From: Marcelo Mendes Spessoto Junior <marcelomspessoto@gmail.com>
To: Carlos Maiolino <cem@kernel.org>
Cc: linux-xfs@vger.kernel.org, linux-kernel@vger.kernel.org,
Marcelo Mendes Spessoto Junior <marcelomspessoto@gmail.com>,
syzbot+4e6ee73c0ae4b6e8753f@syzkaller.appspotmail.com
Subject: [PATCH] xfs: add guard before freeing buffer log item
Date: Fri, 31 Jul 2026 03:14:48 -0300 [thread overview]
Message-ID: <20260731061448.192010-1-marcelomspessoto@gmail.com> (raw)
A buffer's write completion can race with the CIL walking the same
checkpoint's item list during a forced shutdown's simulated commit
callbacks. Whichever side reaches the item last should be the one to
free it; right now completion frees it unconditionally, so the CIL
walk can end up touching memory that's already gone.
Fixes: d2fe5c4c8d25 ("xfs: rearrange code in xfs_buf_item.c")
Reported-by: syzbot+4e6ee73c0ae4b6e8753f@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=4e6ee73c0ae4b6e8753f
Tested-by: syzbot+4e6ee73c0ae4b6e8753f@syzkaller.appspotmail.com
Signed-off-by: Marcelo Mendes Spessoto Junior <marcelomspessoto@gmail.com>
---
fs/xfs/xfs_buf_item.c | 3 +++
1 file changed, 3 insertions(+)
diff --git a/fs/xfs/xfs_buf_item.c b/fs/xfs/xfs_buf_item.c
index f4c5be67826e..c86c4387f52b 100644
--- a/fs/xfs/xfs_buf_item.c
+++ b/fs/xfs/xfs_buf_item.c
@@ -1072,6 +1072,9 @@ void
xfs_buf_item_done(
struct xfs_buf *bp)
{
+ if (atomic_read(&bp->b_log_item->bli_refcount) != 0)
+ return;
+
/*
* If we are forcibly shutting down, this may well be off the AIL
* already. That's because we simulate the log-committed callbacks to
--
2.55.0
next reply other threads:[~2026-07-31 6:17 UTC|newest]
Thread overview: 3+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-07-31 6:14 Marcelo Mendes Spessoto Junior [this message]
2026-07-31 7:02 ` [PATCH] xfs: add guard before freeing buffer log item Marcelo Mendes
2026-07-31 23:13 ` Dave Chinner
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260731061448.192010-1-marcelomspessoto@gmail.com \
--to=marcelomspessoto@gmail.com \
--cc=cem@kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-xfs@vger.kernel.org \
--cc=syzbot+4e6ee73c0ae4b6e8753f@syzkaller.appspotmail.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.