From: Johannes Thumshirn <johannes.thumshirn@wdc.com>
To: David Sterba <dsterba@suse.cz>
Cc: linux-btrfs@vger.kernel.org, Naohiro Aota <naohiro.aota@wdc.com>,
David Sterba <dsterba@suse.com>, Qu Wenruo <wqu@suse.com>
Subject: Re: [PATCH 2/4] btrfs: zoned: fix possible UAF in wait_eb_writebacks
Date: Fri, 2 Oct 2026 09:32:52 +0200 [thread overview]
Message-ID: <ar9eCQDToxCdl5UP@mayhem.fritz.box> (raw)
In-Reply-To: <20260914150503.GI54722@twin.jikos.cz>
On Mon, Sep 14, 2026 at 05:05:03PM +0200, David Sterba wrote:
> On Mon, Sep 14, 2026 at 10:52:46AM +0200, Johannes Thumshirn wrote:
> > wait_eb_writebacks() iterates the fs_info->buffer_tree xarray and waits
> > for the writeback of these extent-buffers. Waiting for writeback needs
> > to be done without the rcu_read_lock() held (because it can sleep) and
> > thus the loop drops the rcu_read_lock() before calling into
> > wait_on_extent_buffer_writeback(). But extent_buffers are freed through
> > RCU, so if btrfs_release_extent_buffer_rcu() is scheduled while we're
> > still waiting on the writeback, the extent_buffer will be freed causing
> > a use-after-free.
> >
> > Similar to what is done in find_extent_buffer_nolock(), get a reference
> > to the extent_buffer before calling into
> > wait_on_extent_buffer_writeback() so a sucessfull writeback does not
> > free the extent_buffer while we still have a reference to it.
> >
> > Fixes: 2dd7e7bc0282 ("btrfs: zoned: wait for extent buffer IOs before finishing a zone")
> > Signed-off-by: Johannes Thumshirn <johannes.thumshirn@wdc.com>
> > ---
> > fs/btrfs/zoned.c | 3 +++
> > 1 file changed, 3 insertions(+)
> >
> > diff --git a/fs/btrfs/zoned.c b/fs/btrfs/zoned.c
> > index 12391063304b..c09e32904caf 100644
> > --- a/fs/btrfs/zoned.c
> > +++ b/fs/btrfs/zoned.c
> > @@ -2511,8 +2511,11 @@ static void wait_eb_writebacks(struct btrfs_block_group *block_group)
> > continue;
> > if (eb->start >= end)
> > break;
> > + if (!refcount_inc_not_zero(&eb->refs))
>
> Please add a comment with the reason for that, several other uses of
> inc-not-zero also have it. It makes it more visible and noticeable, also
> a disappearing eb during some operation is disasterous.
>
> Unrelated to this patch, the LLM reviews take the comments into account
> and sometimes point out a pattern that is not followed in some case. It
> can be either valid or a false positive, we can verify that. For humans
> reading the code it's also useful as a drive-by knowledge.
Done.
next prev parent reply other threads:[~2026-10-02 7:33 UTC|newest]
Thread overview: 9+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-14 8:52 [PATCH 0/4] btrfs: zoned: LLM inspired fixes Johannes Thumshirn
2026-09-14 8:52 ` [PATCH 1/4] btrfs: zoned: only change active zone counter on successful (de)activation Johannes Thumshirn
2026-09-14 8:52 ` [PATCH 2/4] btrfs: zoned: fix possible UAF in wait_eb_writebacks Johannes Thumshirn
2026-09-14 15:05 ` David Sterba
2026-10-02 7:32 ` Johannes Thumshirn [this message]
2026-09-14 8:52 ` [PATCH 3/4] btrfs: zoned: requeue block group if zone reset bails out Johannes Thumshirn
2026-09-14 8:52 ` [PATCH 4/4] btrfs: zoned: avoid underflow of bytes_zone_unusable Johannes Thumshirn
2026-09-14 15:08 ` David Sterba
2026-10-02 7:32 ` Johannes Thumshirn
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=ar9eCQDToxCdl5UP@mayhem.fritz.box \
--to=johannes.thumshirn@wdc.com \
--cc=dsterba@suse.com \
--cc=dsterba@suse.cz \
--cc=linux-btrfs@vger.kernel.org \
--cc=naohiro.aota@wdc.com \
--cc=wqu@suse.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox