From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 421F04EFFD5; Thu, 17 Sep 2026 15:56:13 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789660574; cv=none; b=c28O+g6E4CvQPe1owsrqZl4C/20xoizpu0y7Mlh4Y2D88KBjMqskotOw8bsSz/jnDkv6qG1XEWnKtJB/6PF98xZC/u9Mj3H40yMWhaFQ+KdvaqULWCTYYFSDyoEIYZDgA3i/0490HhxUqNP1jgvIE+B6k+G65FRwGoNHk1l80H0= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789660574; c=relaxed/simple; bh=LWNCv6fmCGU7tWGLpDsfyllkFG2cJVkm8VMeiGJWzfM=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=qm2noYq1rJMXw58r+kF2Uois/3vReqkwHyOhWmdJngs8Qt7aEMfR/QXd85iiptUzKUS/EnscJhNGmNaUQ7I2KV14iamvF508rsM3hD7xA19bkdcVitZzLihI8/ClU0AyOCFLFLrqYyrYYK1kkTt20TLeFKznMjoh44wWDt1yVA0= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=vMAmqE+N; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="vMAmqE+N" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 949711F000FF; Thu, 17 Sep 2026 15:56:12 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1789660573; bh=eEekKH46o5oW21f5Ua+1K5tBZjxzWZHW/k+x702QhXY=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=vMAmqE+N/stSP67lSWkNy6y4LsSSA9bu14lJvp8car+QGWIHLIfFUtj1ra5p9DBmS +qhwyYiGpQ+8uI16aUNm0cTaUxBYTQrulo1A2oInwktgvr+COmm7MY58hADZ8pGL3W iiRwXDCYt7Clt9ATqa3U4Dv+lAxSwl+aFmpkCfvM= From: Greg Kroah-Hartman To: stable@vger.kernel.org Cc: Greg Kroah-Hartman , patches@lists.linux.dev, Bjoern Doebel , Namjae Jeon , Paulo Alcantara Subject: [PATCH 7.2 637/733] smb: client: avoid leaking refcount in cifs_queue_oplock_break() Date: Thu, 17 Sep 2026 16:15:45 +0100 Message-ID: <20260917151408.456865142@linuxfoundation.org> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260917151350.597953846@linuxfoundation.org> References: <20260917151350.597953846@linuxfoundation.org> User-Agent: quilt/0.69 X-stable: review X-Patchwork-Hint: ignore Precedence: bulk X-Mailing-List: patches@lists.linux.dev List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit 7.2-stable review patch. If anyone has any objections, please let me know. ------------------ From: Bjoern Doebel commit 9f2e63f1b2d5fc5b5423424902c091123e220e7e upstream. cifs_queue_oplock_break() unconditionally takes a reference on the target file before queueing cifs_oplock_break(). Only that work item decreases the reference counter again. If another oplock break arrives while that work is still queued, queue_work() will return false and not queue this second work item. As a result, we will never reach the point to drop the file reference again and are leaking this reference. This can be triggered when interacting with a slow-responding server. As a result, later unmount operations for this file system will fail with BUG: Dentry ... still in use (1) [unmount of cifs cifs] VFS: Busy inodes after unmount of cifs (cifs) kernel BUG at fs/super.c:777! Fix this by only incrementing the reference count if the work has been queued successfully. Taking it after queue_work() is safe because all three callers hold tcon->open_file_lock across the call and _cifsFileInfo_put() decrements under that same lock, so a worker that starts the handler in the window cannot drop the reference before it has been taken. Fixes: b98749cac4a69 ("CIFS: keep FileInfo handle live during oplock break") Cc: stable@vger.kernel.org Assisted-by: Kiro:claude-opus-5 Signed-off-by: Bjoern Doebel Reviewed-by: Namjae Jeon Signed-off-by: Paulo Alcantara Signed-off-by: Greg Kroah-Hartman --- fs/smb/client/misc.c | 7 ++++--- 1 file changed, 4 insertions(+), 3 deletions(-) --- a/fs/smb/client/misc.c +++ b/fs/smb/client/misc.c @@ -378,10 +378,11 @@ void cifs_queue_oplock_break(struct cifs * open_file_lock to enforce the validity of it for the oplock * break handler. The matching put is done at the end of the * handler. + * + * Only take a reference if the work is actually queued. */ - cifsFileInfo_get(cfile); - - queue_work(cifsoplockd_wq, &cfile->oplock_break); + if (queue_work(cifsoplockd_wq, &cfile->oplock_break)) + cifsFileInfo_get(cfile); } void cifs_done_oplock_break(struct cifsInodeInfo *cinode)