Linux Btrfs filesystem development
 help / color / mirror / Atom feed
From: Qu Wenruo <wqu@suse.com>
To: fdmanana@kernel.org, linux-btrfs@vger.kernel.org
Subject: Re: [PATCH v2] btrfs: fix invalid pointer dereference in __btrfs_run_delayed_refs()
Date: Fri, 22 May 2026 07:43:00 +0930	[thread overview]
Message-ID: <bb91f646-6ccd-427c-b6aa-4e945dc39f07@suse.com> (raw)
In-Reply-To: <f81a69124ba44ff062f13e6287be7f0f5cf56072.1779375954.git.fdmanana@suse.com>



在 2026/5/22 00:37, fdmanana@kernel.org 写道:
> From: Filipe Manana <fdmanana@suse.com>
> 
> In the beginning of the loop, we try to obtain a locked delayed ref head,
> if 'locked_ref' is currently NULL, by calling btrfs_select_ref_head(),
> which can return an error pointer. If the error pointer is -EAGAIN we do
> a continue and go back to the beginning of the loop, which will not try
> again to call btrfs_select_ref_head() since 'locked_ref' is no longer
> NULL but it's ERR_PTR(-EAGAIN), and then we do:
> 
>     spin_lock(&locked_ref->lock);
> 
> against a ERR_PTR(-EAGAIN) value, generating an invalid pointer
> dereference.
> 
> Fix this by ensuring that 'locked_ref' is set to NULL when
> btrfs_select_ref_head() returns ERR_PTR(-EAGAIN) and incrementing 'count'
> as well, to prevent infinite looping. We do this by doing a goto to the
> bottom of the loop that already sets 'locked_ref' to NULL and does a
> cond_resched(), with an increment to 'count' right before the goto.
> These measures were in place before the refactoring in commit 0110a4c43451
> ("btrfs: refactor __btrfs_run_delayed_refs loop") but were unintentionally
> lost afterwards.
> 
> Reported-by: Dan Carpenter <error27@gmail.com>
> Link: https://lore.kernel.org/linux-btrfs/ag8ARRwykv8bpJ87@stanley.mountain/
> Fixes: 0110a4c43451 ("btrfs: refactor __btrfs_run_delayed_refs loop")
> Signed-off-by: Filipe Manana <fdmanana@suse.com>

Reviewed-by: Qu Wenruo <wqu@suse.com>

Thanks,
Qu

> ---
> 
> V2: Use a goto approach to jump to the bottom of the loop, that already
>      sets locked_ref to NULL and does a cond_resched() too.
> 
>   fs/btrfs/extent-tree.c | 5 +++--
>   1 file changed, 3 insertions(+), 2 deletions(-)
> 
> diff --git a/fs/btrfs/extent-tree.c b/fs/btrfs/extent-tree.c
> index ecc1acb1e340..6030cdbdb742 100644
> --- a/fs/btrfs/extent-tree.c
> +++ b/fs/btrfs/extent-tree.c
> @@ -2108,7 +2108,8 @@ static noinline int __btrfs_run_delayed_refs(struct btrfs_trans_handle *trans,
>   			locked_ref = btrfs_select_ref_head(fs_info, delayed_refs);
>   			if (IS_ERR_OR_NULL(locked_ref)) {
>   				if (PTR_ERR(locked_ref) == -EAGAIN) {
> -					continue;
> +					count++;
> +					goto again;
>   				} else {
>   					break;
>   				}
> @@ -2156,7 +2157,7 @@ static noinline int __btrfs_run_delayed_refs(struct btrfs_trans_handle *trans,
>   		 * Either success case or btrfs_run_delayed_refs_for_head
>   		 * returned -EAGAIN, meaning we need to select another head
>   		 */
> -
> +again:
>   		locked_ref = NULL;
>   		cond_resched();
>   	} while ((min_bytes != U64_MAX && bytes_processed < min_bytes) ||


      parent reply	other threads:[~2026-05-21 22:13 UTC|newest]

Thread overview: 4+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-05-21 14:41 [PATCH] btrfs: fix invalid pointer dereference in __btrfs_run_delayed_refs() fdmanana
2026-05-21 15:07 ` [PATCH v2] " fdmanana
2026-05-21 19:53   ` Boris Burkov
2026-05-21 22:13   ` Qu Wenruo [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=bb91f646-6ccd-427c-b6aa-4e945dc39f07@suse.com \
    --to=wqu@suse.com \
    --cc=fdmanana@kernel.org \
    --cc=linux-btrfs@vger.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox