All of lore.kernel.org
 help / color / mirror / Atom feed
From: Moritz Tanner <moritz.tanner@linbit.com>
To: fstests@vger.kernel.org
Cc: Zorro Lang <zlang@kernel.org>,
	Christian Brauner <brauner@kernel.org>,
	Lars Ellenberg <lars.ellenberg@linbit.com>,
	Moritz Tanner <moritz.tanner@linbit.com>,
	Christoph Hellwig <hch@lst.de>
Subject: [PATCH] generic: test bdev freeze count leak on nested thaw
Date: Thu, 17 Sep 2026 08:59:38 +0200	[thread overview]
Message-ID: <20260917065938.51819-1-moritz.tanner@linbit.com> (raw)

Since kernel v6.8, a nested thaw that drops its freeze reference
while other freezers remain returns -EINVAL although it succeeded.
bdev_thaw() then keeps bd_fsfreeze_count elevated, and since
device-mapper's unlock_fs() ignores the error, a dm suspend/resume
cycle on a filesystem frozen with FIFREEZE leaks the count. After
unfreezing and unmounting, the block device can never be mounted
again:

    dm-1: Can't mount, blockdev is frozen

Add a regression test that freezes a filesystem on a dm-linear
device, runs a dm suspend/resume cycle inside the freeze, unfreezes
and remounts. On buggy kernels the final mount fails with EBUSY.

Suggested-by: Christoph Hellwig <hch@lst.de>
Lore: https://lore.kernel.org/linux-fsdevel/20260821085451.65206-1-moritz.tanner@linbit.com/
Signed-off-by: Moritz Tanner <moritz.tanner@linbit.com>
---
 tests/generic/802     | 69 +++++++++++++++++++++++++++++++++++++++++++
 tests/generic/802.out |  2 ++
 2 files changed, 71 insertions(+)
 create mode 100755 tests/generic/802
 create mode 100644 tests/generic/802.out

diff --git a/tests/generic/802 b/tests/generic/802
new file mode 100755
index 00000000..d3b84200
--- /dev/null
+++ b/tests/generic/802
@@ -0,0 +1,69 @@
+#! /bin/bash
+# SPDX-License-Identifier: GPL-2.0
+# Copyright (c) 2026 LINBIT HA-Solutions GmbH.  All Rights Reserved.
+#
+# FS QA Test 802
+#
+# Test that a device-mapper suspend/resume cycle on a filesystem that is
+# already frozen by userspace does not leak a block device freeze reference.
+#
+# On buggy kernels thaw_super() returns -EINVAL for a nested thaw although
+# it dropped its freeze reference, so bdev_thaw() leaves bd_fsfreeze_count
+# elevated. Once the filesystem is unmounted, the block device can never
+# be mounted again:
+#
+#     dm-1: Can't mount, blockdev is frozen
+#
+. ./common/preamble
+_begin_fstest auto quick freeze mount
+
+_fixed_by_kernel_commit fe967191e585 \
+	"fs: don't return -EINVAL for successful nested thaw"
+
+# Override the default cleanup function.
+_cleanup()
+{
+	xfs_freeze -u $SCRATCH_MNT 2>/dev/null
+	$DMSETUP_PROG resume $lvdev >> $seqres.full 2>&1
+	_unmount -q $SCRATCH_MNT
+	_dmsetup_remove $node
+	cd /
+	rm -f $tmp.*
+}
+
+_require_scratch
+_require_dm_target linear
+_require_freeze
+
+echo "Silence is golden"
+
+size=$((256 * 1024 * 1024))
+size_in_sector=$((size / 512))
+_scratch_mkfs_sized $size >> $seqres.full 2>&1
+
+node=$seq-test
+lvdev=/dev/mapper/$node
+table="0 $size_in_sector linear $SCRATCH_DEV 0"
+_dmsetup_create $node --table "$table" || \
+	_fail "failed to create dm device"
+
+_mount $lvdev $SCRATCH_MNT || _fail "failed to mount dm device"
+
+# Freeze the filesystem from userspace first, then nest a block device
+# initiated freeze/thaw cycle inside it via dm suspend/resume.
+xfs_freeze -f $SCRATCH_MNT || _fail "failed to freeze filesystem"
+$DMSETUP_PROG suspend $lvdev >> $seqres.full 2>&1 || \
+	_fail "failed to suspend dm device"
+$DMSETUP_PROG resume $lvdev >> $seqres.full 2>&1 || \
+	_fail "failed to resume dm device"
+xfs_freeze -u $SCRATCH_MNT || _fail "failed to unfreeze filesystem"
+
+# On buggy kernels the resume leaked a block device freeze reference,
+# and the device cannot be mounted again once unmounted.
+_unmount $SCRATCH_MNT
+_mount $lvdev $SCRATCH_MNT || \
+	_fail "failed to mount dm device after nested freeze/thaw"
+_unmount $SCRATCH_MNT
+
+status=0
+exit
diff --git a/tests/generic/802.out b/tests/generic/802.out
new file mode 100644
index 00000000..a69c0539
--- /dev/null
+++ b/tests/generic/802.out
@@ -0,0 +1,2 @@
+QA output created by 802
+Silence is golden
-- 
2.55.0


             reply	other threads:[~2026-09-17  7:00 UTC|newest]

Thread overview: 3+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-17  6:59 Moritz Tanner [this message]
2026-09-18  9:01 ` [PATCH] generic: test bdev freeze count leak on nested thaw Christoph Hellwig
2026-09-20 12:02 ` Zorro Lang

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260917065938.51819-1-moritz.tanner@linbit.com \
    --to=moritz.tanner@linbit.com \
    --cc=brauner@kernel.org \
    --cc=fstests@vger.kernel.org \
    --cc=hch@lst.de \
    --cc=lars.ellenberg@linbit.com \
    --cc=zlang@kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.