Linux Btrfs filesystem development
 help / color / mirror / Atom feed
From: David Sterba <dsterba@suse.cz>
To: Johannes Thumshirn <johannes.thumshirn@wdc.com>
Cc: linux-btrfs@vger.kernel.org, Naohiro Aota <naohiro.aota@wdc.com>,
	David Sterba <dsterba@suse.com>, Qu Wenruo <wqu@suse.com>
Subject: Re: [PATCH 2/4] btrfs: zoned: fix possible UAF in wait_eb_writebacks
Date: Mon, 14 Sep 2026 17:05:03 +0200	[thread overview]
Message-ID: <20260914150503.GI54722@twin.jikos.cz> (raw)
In-Reply-To: <20260914085248.347198-3-johannes.thumshirn@wdc.com>

On Mon, Sep 14, 2026 at 10:52:46AM +0200, Johannes Thumshirn wrote:
> wait_eb_writebacks() iterates the fs_info->buffer_tree xarray and waits
> for the writeback of these extent-buffers. Waiting for writeback needs
> to be done without the rcu_read_lock() held (because it can sleep) and
> thus the loop drops the rcu_read_lock() before calling into
> wait_on_extent_buffer_writeback(). But extent_buffers are freed through
> RCU, so if btrfs_release_extent_buffer_rcu() is scheduled while we're
> still waiting on the writeback, the extent_buffer will be freed causing
> a use-after-free.
> 
> Similar to what is done in find_extent_buffer_nolock(), get a reference
> to the extent_buffer before calling into
> wait_on_extent_buffer_writeback() so a sucessfull writeback does not
> free the extent_buffer while we still have a reference to it.
> 
> Fixes: 2dd7e7bc0282 ("btrfs: zoned: wait for extent buffer IOs before finishing a zone")
> Signed-off-by: Johannes Thumshirn <johannes.thumshirn@wdc.com>
> ---
>  fs/btrfs/zoned.c | 3 +++
>  1 file changed, 3 insertions(+)
> 
> diff --git a/fs/btrfs/zoned.c b/fs/btrfs/zoned.c
> index 12391063304b..c09e32904caf 100644
> --- a/fs/btrfs/zoned.c
> +++ b/fs/btrfs/zoned.c
> @@ -2511,8 +2511,11 @@ static void wait_eb_writebacks(struct btrfs_block_group *block_group)
>  			continue;
>  		if (eb->start >= end)
>  			break;
> +		if (!refcount_inc_not_zero(&eb->refs))

Please add a comment with the reason for that, several other uses of
inc-not-zero also have it. It makes it more visible and noticeable, also
a disappearing eb during some operation is disasterous.

Unrelated to this patch, the LLM reviews take the comments into account
and sometimes point out a pattern that is not followed in some case. It
can be either valid or a false positive, we can verify that. For humans
reading the code it's also useful as a drive-by knowledge.

> +			continue;
>  		rcu_read_unlock();
>  		wait_on_extent_buffer_writeback(eb);
> +		free_extent_buffer(eb);
>  		rcu_read_lock();
>  	}
>  	rcu_read_unlock();
> -- 
> 2.55.0
> 

  reply	other threads:[~2026-09-14 15:05 UTC|newest]

Thread overview: 9+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-14  8:52 [PATCH 0/4] btrfs: zoned: LLM inspired fixes Johannes Thumshirn
2026-09-14  8:52 ` [PATCH 1/4] btrfs: zoned: only change active zone counter on successful (de)activation Johannes Thumshirn
2026-09-14  8:52 ` [PATCH 2/4] btrfs: zoned: fix possible UAF in wait_eb_writebacks Johannes Thumshirn
2026-09-14 15:05   ` David Sterba [this message]
2026-10-02  7:32     ` Johannes Thumshirn
2026-09-14  8:52 ` [PATCH 3/4] btrfs: zoned: requeue block group if zone reset bails out Johannes Thumshirn
2026-09-14  8:52 ` [PATCH 4/4] btrfs: zoned: avoid underflow of bytes_zone_unusable Johannes Thumshirn
2026-09-14 15:08   ` David Sterba
2026-10-02  7:32     ` Johannes Thumshirn

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260914150503.GI54722@twin.jikos.cz \
    --to=dsterba@suse.cz \
    --cc=dsterba@suse.com \
    --cc=johannes.thumshirn@wdc.com \
    --cc=linux-btrfs@vger.kernel.org \
    --cc=naohiro.aota@wdc.com \
    --cc=wqu@suse.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox