All of lore.kernel.org
 help / color / mirror / Atom feed
* [PATCH] btrfs: fix transaction use-after-free in raid stripe insertion
@ 2026-08-17  1:27 Shuangpeng Bai
  2026-08-17  1:58 ` Qu Wenruo
  2026-08-17  2:15 ` [PATCH v2] " Shuangpeng Bai
  0 siblings, 2 replies; 6+ messages in thread
From: Shuangpeng Bai @ 2026-08-17  1:27 UTC (permalink / raw)
  To: linux-btrfs; +Cc: clm, dsterba

If allocation of a RAID stripe extent fails,
btrfs_insert_one_raid_extent() aborts and ends the transaction before
returning -ENOMEM.

btrfs_finish_one_ordered(), the production caller through
btrfs_insert_raid_extent(), still owns the transaction handle. It handles
the error by aborting the transaction and then reaches the common exit
path, which ends the transaction again.

The premature end can free the handle and drop its transaction reference.
Transaction cleanup can then free the transaction before the caller's
second abort accesses the handle and transaction, resulting in
use-after-free.

Keep the abort at the failure site, but let the caller's common exit path
end the transaction once, after it has finished using both objects.

Fixes: 02c372e1f016 ("btrfs: add support for inserting raid stripe extents")
Cc: stable@vger.kernel.org
Signed-off-by: Shuangpeng Bai <shuangpeng.kernel@gmail.com>
---
 fs/btrfs/raid-stripe-tree.c | 1 -
 1 file changed, 1 deletion(-)

diff --git a/fs/btrfs/raid-stripe-tree.c b/fs/btrfs/raid-stripe-tree.c
index b210371ce91e..89e259a47d8d 100644
--- a/fs/btrfs/raid-stripe-tree.c
+++ b/fs/btrfs/raid-stripe-tree.c
@@ -337,7 +337,6 @@ int btrfs_insert_one_raid_extent(struct btrfs_trans_handle *trans,
 	stripe_extent = kzalloc(item_size, GFP_NOFS);
 	if (unlikely(!stripe_extent)) {
 		btrfs_abort_transaction(trans, -ENOMEM);
-		btrfs_end_transaction(trans);
 		return -ENOMEM;
 	}
 
-- 
2.43.0


^ permalink raw reply related	[flat|nested] 6+ messages in thread

* Re: [PATCH] btrfs: fix transaction use-after-free in raid stripe insertion
  2026-08-17  1:27 [PATCH] btrfs: fix transaction use-after-free in raid stripe insertion Shuangpeng Bai
@ 2026-08-17  1:58 ` Qu Wenruo
  2026-08-17  2:09   ` Shuangpeng
  2026-08-17  2:15 ` [PATCH v2] " Shuangpeng Bai
  1 sibling, 1 reply; 6+ messages in thread
From: Qu Wenruo @ 2026-08-17  1:58 UTC (permalink / raw)
  To: Shuangpeng Bai, linux-btrfs; +Cc: clm, dsterba



在 2026/8/17 10:57, Shuangpeng Bai 写道:
> If allocation of a RAID stripe extent fails,
> btrfs_insert_one_raid_extent() aborts and ends the transaction before
> returning -ENOMEM.
> 
> btrfs_finish_one_ordered(), the production caller through
> btrfs_insert_raid_extent(), still owns the transaction handle. It handles
> the error by aborting the transaction and then reaches the common exit
> path, which ends the transaction again.
> 
> The premature end can free the handle and drop its transaction reference.
> Transaction cleanup can then free the transaction before the caller's
> second abort accesses the handle and transaction, resulting in
> use-after-free.
> 
> Keep the abort at the failure site, but let the caller's common exit path
> end the transaction once, after it has finished using both objects.
> 
> Fixes: 02c372e1f016 ("btrfs: add support for inserting raid stripe extents")
> Cc: stable@vger.kernel.org

Please disclose LLM usage.

> Signed-off-by: Shuangpeng Bai <shuangpeng.kernel@gmail.com>
> ---
>   fs/btrfs/raid-stripe-tree.c | 1 -
>   1 file changed, 1 deletion(-)
> 
> diff --git a/fs/btrfs/raid-stripe-tree.c b/fs/btrfs/raid-stripe-tree.c
> index b210371ce91e..89e259a47d8d 100644
> --- a/fs/btrfs/raid-stripe-tree.c
> +++ b/fs/btrfs/raid-stripe-tree.c
> @@ -337,7 +337,6 @@ int btrfs_insert_one_raid_extent(struct btrfs_trans_handle *trans,
>   	stripe_extent = kzalloc(item_size, GFP_NOFS);
>   	if (unlikely(!stripe_extent)) {
>   		btrfs_abort_transaction(trans, -ENOMEM);
> -		btrfs_end_transaction(trans);
>   		return -ENOMEM;
>   	}
>   


^ permalink raw reply	[flat|nested] 6+ messages in thread

* Re: [PATCH] btrfs: fix transaction use-after-free in raid stripe insertion
  2026-08-17  1:58 ` Qu Wenruo
@ 2026-08-17  2:09   ` Shuangpeng
  2026-08-17  2:16     ` Qu Wenruo
  0 siblings, 1 reply; 6+ messages in thread
From: Shuangpeng @ 2026-08-17  2:09 UTC (permalink / raw)
  To: Qu Wenruo; +Cc: linux-btrfs, clm, dsterba



> On Aug 16, 2026, at 21:58, Qu Wenruo <wqu@suse.com> wrote:
> 
> 
> 
> 在 2026/8/17 10:57, Shuangpeng Bai 写道:
>> If allocation of a RAID stripe extent fails,
>> btrfs_insert_one_raid_extent() aborts and ends the transaction before
>> returning -ENOMEM.
>> btrfs_finish_one_ordered(), the production caller through
>> btrfs_insert_raid_extent(), still owns the transaction handle. It handles
>> the error by aborting the transaction and then reaches the common exit
>> path, which ends the transaction again.
>> The premature end can free the handle and drop its transaction reference.
>> Transaction cleanup can then free the transaction before the caller's
>> second abort accesses the handle and transaction, resulting in
>> use-after-free.
>> Keep the abort at the failure site, but let the caller's common exit path
>> end the transaction once, after it has finished using both objects.
>> Fixes: 02c372e1f016 ("btrfs: add support for inserting raid stripe extents")
>> Cc: stable@vger.kernel.org
> 
> Please disclose LLM usage.
> 

Hi Qu,

Thanks for pointing this out.

I used Codex to help generate the patch. I had confirmed the bug with KASAN,
and I also verified the proposed fix with my reproducer. With the patch applied,
the reproducer no longer triggers the KASAN report.

I will send a v2 with the appropriate LLM disclosure tag.

Thanks,
Shuangpeng

>> Signed-off-by: Shuangpeng Bai <shuangpeng.kernel@gmail.com>
>> ---
>>  fs/btrfs/raid-stripe-tree.c | 1 -
>>  1 file changed, 1 deletion(-)
>> diff --git a/fs/btrfs/raid-stripe-tree.c b/fs/btrfs/raid-stripe-tree.c
>> index b210371ce91e..89e259a47d8d 100644
>> --- a/fs/btrfs/raid-stripe-tree.c
>> +++ b/fs/btrfs/raid-stripe-tree.c
>> @@ -337,7 +337,6 @@ int btrfs_insert_one_raid_extent(struct btrfs_trans_handle *trans,
>>   stripe_extent = kzalloc(item_size, GFP_NOFS);
>>   if (unlikely(!stripe_extent)) {
>>   btrfs_abort_transaction(trans, -ENOMEM);
>> - btrfs_end_transaction(trans);
>>   return -ENOMEM;
>>   }
>>  
> 


^ permalink raw reply	[flat|nested] 6+ messages in thread

* [PATCH v2] btrfs: fix transaction use-after-free in raid stripe insertion
  2026-08-17  1:27 [PATCH] btrfs: fix transaction use-after-free in raid stripe insertion Shuangpeng Bai
  2026-08-17  1:58 ` Qu Wenruo
@ 2026-08-17  2:15 ` Shuangpeng Bai
  2026-08-17  3:04   ` Qu Wenruo
  1 sibling, 1 reply; 6+ messages in thread
From: Shuangpeng Bai @ 2026-08-17  2:15 UTC (permalink / raw)
  To: linux-btrfs; +Cc: clm, dsterba, wqu

If allocation of a RAID stripe extent fails,
btrfs_insert_one_raid_extent() aborts and ends the transaction before
returning -ENOMEM.

btrfs_finish_one_ordered(), the production caller through
btrfs_insert_raid_extent(), still owns the transaction handle. It handles
the error by aborting the transaction and then reaches the common exit
path, which ends the transaction again.

The premature end can free the handle and drop its transaction reference.
Transaction cleanup can then free the transaction before the caller's
second abort accesses the handle and transaction, resulting in
use-after-free.

Keep the abort at the failure site, but let the caller's common exit path
end the transaction once, after it has finished using both objects.

Fixes: 02c372e1f016 ("btrfs: add support for inserting raid stripe extents")
Cc: stable@vger.kernel.org
Assisted-by: Codex:GPT-5
Signed-off-by: Shuangpeng Bai <shuangpeng.kernel@gmail.com>
---
Changes in v2:
- Add the Assisted-by tag to disclose LLM usage.

v1: https://lore.kernel.org/r/20260817012733.2962781-1-shuangpeng.kernel@gmail.com

 fs/btrfs/raid-stripe-tree.c | 1 -
 1 file changed, 1 deletion(-)

diff --git a/fs/btrfs/raid-stripe-tree.c b/fs/btrfs/raid-stripe-tree.c
index b210371ce91e..89e259a47d8d 100644
--- a/fs/btrfs/raid-stripe-tree.c
+++ b/fs/btrfs/raid-stripe-tree.c
@@ -337,7 +337,6 @@ int btrfs_insert_one_raid_extent(struct btrfs_trans_handle *trans,
 	stripe_extent = kzalloc(item_size, GFP_NOFS);
 	if (unlikely(!stripe_extent)) {
 		btrfs_abort_transaction(trans, -ENOMEM);
-		btrfs_end_transaction(trans);
 		return -ENOMEM;
 	}
 
-- 
2.43.0

^ permalink raw reply related	[flat|nested] 6+ messages in thread

* Re: [PATCH] btrfs: fix transaction use-after-free in raid stripe insertion
  2026-08-17  2:09   ` Shuangpeng
@ 2026-08-17  2:16     ` Qu Wenruo
  0 siblings, 0 replies; 6+ messages in thread
From: Qu Wenruo @ 2026-08-17  2:16 UTC (permalink / raw)
  To: Shuangpeng; +Cc: linux-btrfs, clm, dsterba



在 2026/8/17 11:39, Shuangpeng 写道:
> 
> 
>> On Aug 16, 2026, at 21:58, Qu Wenruo <wqu@suse.com> wrote:
>>
>>
>>
>> 在 2026/8/17 10:57, Shuangpeng Bai 写道:
>>> If allocation of a RAID stripe extent fails,
>>> btrfs_insert_one_raid_extent() aborts and ends the transaction before
>>> returning -ENOMEM.
>>> btrfs_finish_one_ordered(), the production caller through
>>> btrfs_insert_raid_extent(), still owns the transaction handle. It handles
>>> the error by aborting the transaction and then reaches the common exit
>>> path, which ends the transaction again.
>>> The premature end can free the handle and drop its transaction reference.
>>> Transaction cleanup can then free the transaction before the caller's
>>> second abort accesses the handle and transaction, resulting in
>>> use-after-free.
>>> Keep the abort at the failure site, but let the caller's common exit path
>>> end the transaction once, after it has finished using both objects.
>>> Fixes: 02c372e1f016 ("btrfs: add support for inserting raid stripe extents")
>>> Cc: stable@vger.kernel.org
>>
>> Please disclose LLM usage.
>>
> 
> Hi Qu,
> 
> Thanks for pointing this out.
> 
> I used Codex to help generate the patch. I had confirmed the bug with KASAN,
> and I also verified the proposed fix with my reproducer. With the patch applied,
> the reproducer no longer triggers the KASAN report.

And a full fstests run to prevent regression.

> 
> I will send a v2 with the appropriate LLM disclosure tag.
> 
> Thanks,
> Shuangpeng
> 
>>> Signed-off-by: Shuangpeng Bai <shuangpeng.kernel@gmail.com>
>>> ---
>>>   fs/btrfs/raid-stripe-tree.c | 1 -
>>>   1 file changed, 1 deletion(-)
>>> diff --git a/fs/btrfs/raid-stripe-tree.c b/fs/btrfs/raid-stripe-tree.c
>>> index b210371ce91e..89e259a47d8d 100644
>>> --- a/fs/btrfs/raid-stripe-tree.c
>>> +++ b/fs/btrfs/raid-stripe-tree.c
>>> @@ -337,7 +337,6 @@ int btrfs_insert_one_raid_extent(struct btrfs_trans_handle *trans,
>>>    stripe_extent = kzalloc(item_size, GFP_NOFS);
>>>    if (unlikely(!stripe_extent)) {
>>>    btrfs_abort_transaction(trans, -ENOMEM);
>>> - btrfs_end_transaction(trans);
>>>    return -ENOMEM;
>>>    }
>>>   
>>
> 


^ permalink raw reply	[flat|nested] 6+ messages in thread

* Re: [PATCH v2] btrfs: fix transaction use-after-free in raid stripe insertion
  2026-08-17  2:15 ` [PATCH v2] " Shuangpeng Bai
@ 2026-08-17  3:04   ` Qu Wenruo
  0 siblings, 0 replies; 6+ messages in thread
From: Qu Wenruo @ 2026-08-17  3:04 UTC (permalink / raw)
  To: Shuangpeng Bai, linux-btrfs; +Cc: clm, dsterba



在 2026/8/17 11:45, Shuangpeng Bai 写道:
> If allocation of a RAID stripe extent fails,
> btrfs_insert_one_raid_extent() aborts and ends the transaction before
> returning -ENOMEM.
> 
> btrfs_finish_one_ordered(), the production caller through
> btrfs_insert_raid_extent(), still owns the transaction handle. It handles
> the error by aborting the transaction and then reaches the common exit
> path, which ends the transaction again.
> 
> The premature end can free the handle and drop its transaction reference.
> Transaction cleanup can then free the transaction before the caller's
> second abort accesses the handle and transaction, resulting in
> use-after-free.
> 
> Keep the abort at the failure site, but let the caller's common exit path
> end the transaction once, after it has finished using both objects.
> 
> Fixes: 02c372e1f016 ("btrfs: add support for inserting raid stripe extents")
> Cc: stable@vger.kernel.org
> Assisted-by: Codex:GPT-5
> Signed-off-by: Shuangpeng Bai <shuangpeng.kernel@gmail.com>

Reviewed-by: Qu Wenruo <wqu@suse.com>

> ---
> Changes in v2:
> - Add the Assisted-by tag to disclose LLM usage.
> 
> v1: https://lore.kernel.org/r/20260817012733.2962781-1-shuangpeng.kernel@gmail.com
> 
>   fs/btrfs/raid-stripe-tree.c | 1 -
>   1 file changed, 1 deletion(-)
> 
> diff --git a/fs/btrfs/raid-stripe-tree.c b/fs/btrfs/raid-stripe-tree.c
> index b210371ce91e..89e259a47d8d 100644
> --- a/fs/btrfs/raid-stripe-tree.c
> +++ b/fs/btrfs/raid-stripe-tree.c
> @@ -337,7 +337,6 @@ int btrfs_insert_one_raid_extent(struct btrfs_trans_handle *trans,
>   	stripe_extent = kzalloc(item_size, GFP_NOFS);
>   	if (unlikely(!stripe_extent)) {
>   		btrfs_abort_transaction(trans, -ENOMEM);
> -		btrfs_end_transaction(trans);
>   		return -ENOMEM;
>   	}
>   


^ permalink raw reply	[flat|nested] 6+ messages in thread

end of thread, other threads:[~2026-08-17  3:04 UTC | newest]

Thread overview: 6+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-08-17  1:27 [PATCH] btrfs: fix transaction use-after-free in raid stripe insertion Shuangpeng Bai
2026-08-17  1:58 ` Qu Wenruo
2026-08-17  2:09   ` Shuangpeng
2026-08-17  2:16     ` Qu Wenruo
2026-08-17  2:15 ` [PATCH v2] " Shuangpeng Bai
2026-08-17  3:04   ` Qu Wenruo

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.