-
Bug
-
Resolution: Fixed
-
Medium
-
None
-
None
-
3
-
9223372036854775807
there is calltrace occurred:
116376.572163] Lustre: 1079606:0:(llog_cat.c:822:llog_cat_process_common()) global-MDD0002: can't find llog handle [0x1:0x68c0a:0x0]: rc = -5 [116376.574785] BUG: unable to handle kernel NULL pointer dereference at 0000000000000070 [116376.576509] PGD 1f344f5067 P4D 0 [116376.577384] Oops: 0000 [#1] SMP NOPTI [116376.578308] CPU: 5 PID: 1079606 Comm: lctl Kdump: loaded Tainted: G OE -------- - - 4.18.0-553.71.1.el8_lustre.ddn17.x86_64 #1 [116376.580692] Hardware name: DDN SFA400NVX2E, BIOS 1.16.3-20250723_202142-72a82f624f3c 04/01/2014 [116376.582523] RIP: 0010:llog_size+0xd/0xd0 [obdclass] [116376.583728] Code: Unable to access opcode bytes at RIP 0xffffffffc111aff3. [116376.585200] RSP: 0018:ff6269c02af9fb28 EFLAGS: 00010286 [116376.586404] RAX: 00000000fffffffb RBX: 0000000000000000 RCX: ffffffffc120e730 [116376.587925] RDX: 00000000fffffffb RSI: 0000000000000000 RDI: ff6269c02af9fdf8 [116376.589475] RBP: ff21844145783a00 R08: 0000000000000000 R09: c0000000ffff7fff [116376.591014] R10: 0000000000000001 R11: ff6269c02af9f830 R12: ff2184536aa50640 [116376.592547] R13: ff6269c02af9fd98 R14: 000000000000151a R15: ff2184414571c000 [116376.594078] FS: 00007fe2cdd92740(0000) GS:ff21846271740000(0000) knlGS:0000000000000000 [116376.595777] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [116376.597075] CR2: ffffffffc111aff3 CR3: 0000001e9bdd0001 CR4: 0000000000771ee0 [116376.598602] DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000 [116376.600119] DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400 [116376.601619] PKRU: 55555554 [116376.602387] Call Trace: [116376.603112] ? __die_body+0x1a/0x60 [116376.604001] ? no_context+0x1ba/0x3f0 [116376.604928] ? __bad_area_nosemaphore+0x157/0x180 [116376.606014] ? do_page_fault+0x37/0x12d [116376.606953] ? page_fault+0x1e/0x30 [116376.607833] ? llog_size+0xd/0xd0 [obdclass] [116376.608914] ? llog_cat_process_common+0x15a/0x3b0 [obdclass] [116376.610235] llog_cat_size_cb+0x78/0x200 [obdclass] [116376.611410] llog_process_thread+0xd81/0x1aa0 [obdclass] [116376.612657] ? llog_process_or_fork+0x5e/0x4e0 [obdclass] [116376.614171] ? kmem_cache_alloc_trace+0x142/0x280 [116376.615226] ? llog_cat_process_cb+0x2e0/0x2e0 [obdclass] [116376.616461] llog_process_or_fork+0x1c7/0x4e0 [obdclass] [116376.617692] llog_cat_process_or_fork+0x125/0x400 [obdclass] [116376.618986] ? llog_size+0x31/0xd0 [obdclass] [116376.620054] llog_cat_size+0x4a/0x70 [obdclass] [116376.621159] mdd_changelog_size_ctxt+0x70/0x2a0 [mdd] [116376.622316] changelog_size_show+0x79/0xc0 [mdd] [116376.623403] sysfs_kf_seq_show+0x9b/0x110 [116376.624356] seq_read+0x163/0x420 [116376.625180] vfs_read+0x91/0x150 [116376.625991] ksys_read+0x4f/0xb0 [116376.626797] do_syscall_64+0x5b/0x1a0 [116376.627670] entry_SYSCALL_64_after_hwframe+0x66/0xcb
it reveals bug in llog_cat_size_cb():
rc = llog_cat_process_common(env, cat_llh, rec, &llh);
# if it returns rc, then llh is NULL, but below:
if (rc == LLOG_DEL_PLAIN) {
/* empty log was deleted, don't count it */
rc = llog_cat_cleanup(env, cat_llh, llh,
llh->u.phd.phd_cookie.lgc_index);
} else if (rc == LLOG_DEL_RECORD) {
/* clear wrong catalog entry */
rc = llog_cat_cleanup(env, cat_llh, NULL, rec->lrh_index);
} else { <--- this is a bug, rc still should be checked to be 0 here
size = llog_size(env, llh);
*cum_size += size; CDEBUG(D_INFO, "Add llog entry "DFID" size=%llu, tot=%llu\n",
PLOGID(&llh->lgh_id), size, *cum_size);
}