts/common/fs/zfs/vdev_geom.c225===================================================================226--- sys/cddl/contrib/opensolaris/uts/common/fs/zfs/vdev_geom.c (revision 284174)227+++ sys/cddl/contrib/opensolaris/uts/common/fs/zfs/vdev_geom.c (working copy)228@@ -832,6 +832,11 @@ vdev_geom_io_start(zio_t *zio)229return (ZIO_PIPELINE_STOP);230}231sendreq:232+ ASSERT(zio->io_type == ZIO_TYPE_READ ||233+ zio->io_type == ZIO_TYPE_WRITE ||234+ zio->io_type == ZIO_TYPE_FREE ||235+ zio->io_type == ZIO_TYPE_IOCTL);236+237cp = vd->vdev_tsd;238if (cp == NULL) {239zio->io_error = SET_ERROR(ENXIO);240Index: sys/cddl/contrib/opensolaris/uts/common/fs/zfs/vdev_label.c241===================================================================242--- sys/cddl/contrib/opensolaris/uts/common/fs/zfs/vdev_label.c (revision 284174)243+++ sys/cddl/contrib/opensolaris/uts/common/fs/zfs/vdev_label.c (working copy)244@@ -713,8 +713,9 @@ vdev_label_init(vdev_t *vd, uint64_t crtxg, vdev_l245* Don't TRIM if removing so that we don't interfere with zpool246* disaster recovery.247*/248- if (zfs_trim_enabled && vdev_trim_on_init && (reason == VDEV_LABEL_CREATE ||249- reason == VDEV_LABEL_SPARE || reason == VDEV_LABEL_L2CACHE))250+ if (zfs_trim_enabled && vdev_trim_on_init && !vd->vdev_notrim &&251+ (reason == VDEV_LABEL_CREATE || reason == VDEV_LABEL_SPARE ||252+ reason == VDEV_LABEL_L2CACHE))253zio_wait(zio_trim(NULL, spa, vd, 0, vd->vdev_psize));254255/*256257258