Skip to content

Commit

Permalink
Avoid some crashes when importing a pool with corrupt metadata
Browse files Browse the repository at this point in the history
- Skip invalid DVAs when importing pools in readonly mode
  (in addition to when the config is untrusted).

- Upon encountering a DVA with a null VDEV, fail gracefully
  instead of panicking with a NULL pointer dereference.

Reviewed-by: Pavel Zakharov <[email protected]>
Reviewed-by: Brian Behlendorf <[email protected]>
Signed-off-by: Steve Mokris <[email protected]>
Closes #9022
  • Loading branch information
smokris authored and behlendorf committed Dec 26, 2019
1 parent ad353e2 commit d5c97f3
Showing 1 changed file with 11 additions and 3 deletions.
14 changes: 11 additions & 3 deletions module/zfs/vdev_mirror.c
Original file line number Diff line number Diff line change
Expand Up @@ -282,10 +282,11 @@ vdev_mirror_map_init(zio_t *zio)
}

/*
* If we do not trust the pool config, some DVAs might be
* invalid or point to vdevs that do not exist. We skip them.
* If the pool cannot be written to, then infer that some
* DVAs might be invalid or point to vdevs that do not exist.
* We skip them.
*/
if (!spa_trust_config(spa)) {
if (!spa_writeable(spa)) {
ASSERT3U(zio->io_type, ==, ZIO_TYPE_READ);
int j = 0;
for (int i = 0; i < c; i++) {
Expand All @@ -309,6 +310,13 @@ vdev_mirror_map_init(zio_t *zio)

mc->mc_vd = vdev_lookup_top(spa, DVA_GET_VDEV(&dva[c]));
mc->mc_offset = DVA_GET_OFFSET(&dva[c]);
if (mc->mc_vd == NULL) {
kmem_free(mm, vdev_mirror_map_size(
mm->mm_children));
zio->io_vsd = NULL;
zio->io_error = ENXIO;
return (NULL);
}
}
} else {
/*
Expand Down

0 comments on commit d5c97f3

Please sign in to comment.