From: Qu Wenruo <wqu@suse.com>
To: fdmanana@kernel.org, linux-btrfs@vger.kernel.org
Subject: Re: [PATCH v2] btrfs: fix invalid pointer dereference in __btrfs_run_delayed_refs()
Date: Fri, 22 May 2026 07:43:00 +0930 [thread overview]
Message-ID: <bb91f646-6ccd-427c-b6aa-4e945dc39f07@suse.com> (raw)
In-Reply-To: <f81a69124ba44ff062f13e6287be7f0f5cf56072.1779375954.git.fdmanana@suse.com>
在 2026/5/22 00:37, fdmanana@kernel.org 写道:
> From: Filipe Manana <fdmanana@suse.com>
>
> In the beginning of the loop, we try to obtain a locked delayed ref head,
> if 'locked_ref' is currently NULL, by calling btrfs_select_ref_head(),
> which can return an error pointer. If the error pointer is -EAGAIN we do
> a continue and go back to the beginning of the loop, which will not try
> again to call btrfs_select_ref_head() since 'locked_ref' is no longer
> NULL but it's ERR_PTR(-EAGAIN), and then we do:
>
> spin_lock(&locked_ref->lock);
>
> against a ERR_PTR(-EAGAIN) value, generating an invalid pointer
> dereference.
>
> Fix this by ensuring that 'locked_ref' is set to NULL when
> btrfs_select_ref_head() returns ERR_PTR(-EAGAIN) and incrementing 'count'
> as well, to prevent infinite looping. We do this by doing a goto to the
> bottom of the loop that already sets 'locked_ref' to NULL and does a
> cond_resched(), with an increment to 'count' right before the goto.
> These measures were in place before the refactoring in commit 0110a4c43451
> ("btrfs: refactor __btrfs_run_delayed_refs loop") but were unintentionally
> lost afterwards.
>
> Reported-by: Dan Carpenter <error27@gmail.com>
> Link: https://lore.kernel.org/linux-btrfs/ag8ARRwykv8bpJ87@stanley.mountain/
> Fixes: 0110a4c43451 ("btrfs: refactor __btrfs_run_delayed_refs loop")
> Signed-off-by: Filipe Manana <fdmanana@suse.com>
Reviewed-by: Qu Wenruo <wqu@suse.com>
Thanks,
Qu
> ---
>
> V2: Use a goto approach to jump to the bottom of the loop, that already
> sets locked_ref to NULL and does a cond_resched() too.
>
> fs/btrfs/extent-tree.c | 5 +++--
> 1 file changed, 3 insertions(+), 2 deletions(-)
>
> diff --git a/fs/btrfs/extent-tree.c b/fs/btrfs/extent-tree.c
> index ecc1acb1e340..6030cdbdb742 100644
> --- a/fs/btrfs/extent-tree.c
> +++ b/fs/btrfs/extent-tree.c
> @@ -2108,7 +2108,8 @@ static noinline int __btrfs_run_delayed_refs(struct btrfs_trans_handle *trans,
> locked_ref = btrfs_select_ref_head(fs_info, delayed_refs);
> if (IS_ERR_OR_NULL(locked_ref)) {
> if (PTR_ERR(locked_ref) == -EAGAIN) {
> - continue;
> + count++;
> + goto again;
> } else {
> break;
> }
> @@ -2156,7 +2157,7 @@ static noinline int __btrfs_run_delayed_refs(struct btrfs_trans_handle *trans,
> * Either success case or btrfs_run_delayed_refs_for_head
> * returned -EAGAIN, meaning we need to select another head
> */
> -
> +again:
> locked_ref = NULL;
> cond_resched();
> } while ((min_bytes != U64_MAX && bytes_processed < min_bytes) ||
prev parent reply other threads:[~2026-05-21 22:13 UTC|newest]
Thread overview: 4+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-05-21 14:41 [PATCH] btrfs: fix invalid pointer dereference in __btrfs_run_delayed_refs() fdmanana
2026-05-21 15:07 ` [PATCH v2] " fdmanana
2026-05-21 19:53 ` Boris Burkov
2026-05-21 22:13 ` Qu Wenruo [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=bb91f646-6ccd-427c-b6aa-4e945dc39f07@suse.com \
--to=wqu@suse.com \
--cc=fdmanana@kernel.org \
--cc=linux-btrfs@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox