From: Kefeng Wang <wangkefeng.wang@huawei.com>
To: <brauner@kernel.org>, <djwong@kernel.org>, <cem@kernel.org>,
<akpm@linux-foundation.org>, <vbabka@kernel.org>,
<surenb@google.com>, <mhocko@suse.com>,
<brendan.jackman@linux.dev>, <hannes@cmpxchg.org>,
<ziy@nvidia.com>, <david@kernel.org>, <qi.zheng@linux.dev>,
<shakeel.butt@linux.dev>, <ljs@kernel.org>
Cc: <linux-xfs@vger.kernel.org>, <linux-fsdevel@vger.kernel.org>,
<linux-mm@kvack.org>, Kefeng Wang <wangkefeng.wang@huawei.com>
Subject: [PATCH] xfs: fix NOFS state corruption in btree split worker
Date: Thu, 3 Sep 2026 21:37:56 +0800 [thread overview]
Message-ID: <20260903133756.2006032-1-wangkefeng.wang@huawei.com> (raw)
In-Reply-To: <20260902134417.c44503a1d65533f81fb1c391@linux-foundation.org>
xfs_btree_split_worker() calls xfs_trans_set_context() and
xfs_trans_clear_context() on the caller's transaction, overwriting
tp->t_pflags with the worker's NOFS state. When the caller already has
PF_MEMALLOC_NOFS set (e.g. xfs_end_ioend_write, xfs_dio_write_end_io),
the corrupted tp->t_pflags causes xfs_trans_free() to erroneously clear
the caller's NOFS protection.
Use memalloc_nofs_save/restore with a local variable instead so
tp->t_pflags is never touched.
Closes: https://sashiko.dev/#/patchset/20260902131653.1338227-1-wangkefeng.wang@huawei.com
Fixes: 756b1c343333 ("xfs: use current->journal_info for detecting transaction recursion")
Signed-off-by: Kefeng Wang <wangkefeng.wang@huawei.com>
---
fs/xfs/libxfs/xfs_btree.c | 10 ++++++++--
1 file changed, 8 insertions(+), 2 deletions(-)
diff --git a/fs/xfs/libxfs/xfs_btree.c b/fs/xfs/libxfs/xfs_btree.c
index 6738d9d1511b..8ae4b94e6995 100644
--- a/fs/xfs/libxfs/xfs_btree.c
+++ b/fs/xfs/libxfs/xfs_btree.c
@@ -3007,12 +3007,18 @@ xfs_btree_split_worker(
{
struct xfs_btree_split_args *args = container_of(work,
struct xfs_btree_split_args, work);
- xfs_trans_set_context(args->cur->bc_tp);
+ unsigned int nofs_flags;
+
+ /*
+ * Don't use xfs_trans_set_context() here: it would overwrite the
+ * caller's saved NOFS state in tp->t_pflags. Use a local scope.
+ */
+ nofs_flags = memalloc_nofs_save();
args->result = __xfs_btree_split(args->cur, args->level, args->ptrp,
args->key, args->curp, args->stat);
- xfs_trans_clear_context(args->cur->bc_tp);
+ memalloc_nofs_restore(nofs_flags);
/*
* Do not access args after complete() has run here. We don't own args
--
2.55.0
next prev parent reply other threads:[~2026-09-03 13:38 UTC|newest]
Thread overview: 34+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-02 13:16 [PATCH 0/4] mm: replace PF_KCOMPACTD/PF_KSWAPD with kthread_func() Kefeng Wang
2026-09-02 13:16 ` [PATCH 1/4] xfs: remove dead kswapd flag inheritance from btree split worker Kefeng Wang
2026-09-02 14:32 ` Christoph Hellwig
2026-09-02 15:33 ` Shakeel Butt
2026-09-02 13:16 ` [PATCH 2/4] iomap: simplify writepages reclaim guard Kefeng Wang
2026-09-02 14:32 ` Christoph Hellwig
2026-09-03 13:46 ` Kefeng Wang
2026-09-02 15:34 ` Shakeel Butt
2026-09-02 13:16 ` [PATCH 3/4] mm: replace PF_KSWAPD flag with kthread_func() check Kefeng Wang
2026-09-02 15:36 ` Shakeel Butt
2026-09-02 16:35 ` Vlastimil Babka (SUSE)
2026-09-02 16:39 ` Zi Yan
2026-09-10 11:56 ` David Hildenbrand (Arm)
2026-09-02 13:16 ` [PATCH 4/4] mm: replace PF_KCOMPACTD " Kefeng Wang
2026-09-02 15:37 ` Shakeel Butt
2026-09-02 16:36 ` Vlastimil Babka (SUSE)
2026-09-02 16:40 ` Zi Yan
2026-09-10 11:57 ` David Hildenbrand (Arm)
2026-09-02 15:31 ` [PATCH 0/4] mm: replace PF_KCOMPACTD/PF_KSWAPD with kthread_func() Shakeel Butt
2026-09-02 20:44 ` Andrew Morton
2026-09-03 13:37 ` Kefeng Wang [this message]
2026-09-03 13:52 ` [PATCH] xfs: fix NOFS state corruption in btree split worker Brian Foster
2026-09-04 0:41 ` Kefeng Wang
2026-09-04 11:57 ` Brian Foster
2026-09-10 5:47 ` Christoph Hellwig
2026-09-10 6:07 ` Darrick J. Wong
2026-09-15 7:09 ` Zhou, Yun
2026-09-15 9:19 ` Carlos Maiolino
2026-09-15 10:34 ` Zhou, Yun
2026-09-15 10:50 ` Carlos Maiolino
[not found] ` <20260910140742.833170-1-wangkefeng.wang@huawei.com>
[not found] ` <aqLqeTsbKBMEsl-G@bfoster>
2026-09-11 0:57 ` [PATCH] xfs: kill xfs_trans_set/clear_context() helpers Kefeng Wang
2026-09-11 7:12 ` Christoph Hellwig
2026-09-11 10:51 ` Kefeng Wang
2026-09-03 13:40 ` [PATCH 0/4] mm: replace PF_KCOMPACTD/PF_KSWAPD with kthread_func() Kefeng Wang
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260903133756.2006032-1-wangkefeng.wang@huawei.com \
--to=wangkefeng.wang@huawei.com \
--cc=akpm@linux-foundation.org \
--cc=brauner@kernel.org \
--cc=brendan.jackman@linux.dev \
--cc=cem@kernel.org \
--cc=david@kernel.org \
--cc=djwong@kernel.org \
--cc=hannes@cmpxchg.org \
--cc=linux-fsdevel@vger.kernel.org \
--cc=linux-mm@kvack.org \
--cc=linux-xfs@vger.kernel.org \
--cc=ljs@kernel.org \
--cc=mhocko@suse.com \
--cc=qi.zheng@linux.dev \
--cc=shakeel.butt@linux.dev \
--cc=surenb@google.com \
--cc=vbabka@kernel.org \
--cc=ziy@nvidia.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.