Linux Btrfs filesystem development
 help / color / mirror / Atom feed
* [PATCH v4 0/3] btrfs: fix a UAF where btrfs_root::dirty_list is freed but still referred
@ 2026-10-08 22:13 Qu Wenruo
  2026-10-08 22:13 ` [PATCH v4 1/3] btrfs: protect dirty_cowonly_roots, switch_commits and root->dirty_list Qu Wenruo
                   ` (3 more replies)
  0 siblings, 4 replies; 6+ messages in thread
From: Qu Wenruo @ 2026-10-08 22:13 UTC (permalink / raw)
  To: linux-btrfs

[CHANGELOG]
v4:
- Also cleanup qgroup swapped blocks and dirty_log_pages
  Which are only released during switch_commit_roots().

v3:
- Use Yalagada's v2 fix as the final UAF fix
  The delayed list_del_init() call inside btrfs_put_root() is not
  safe as another racing ioctl can grab the quota root, extending
  its lifespan.

v2:
- Add extra patches to address Sashiko's comment
  * Make all root->dirty_list users to hold trans_lock
  * Release root->dirty_list from cur_trans->switch_commits during
    transaction cleanup

The first patch is to make lock consistent when accessing
btrfs_root::dirty_list, btrfs_fs_info::dirty_cowonly_roots and
btrfs_transaction::switch_commits.

Normally it's not a big deal as the existing lock-holding callers are
also holding a trans handle, thus they can not race with transaction
committing.
But the last commit will change the cleanup timing, and Sashiko is not
happy with that, so make it more consistent and shut Sashiko up.

The second patch is an existing bug exposed by Sashiko, which also
affects the last UAF fix.

The last one is the final UAF fix for the bug reported by syzbot.

Qu Wenruo (2):
  btrfs: protect dirty_cowonly_roots, switch_commits and
    root->dirty_list
  btrfs: prevent use-after-free in btrfs_transaction::switch_commits

Yalagada Pavan Kumar (1):
  btrfs: fix use-after-free on quota enable allocation failure

 fs/btrfs/disk-io.c     | 14 ++++++++++++++
 fs/btrfs/qgroup.c      |  7 +++++++
 fs/btrfs/transaction.c | 30 ++++++++++++++++++++++++++----
 3 files changed, 47 insertions(+), 4 deletions(-)

-- 
2.55.0


^ permalink raw reply	[flat|nested] 6+ messages in thread

end of thread, other threads:[~2026-10-09 21:00 UTC | newest]

Thread overview: 6+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-10-08 22:13 [PATCH v4 0/3] btrfs: fix a UAF where btrfs_root::dirty_list is freed but still referred Qu Wenruo
2026-10-08 22:13 ` [PATCH v4 1/3] btrfs: protect dirty_cowonly_roots, switch_commits and root->dirty_list Qu Wenruo
2026-10-08 22:13 ` [PATCH v4 2/3] btrfs: prevent use-after-free in btrfs_transaction::switch_commits Qu Wenruo
2026-10-08 22:13 ` [PATCH v4 3/3] btrfs: fix use-after-free on quota enable allocation failure Qu Wenruo
2026-10-09 16:30 ` [PATCH v4 0/3] btrfs: fix a UAF where btrfs_root::dirty_list is freed but still referred Boris Burkov
2026-10-09 21:00   ` Qu Wenruo

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox