This is an automated email from the git hooks/post-receive script. It was
generated because a ref change was pushed to the repository containing
the project "Hurd".

The branch, master has been updated
       via  03333cabcf9a39624f7fe4e6ffe9b854e95008a7 (commit)
      from  a1520349d38e9b7449454345e19f3e58c203b9e6 (commit)

Those revisions listed above that are new to this repository have
not appeared on any other notification email; so we list those
revisions in full, below.

- Log -----------------------------------------------------------------
commit 03333cabcf9a39624f7fe4e6ffe9b854e95008a7
Author: Milos Nikic <[email protected]>
Date:   Mon Oct 5 15:34:26 2026 -0700

    ext2fs: Do not crash when poking a page that cannot be written
    
    Before a truncate, force_delayed_copies maps the file and writes every
    page past the new size, so that delayed copies of the data are made
    before it is discarded.  When the write fault on such a page fails, for
    instance because an earlier pager_unlock_page for it found no free
    block, libpager answers the fault with memory_object_data_error and the
    kernel raises a memory exception in ext2fs itself.  diskfs_catch_exception
    only covers faults on the disk image, so the exception kills the
    translator.  Filling the filesystem and truncating a file whose writes
    failed is enough to crash it, with or without a journal.
    
    Poke each page with hurd_safe_copyin and hurd_safe_copyout, which catch
    the fault, and skip a page that faults.  The page lies past the new size
    and is discarded anyway.  A delayed copy of such a page is then not
    forced, so a holder of that copy can see it as zeros; the page could not
    be written in the first place.
    
    To reproduce:
    - fill an ext2 filesystem until writes fail with ENOSPC,
      then truncate one of the files whose writes failed;
      the ext2fs translator dies with SIGBUS in poke_pages,
      with or without a journal.
    
    With this fix fsck remains clean in such a case with or
    without a journal.
    Message-ID: <[email protected]>

-----------------------------------------------------------------------

Summary of changes:
 ext2fs/truncate.c | 13 ++++++++++++-
 1 file changed, 12 insertions(+), 1 deletion(-)


hooks/post-receive
-- 
Hurd

Reply via email to