From: Tao Cui <cui.tao@linux.dev>
To: Yu Kuai <yukuai@kernel.org>, tj@kernel.org, axboe@kernel.dk
Cc: cgroups@vger.kernel.org, linux-block@vger.kernel.org,
linux-kernel@vger.kernel.org, zhengqixing@huawei.com, hch@lst.de,
yizhou.tang@shopee.com, yukuai@fygo.io, nilay@linux.ibm.com
Subject: Re: [PATCH v4 2/4] blk-cgroup: fix race between policy activation and blkg destruction
Date: Sun, 02 Aug 2026 19:46:06 +0800 [thread overview]
Message-ID: <491DAFBA-ADD6-4CA4-B0E4-87402A0BC64B@linux.dev> (raw)
In-Reply-To: <20260802112525.3933753-3-yukuai@kernel.org>
于 2026年8月2日 GMT+08:00 19:25:18,Yu Kuai <yukuai@kernel.org> 写道:
>From: Zheng Qixing <zhengqixing@huawei.com>
>
>When switching an IO scheduler on a block device, blkcg_activate_policy()
>allocates blkg_policy_data (pd) for all blkgs attached to the queue.
>However, blkcg_activate_policy() may race with concurrent blkcg deletion,
>leading to use-after-free and memory leak issues.
>
>The use-after-free occurs in the following race:
>
>T1 (blkcg_activate_policy):
> - Successfully allocates pd for blkg1 (loop0->queue, blkcgA)
> - Fails to allocate pd for blkg2 (loop0->queue, blkcgB)
> - Enters the enomem rollback path to release blkg1 resources
>
>T2 (blkcg deletion):
> - blkcgA is deleted concurrently
> - blkg1 is freed via blkg_free_workfn()
> - blkg1->pd is freed
>
>T1 (continued):
> - Rollback path accesses blkg1->pd->online after pd is freed
> - Triggers use-after-free
>
>In addition, blkg_free_workfn() frees pd before removing the blkg from
>q->blkg_list. This allows blkcg_activate_policy() to allocate a new pd
>for a blkg that is being destroyed, leaving the newly allocated pd
>unreachable when the blkg is finally freed.
>
>Fix these races by extending blkcg_mutex coverage to serialize
>blkcg_activate_policy() rollback and blkg destruction, ensuring pd
>lifecycle is synchronized with blkg list visibility.
>
>Fixes: f1c006f1c685 ("blk-cgroup: synchronize pd_free_fn() from blkg_free_workfn() and blkcg_deactivate_policy()")
>Signed-off-by: Zheng Qixing <zhengqixing@huawei.com>
>Reviewed-by: Tang Yizhou <yizhou.tang@shopee.com>
>Signed-off-by: Yu Kuai <yukuai@fygo.io>
>---
> block/blk-cgroup.c | 3 +++
> 1 file changed, 3 insertions(+)
>
>diff --git a/block/blk-cgroup.c b/block/blk-cgroup.c
>index eb0cfb10b859..047bb42c282b 100644
>--- a/block/blk-cgroup.c
>+++ b/block/blk-cgroup.c
>@@ -1566,6 +1566,8 @@ int blkcg_activate_policy(struct gendisk *disk, const struct blkcg_policy *pol)
>
> if (queue_is_mq(q))
> memflags = blk_mq_freeze_queue(q);
>+
>+ mutex_lock(&q->blkcg_mutex);
> retry:
> spin_lock_irq(&q->queue_lock);
>
>@@ -1628,6 +1630,7 @@ int blkcg_activate_policy(struct gendisk *disk, const struct blkcg_policy *pol)
>
> spin_unlock_irq(&q->queue_lock);
> out:
>+ mutex_unlock(&q->blkcg_mutex);
> if (queue_is_mq(q))
> blk_mq_unfreeze_queue(q, memflags);
> if (pinned_blkg)
Reviewed-by: Tao Cui <cuitao@kylinos.cn>
next prev parent reply other threads:[~2026-08-02 11:46 UTC|newest]
Thread overview: 13+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-02 11:25 [PATCH v4 0/4] blk-cgroup: fix blkg list and policy data races Yu Kuai
2026-08-02 11:25 ` [PATCH v4 1/4] blk-cgroup: protect q->blkg_list iteration in blkg_destroy_all() with blkcg_mutex Yu Kuai
2026-08-02 11:45 ` Tao Cui
2026-08-02 11:25 ` [PATCH v4 2/4] blk-cgroup: fix race between policy activation and blkg destruction Yu Kuai
2026-08-02 11:46 ` Tao Cui [this message]
2026-08-02 11:25 ` [PATCH v4 3/4] blk-cgroup: skip dying blkg in blkcg_activate_policy() Yu Kuai
2026-08-02 11:47 ` Tao Cui
2026-08-02 11:25 ` [PATCH v4 4/4] blk-cgroup: factor policy pd teardown loop into helper Yu Kuai
2026-08-02 11:25 ` [PATCH v4 0/4] blk-cgroup: fix blkg list and policy data races Yu Kuai
2026-08-03 6:51 ` Nilay Shroff
2026-08-03 8:20 ` yu kuai
2026-08-03 9:09 ` Nilay Shroff
2026-08-04 2:17 ` Jens Axboe
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=491DAFBA-ADD6-4CA4-B0E4-87402A0BC64B@linux.dev \
--to=cui.tao@linux.dev \
--cc=axboe@kernel.dk \
--cc=cgroups@vger.kernel.org \
--cc=hch@lst.de \
--cc=linux-block@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=nilay@linux.ibm.com \
--cc=tj@kernel.org \
--cc=yizhou.tang@shopee.com \
--cc=yukuai@fygo.io \
--cc=yukuai@kernel.org \
--cc=zhengqixing@huawei.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.