From: Zorro Lang <zlang@kernel.org>
To: Moritz Tanner <moritz.tanner@linbit.com>
Cc: fstests@vger.kernel.org, Christian Brauner <brauner@kernel.org>,
Lars Ellenberg <lars.ellenberg@linbit.com>,
Christoph Hellwig <hch@lst.de>
Subject: Re: [PATCH] generic: test bdev freeze count leak on nested thaw
Date: Sun, 20 Sep 2026 20:02:37 +0800 [thread overview]
Message-ID: <aq_LAV1YmwpPgwGm@zlang-mailbox> (raw)
In-Reply-To: <20260917065938.51819-1-moritz.tanner@linbit.com>
On Thu, Sep 17, 2026 at 08:59:38AM +0200, Moritz Tanner wrote:
> Since kernel v6.8, a nested thaw that drops its freeze reference
> while other freezers remain returns -EINVAL although it succeeded.
> bdev_thaw() then keeps bd_fsfreeze_count elevated, and since
> device-mapper's unlock_fs() ignores the error, a dm suspend/resume
> cycle on a filesystem frozen with FIFREEZE leaks the count. After
> unfreezing and unmounting, the block device can never be mounted
> again:
>
> dm-1: Can't mount, blockdev is frozen
>
> Add a regression test that freezes a filesystem on a dm-linear
> device, runs a dm suspend/resume cycle inside the freeze, unfreezes
> and remounts. On buggy kernels the final mount fails with EBUSY.
>
> Suggested-by: Christoph Hellwig <hch@lst.de>
> Lore: https://lore.kernel.org/linux-fsdevel/20260821085451.65206-1-moritz.tanner@linbit.com/
> Signed-off-by: Moritz Tanner <moritz.tanner@linbit.com>
> ---
Looks good to me,
Reviewed-by: Zorro Lang <zlang@kernel.org>
> tests/generic/802 | 69 +++++++++++++++++++++++++++++++++++++++++++
> tests/generic/802.out | 2 ++
> 2 files changed, 71 insertions(+)
> create mode 100755 tests/generic/802
> create mode 100644 tests/generic/802.out
>
> diff --git a/tests/generic/802 b/tests/generic/802
> new file mode 100755
> index 00000000..d3b84200
> --- /dev/null
> +++ b/tests/generic/802
> @@ -0,0 +1,69 @@
> +#! /bin/bash
> +# SPDX-License-Identifier: GPL-2.0
> +# Copyright (c) 2026 LINBIT HA-Solutions GmbH. All Rights Reserved.
> +#
> +# FS QA Test 802
> +#
> +# Test that a device-mapper suspend/resume cycle on a filesystem that is
> +# already frozen by userspace does not leak a block device freeze reference.
> +#
> +# On buggy kernels thaw_super() returns -EINVAL for a nested thaw although
> +# it dropped its freeze reference, so bdev_thaw() leaves bd_fsfreeze_count
> +# elevated. Once the filesystem is unmounted, the block device can never
> +# be mounted again:
> +#
> +# dm-1: Can't mount, blockdev is frozen
> +#
> +. ./common/preamble
> +_begin_fstest auto quick freeze mount
> +
> +_fixed_by_kernel_commit fe967191e585 \
> + "fs: don't return -EINVAL for successful nested thaw"
> +
> +# Override the default cleanup function.
> +_cleanup()
> +{
> + xfs_freeze -u $SCRATCH_MNT 2>/dev/null
> + $DMSETUP_PROG resume $lvdev >> $seqres.full 2>&1
> + _unmount -q $SCRATCH_MNT
> + _dmsetup_remove $node
> + cd /
> + rm -f $tmp.*
> +}
> +
> +_require_scratch
> +_require_dm_target linear
> +_require_freeze
> +
> +echo "Silence is golden"
> +
> +size=$((256 * 1024 * 1024))
> +size_in_sector=$((size / 512))
> +_scratch_mkfs_sized $size >> $seqres.full 2>&1
> +
> +node=$seq-test
> +lvdev=/dev/mapper/$node
> +table="0 $size_in_sector linear $SCRATCH_DEV 0"
> +_dmsetup_create $node --table "$table" || \
> + _fail "failed to create dm device"
> +
> +_mount $lvdev $SCRATCH_MNT || _fail "failed to mount dm device"
> +
> +# Freeze the filesystem from userspace first, then nest a block device
> +# initiated freeze/thaw cycle inside it via dm suspend/resume.
> +xfs_freeze -f $SCRATCH_MNT || _fail "failed to freeze filesystem"
> +$DMSETUP_PROG suspend $lvdev >> $seqres.full 2>&1 || \
> + _fail "failed to suspend dm device"
> +$DMSETUP_PROG resume $lvdev >> $seqres.full 2>&1 || \
> + _fail "failed to resume dm device"
> +xfs_freeze -u $SCRATCH_MNT || _fail "failed to unfreeze filesystem"
> +
> +# On buggy kernels the resume leaked a block device freeze reference,
> +# and the device cannot be mounted again once unmounted.
> +_unmount $SCRATCH_MNT
> +_mount $lvdev $SCRATCH_MNT || \
> + _fail "failed to mount dm device after nested freeze/thaw"
> +_unmount $SCRATCH_MNT
> +
> +status=0
> +exit
> diff --git a/tests/generic/802.out b/tests/generic/802.out
> new file mode 100644
> index 00000000..a69c0539
> --- /dev/null
> +++ b/tests/generic/802.out
> @@ -0,0 +1,2 @@
> +QA output created by 802
> +Silence is golden
> --
> 2.55.0
>
prev parent reply other threads:[~2026-09-20 12:02 UTC|newest]
Thread overview: 3+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-17 6:59 [PATCH] generic: test bdev freeze count leak on nested thaw Moritz Tanner
2026-09-18 9:01 ` Christoph Hellwig
2026-09-20 12:02 ` Zorro Lang [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=aq_LAV1YmwpPgwGm@zlang-mailbox \
--to=zlang@kernel.org \
--cc=brauner@kernel.org \
--cc=fstests@vger.kernel.org \
--cc=hch@lst.de \
--cc=lars.ellenberg@linbit.com \
--cc=moritz.tanner@linbit.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.