* [PATCH] block: Fix dio->ref leak on integrity error in __blkdev_direct_IO()
@ 2026-06-25 9:21 Wentao Liang
2026-06-26 8:58 ` Yang Xiuwei
2026-06-26 14:24 ` Keith Busch
0 siblings, 2 replies; 3+ messages in thread
From: Wentao Liang @ 2026-06-25 9:21 UTC (permalink / raw)
To: axboe; +Cc: linux-block, linux-kernel, Wentao Liang, stable
When __blkdev_direct_IO() splits an I/O across multiple bios and
bio_integrity_map_iter() fails on a non-first bio, the function jumps
to the 'fail' label which frees the current bio without accounting for
the dio->ref increments from previously submitted bios.
The in-flight bios complete normally but their atomic_dec_and_test()
in blkdev_bio_end_io() can never bring dio->ref to zero, leaving the
dio structure (and the first bio it is embedded in) permanently leaked.
For synchronous I/O, the waiter is never woken, causing a hang.
Fix by matching the existing error handling pattern used for
blkdev_iov_iter_get_pages() failure: end the current bio with an error
status and break out of the submission loop. This ensures the normal
completion path properly accounts for all dio->ref references, both
from the current errored bio and from any in-flight bios.
The NOWAIT error path is unaffected as its goto fail only triggers
on the first iteration where no bios have been submitted yet.
Cc: stable@vger.kernel.org
Fixes: 3d8b5a22d404 ("block: add support to pass user meta buffer")
Signed-off-by: Wentao Liang <vulab@iscas.ac.cn>
---
block/fops.c | 7 +++++--
1 file changed, 5 insertions(+), 2 deletions(-)
diff --git a/block/fops.c b/block/fops.c
index bb6642b45937..9f16b995c60c 100644
--- a/block/fops.c
+++ b/block/fops.c
@@ -239,8 +239,11 @@ static ssize_t __blkdev_direct_IO(struct kiocb *iocb, struct iov_iter *iter,
}
if (iocb->ki_flags & IOCB_HAS_METADATA) {
ret = bio_integrity_map_iter(bio, iocb->private);
- if (unlikely(ret))
- goto fail;
+ if (unlikely(ret)) {
+ bio->bi_status = errno_to_blk_status(ret);
+ bio_endio(bio);
+ break;
+ }
}
if (is_read) {
--
2.39.5 (Apple Git-154)
^ permalink raw reply related [flat|nested] 3+ messages in thread
* Re: [PATCH] block: Fix dio->ref leak on integrity error in __blkdev_direct_IO()
2026-06-25 9:21 [PATCH] block: Fix dio->ref leak on integrity error in __blkdev_direct_IO() Wentao Liang
@ 2026-06-26 8:58 ` Yang Xiuwei
2026-06-26 14:24 ` Keith Busch
1 sibling, 0 replies; 3+ messages in thread
From: Yang Xiuwei @ 2026-06-26 8:58 UTC (permalink / raw)
To: vulab; +Cc: axboe, linux-block, linux-kernel, stable, Yang Xiuwei
---
Hi Wentao,
On Thu, Jun 25, 2026 at 05:21:06PM +0800, Wentao Liang wrote:
> Fix by matching the existing error handling pattern used for
> blkdev_iov_iter_get_pages() failure: end the current bio with an error
> status and break out of the submission loop.
Looks good to me.
> + if (unlikely(ret)) {
> + bio->bi_status = errno_to_blk_status(ret);
> + bio_endio(bio);
> + break;
> + }
Small nit: consider bio_endio_status(bio, errno_to_blk_status(ret))
instead, now that the helper exists.
Reviewed-by: Yang Xiuwei <yangxiuwei@kylinos.cn>
Thanks,
Yang Xiuwei
^ permalink raw reply [flat|nested] 3+ messages in thread
* Re: [PATCH] block: Fix dio->ref leak on integrity error in __blkdev_direct_IO()
2026-06-25 9:21 [PATCH] block: Fix dio->ref leak on integrity error in __blkdev_direct_IO() Wentao Liang
2026-06-26 8:58 ` Yang Xiuwei
@ 2026-06-26 14:24 ` Keith Busch
1 sibling, 0 replies; 3+ messages in thread
From: Keith Busch @ 2026-06-26 14:24 UTC (permalink / raw)
To: Wentao Liang; +Cc: axboe, linux-block, linux-kernel, stable
On Thu, Jun 25, 2026 at 05:21:06PM +0800, Wentao Liang wrote:
> @@ -239,8 +239,11 @@ static ssize_t __blkdev_direct_IO(struct kiocb *iocb, struct iov_iter *iter,
> }
> if (iocb->ki_flags & IOCB_HAS_METADATA) {
> ret = bio_integrity_map_iter(bio, iocb->private);
> - if (unlikely(ret))
> - goto fail;
> + if (unlikely(ret)) {
> + bio->bi_status = errno_to_blk_status(ret);
> + bio_endio(bio);
> + break;
> + }
I've submitted this same fix earlier:
https://lore.kernel.org/linux-block/20260624170905.3972095-3-kbusch@meta.com/
^ permalink raw reply [flat|nested] 3+ messages in thread
end of thread, other threads:[~2026-06-26 14:24 UTC | newest]
Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-06-25 9:21 [PATCH] block: Fix dio->ref leak on integrity error in __blkdev_direct_IO() Wentao Liang
2026-06-26 8:58 ` Yang Xiuwei
2026-06-26 14:24 ` Keith Busch
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox