All of lore.kernel.org
 help / color / mirror / Atom feed
From: Adarsh Das <adarshdas950@gmail.com>
To: johannes.thumshirn@wdc.com
Cc: adarshdas950@gmail.com, dsterba@suse.com,
	linux-btrfs@vger.kernel.org, linux-kernel@vger.kernel.org,
	mason@kernel.org,
	syzbot+3bf3e110b2d406b8166c@syzkaller.appspotmail.com
Subject: [PATCH v2] btrfs: unwind device add when sysfs registration fails
Date: Wed,  7 Oct 2026 21:33:49 +0530	[thread overview]
Message-ID: <20261007160349.22411-1-adarshdas950@gmail.com> (raw)
In-Reply-To: <eb63c9f9-a158-4a70-b3ed-30046b15de11@wdc.com>

btrfs_init_new_device() ignored the return value of
btrfs_sysfs_add_device(). When sysfs link creation failed (e.g. -EEXIST),
the add path continued, aborted the transaction with the same errno, and
tripped WARN_ON(btrfs_abort_should_print_stack()) while leaving the device
half-registered in memory.

Check the return value and unwind when registration fails, without
aborting the filesystem for errnos like -EEXIST. If add failed before
anything was published in sysfs, tear down the in-memory device state only
and do not call btrfs_sysfs_remove_device(). When the block-device link
was created but devid kobject registration fails, drop the link inside
btrfs_sysfs_add_device() before returning the error.

Reported-by: syzbot+3bf3e110b2d406b8166c@syzkaller.appspotmail.com
Link: https://lore.kernel.org/all/6a791c94.01d0871a.3a0d52.0099.GAE@google.com
Tested-by: syzbot+3bf3e110b2d406b8166c@syzkaller.appspotmail.com
Assisted-by: LLM
Signed-off-by: Adarsh Das <adarshdas950@gmail.com>
---
v2:
 - Unwind without sysfs remove when add failed (review on v1)
 - Roll back block-device link if devid kobject add fails
v1: https://lore.kernel.org/all/20261003111951.24527-1-adarshdas950@gmail.com/
---
 fs/btrfs/sysfs.c   | 3 +++
 fs/btrfs/volumes.c | 7 ++++++-
 2 files changed, 9 insertions(+), 1 deletion(-)

diff --git a/fs/btrfs/sysfs.c b/fs/btrfs/sysfs.c
index 39cb01ee441a..2f034689e71b 100644
--- a/fs/btrfs/sysfs.c
+++ b/fs/btrfs/sysfs.c
@@ -2165,6 +2165,9 @@ int btrfs_sysfs_add_device(struct btrfs_device *device)
 	ret = kobject_init_and_add(&device->devid_kobj, &devid_ktype,
 				   devinfo_kobj, "%llu", device->devid);
 	if (ret) {
+		if (device->bdev)
+			sysfs_remove_link(devices_kobj,
+					  bdev_kobj(device->bdev)->name);
 		kobject_put(&device->devid_kobj);
 		btrfs_warn(device->fs_info,
 			   "devinfo init for devid %llu failed: %d",
diff --git a/fs/btrfs/volumes.c b/fs/btrfs/volumes.c
index 85ea9c5d4536..56b38f012093 100644
--- a/fs/btrfs/volumes.c
+++ b/fs/btrfs/volumes.c
@@ -3066,7 +3066,11 @@ int btrfs_init_new_device(struct btrfs_fs_info *fs_info, const char *device_path
 	mutex_unlock(&fs_info->chunk_mutex);
 
 	/* Add sysfs device entry */
-	btrfs_sysfs_add_device(device);
+	ret = btrfs_sysfs_add_device(device);
+	if (ret) {
+		mutex_unlock(&fs_devices->device_list_mutex);
+		goto error_unwind_device;
+	}
 
 	mutex_unlock(&fs_devices->device_list_mutex);
 
@@ -3147,6 +3151,7 @@ int btrfs_init_new_device(struct btrfs_fs_info *fs_info, const char *device_path
 
 error_sysfs:
 	btrfs_sysfs_remove_device(device);
+error_unwind_device:
 	mutex_lock(&fs_info->fs_devices->device_list_mutex);
 	if (seeding_dev)
 		btrfs_assign_next_active_device(device, seed_devices->latest_dev);

      reply	other threads:[~2026-10-07 16:03 UTC|newest]

Thread overview: 3+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-10-03 11:19 [PATCH] btrfs: unwind device add when sysfs registration fails Adarsh Das
2026-10-07 13:58 ` Johannes Thumshirn
2026-10-07 16:03   ` Adarsh Das [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20261007160349.22411-1-adarshdas950@gmail.com \
    --to=adarshdas950@gmail.com \
    --cc=dsterba@suse.com \
    --cc=johannes.thumshirn@wdc.com \
    --cc=linux-btrfs@vger.kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=mason@kernel.org \
    --cc=syzbot+3bf3e110b2d406b8166c@syzkaller.appspotmail.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.