All of lore.kernel.org
 help / color / mirror / Atom feed
From: David Howells <dhowells@redhat.com>
To: Christian Brauner <christian@brauner.io>,
	Matthew Wilcox <willy@infradead.org>,
	Christoph Hellwig <hch@infradead.org>
Cc: David Howells <dhowells@redhat.com>,
	Paulo Alcantara <pc@manguebit.org>, Jens Axboe <axboe@kernel.dk>,
	Leon Romanovsky <leon@kernel.org>,
	Steve French <sfrench@samba.org>,
	ChenXiaoSong <chenxiaosong@chenxiaosong.com>,
	Marc Dionne <marc.dionne@auristor.com>,
	Stefan Metzmacher <metze@samba.org>,
	Eric Van Hensbergen <ericvh@kernel.org>,
	Dominique Martinet <asmadeus@codewreck.org>,
	Ilya Dryomov <idryomov@gmail.com>,
	netfs@lists.linux.dev, linux-afs@lists.infradead.org,
	linux-cifs@vger.kernel.org, linux-nfs@vger.kernel.org,
	ceph-devel@vger.kernel.org, v9fs@lists.linux.dev,
	linux-erofs@lists.ozlabs.org, linux-fsdevel@vger.kernel.org,
	linux-kernel@vger.kernel.org, stable@vger.kernel.org
Subject: [PATCH v7 06/29] afs: Fix double-unmap of directory block
Date: Wed, 22 Jul 2026 14:01:53 +0100	[thread overview]
Message-ID: <20260722130218.78958-7-dhowells@redhat.com> (raw)
In-Reply-To: <20260722130218.78958-1-dhowells@redhat.com>

Fix afs_edit_dir_remove() to use a cleanup function to unmap the block
pointed to by afs_dir_iter::block if it's left pointing to something rather
than manually kunmapping the blocks.  Manually kunmapping without clearing
iter.blocks can result in a double-kunmap if afs_dir_find_block() is called
twice in a row (which would be the case if the block being modified is not
first in the hash chain).

Fixes: a5b5beebcf96 ("afs: Use the contained hashtable to search a directory")
Closes: https://sashiko.dev/#/patchset/20260716103030.3065561-1-dhowells%40redhat.com
Signed-off-by: David Howells <dhowells@redhat.com>
cc: Marc Dionne <marc.dionne@auristor.com>
cc: linux-afs@lists.infradead.org
cc: linux-fsdevel@vger.kernel.org
cc: stable@vger.kernel.org
---
 fs/afs/dir_edit.c   |  9 ++-------
 fs/afs/dir_search.c | 10 ++--------
 fs/afs/internal.h   |  8 ++++++++
 3 files changed, 12 insertions(+), 15 deletions(-)

diff --git a/fs/afs/dir_edit.c b/fs/afs/dir_edit.c
index 3ead36a07048..c31303059444 100644
--- a/fs/afs/dir_edit.c
+++ b/fs/afs/dir_edit.c
@@ -442,7 +442,7 @@ void afs_edit_dir_remove(struct afs_vnode *vnode,
 	/* Check and clear the entry. */
 	de = &block->dirents[slot];
 	if (de->u.valid != 1)
-		goto error_unmap;
+		goto error;
 
 	trace_afs_edit_dir(vnode, why, afs_edit_dir_delete, b, slot,
 			   ntohl(de->u.vnode), ntohl(de->u.unique),
@@ -458,7 +458,6 @@ void afs_edit_dir_remove(struct afs_vnode *vnode,
 	/* Clear the constituent entries. */
 	next = de->u.hash_next;
 	memset(de, 0, sizeof(*de) * iter.nr_slots);
-	kunmap_local(block);
 
 	/* Adjust the hash chain: if iter->prev_entry is 0, the hashtable head
 	 * index is previous; otherwise it's slot number of the previous entry.
@@ -485,7 +484,6 @@ void afs_edit_dir_remove(struct afs_vnode *vnode,
 		pde = &pblock->dirents[ps];
 		prev_next = pde->u.hash_next;
 		if (prev_next != htons(entry)) {
-			kunmap_local(pblock);
 			pr_warn("%llx:%llx:%x: not prev in chain b=%x p=%x,%x e=%x %*s",
 				vnode->fid.vid, vnode->fid.vnode, vnode->fid.unique,
 				iter.bucket, iter.prev_entry, prev_next, entry,
@@ -493,7 +491,6 @@ void afs_edit_dir_remove(struct afs_vnode *vnode,
 			goto error;
 		}
 		pde->u.hash_next = next;
-		kunmap_local(pblock);
 	}
 
 	netfs_single_mark_inode_dirty(&vnode->netfs.inode);
@@ -503,18 +500,16 @@ void afs_edit_dir_remove(struct afs_vnode *vnode,
 	_debug("Remove %s from %u[%u]", name->name, b, slot);
 
 out_unmap:
+	afs_dir_end_iter(&iter);
 	kunmap_local(meta);
 	_leave("");
 	return;
 
 already_invalidated:
-	kunmap_local(block);
 	trace_afs_edit_dir(vnode, why, afs_edit_dir_delete_inval,
 			   0, 0, 0, 0, name->name);
 	goto out_unmap;
 
-error_unmap:
-	kunmap_local(block);
 error:
 	trace_afs_edit_dir(vnode, why, afs_edit_dir_delete_error,
 			   0, 0, 0, 0, name->name);
diff --git a/fs/afs/dir_search.c b/fs/afs/dir_search.c
index 4977ad81fa82..11ebdfffcb1d 100644
--- a/fs/afs/dir_search.c
+++ b/fs/afs/dir_search.c
@@ -75,10 +75,7 @@ union afs_xdr_dir_block *afs_dir_find_block(struct afs_dir_iter *iter, size_t bl
 
 	_enter("%zx,%d", block, slot);
 
-	if (iter->block) {
-		kunmap_local(iter->block);
-		iter->block = NULL;
-	}
+	afs_dir_end_iter(iter);
 
 	if (dvnode->directory_size < blend)
 		goto fail;
@@ -174,10 +171,7 @@ int afs_dir_search_bucket(struct afs_dir_iter *iter, const struct qstr *name,
 	ret = -ENOENT;
 found:
 bad:
-	if (iter->block) {
-		kunmap_local(iter->block);
-		iter->block = NULL;
-	}
+	afs_dir_end_iter(iter);
 	if (ret == -ESTALE)
 		afs_invalidate_dir(iter->dvnode, afs_dir_invalid_iter_stale);
 	_leave(" = %d", ret);
diff --git a/fs/afs/internal.h b/fs/afs/internal.h
index 601f01e5c15f..1cff417c5ed1 100644
--- a/fs/afs/internal.h
+++ b/fs/afs/internal.h
@@ -1133,6 +1133,14 @@ int afs_dir_search_bucket(struct afs_dir_iter *iter, const struct qstr *name,
 int afs_dir_search(struct afs_vnode *dvnode, const struct qstr *name,
 		   struct afs_fid *_fid, afs_dataversion_t *_dir_version);
 
+static inline void afs_dir_end_iter(struct afs_dir_iter *iter)
+{
+	if (iter->block) {
+		kunmap_local(iter->block);
+		iter->block = NULL;
+	}
+}
+
 /*
  * dir_silly.c
  */


  parent reply	other threads:[~2026-07-22 13:03 UTC|newest]

Thread overview: 30+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-07-22 13:01 [PATCH v7 00/29] netfs: Keep track of folios in a segmented bio_vec[] chain David Howells
2026-07-22 13:01 ` [PATCH v7 01/29] netfs: clear PG_private_2 on copy-to-cache append failure David Howells
2026-07-22 13:01 ` [PATCH v7 02/29] netfs: handle single writeback rolling buffer allocation failure David Howells
2026-07-22 13:01 ` [PATCH v7 03/29] netfs: release readahead folios on iterator preparation failure David Howells
2026-07-22 13:01 ` [PATCH v7 04/29] afs: Fix missing kunmap in afs_dir_search_bucket() David Howells
2026-07-22 13:01 ` [PATCH v7 05/29] afs: Fix afs_edit_dir_remove() to get, not find, block 0 David Howells
2026-07-22 13:01 ` David Howells [this message]
2026-07-22 13:01 ` [PATCH v7 07/29] mm: Make readahead store folio count in readahead_control David Howells
2026-07-22 13:01 ` [PATCH v7 08/29] netfs: Bulk load the readahead-provided folios up front David Howells
2026-07-22 13:01 ` [PATCH v7 09/29] Add a function to kmap one page of a multipage bio_vec David Howells
2026-07-22 13:01 ` [PATCH v7 10/29] iov_iter: Make iov_iter_get_pages*() wrap iov_iter_extract_pages() David Howells
2026-07-22 13:01 ` [PATCH v7 11/29] iov_iter: Add a segmented queue of bio_vec[] David Howells
2026-07-22 13:01 ` [PATCH v7 12/29] netfs: Add some tools for managing bvecq chains David Howells
2026-07-22 13:02 ` [PATCH v7 13/29] netfs: Add a function to extract from an iter into a bvecq David Howells
2026-07-22 13:02 ` [PATCH v7 14/29] afs: Use a bvecq to hold dir content rather than folioq David Howells
2026-07-22 13:02 ` [PATCH v7 15/29] cifs: Use a bvecq for buffering instead of a folioq David Howells
2026-07-22 13:02 ` [PATCH v7 16/29] smbdirect: Support ITER_BVECQ in smbdirect_map_sges_from_iter() David Howells
2026-07-22 13:02 ` [PATCH v7 17/29] netfs: Remove the writethrough code David Howells
2026-07-22 13:02 ` [PATCH v7 18/29] cachefiles,netfs: sunset ondemand mode David Howells
2026-07-22 13:02 ` [PATCH v7 19/29] cachefiles: Don't rely on backing fs storage map for most use cases David Howells
2026-07-22 13:02 ` [PATCH v7 20/29] netfs: Add the cache object ID to netfs_read/write tracepoints David Howells
2026-07-22 13:02 ` [PATCH v7 21/29] netfs: Switch to using bvecq rather than folio_queue and rolling_buffer David Howells
2026-07-22 13:02 ` [PATCH v7 22/29] smbdirect: Remove support for ITER_FOLIOQ from smbdirect_map_sges_from_iter() David Howells
2026-07-22 13:02 ` [PATCH v7 23/29] netfs: Remove netfs_alloc/free_folioq_buffer() David Howells
2026-07-22 13:02 ` [PATCH v7 24/29] netfs: Remove netfs_extract_user_iter() David Howells
2026-07-22 13:02 ` [PATCH v7 25/29] iov_iter: Remove ITER_FOLIOQ David Howells
2026-07-22 13:02 ` [PATCH v7 26/29] netfs: Remove folio_queue and rolling_buffer David Howells
2026-07-22 13:02 ` [PATCH v7 27/29] netfs: Check for too much data being read David Howells
2026-07-22 13:02 ` [PATCH v7 28/29] netfs: Limit the minimum trigger for progress reporting David Howells
2026-07-22 13:02 ` [PATCH v7 29/29] netfs: Combine prepare and issue ops and grab the buffers on request David Howells

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260722130218.78958-7-dhowells@redhat.com \
    --to=dhowells@redhat.com \
    --cc=asmadeus@codewreck.org \
    --cc=axboe@kernel.dk \
    --cc=ceph-devel@vger.kernel.org \
    --cc=chenxiaosong@chenxiaosong.com \
    --cc=christian@brauner.io \
    --cc=ericvh@kernel.org \
    --cc=hch@infradead.org \
    --cc=idryomov@gmail.com \
    --cc=leon@kernel.org \
    --cc=linux-afs@lists.infradead.org \
    --cc=linux-cifs@vger.kernel.org \
    --cc=linux-erofs@lists.ozlabs.org \
    --cc=linux-fsdevel@vger.kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=linux-nfs@vger.kernel.org \
    --cc=marc.dionne@auristor.com \
    --cc=metze@samba.org \
    --cc=netfs@lists.linux.dev \
    --cc=pc@manguebit.org \
    --cc=sfrench@samba.org \
    --cc=stable@vger.kernel.org \
    --cc=v9fs@lists.linux.dev \
    --cc=willy@infradead.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.