From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 296DB5867C9 for ; Fri, 11 Sep 2026 20:00:36 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789156846; cv=none; b=Sc/mCRwlvxGof15aaJOmS5KrWUfSHE+N+NWkUj45XoxEkNwCx1GO/VAp78ym+Bde3ATHmOYbhtRtf2ufP+1juex94AJdFFFFa3P7UlGY7HFDUSvAtaT72SDg3VgwCrIiNdE+ypGPeKC5Op/177AhiyX7AIo9mo3AeQpswXpSgwA= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789156846; c=relaxed/simple; bh=A7Aad9Zxwo8+xadd5ZQWn+EdVgWM/gS1wZtPtSTRhvU=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=s+jI0q5b3BJXhBJrcn9kWEjlfYIIqYOQ1pNc6/6gMyiqm1ktvloC0W8oa7iOZA+V+QzkaCpsC2trQjviiZ67YULpW1+Y0nSlZhPmm3zOe5m1E4Rg2a/C6lC+Ih9Gl97ay0iN9spssj77yB+wBnmcjKTvqQBJ7MUmSCVYmgMjpP8= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=rapXGRZd; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="rapXGRZd" Received: by smtp.kernel.org (Postfix) with ESMTPSA id DE9DA1F00899; Fri, 11 Sep 2026 20:00:31 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1789156832; bh=xAp/uWzxuBmEmtOQPXvjFHAN0bRTWho9Lq/cv0mS8g8=; h=From:To:Cc:Subject:Date:Reply-To; b=rapXGRZdNWAb1SLhwAfx6vn9FoEH+UvU2VkMAOvS8uBP1ZvMCslTbIUIa/PjtIsQu fn89Z1V8Pn7ZY/vQLozQDtfzPwXAKrvEEBmqzDj+34zsIGKCNxcV36cd/IZovnJQ6J iIKOlGqWEbxX3DBIfY/fNdt81d9vBjWhf+Mw4otY= From: Greg Kroah-Hartman To: linux-cve-announce@vger.kernel.org Cc: Greg Kroah-Hartman Subject: CVE-2026-89647: ceph: do not repeat ceph_trim_dentries() if no progress possible Date: Fri, 11 Sep 2026 21:45:36 +0200 Message-ID: <2026091143-CVE-2026-89647-036a@gregkh> X-Mailer: git-send-email 2.55.0 Reply-To: , Precedence: bulk X-Mailing-List: linux-cve-announce@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-Developer-Signature: v=1; a=openpgp-sha256; l=7002; i=gregkh@linuxfoundation.org; h=from:subject:message-id; bh=dSJkbRLchHQof+J9/ku6YH/zffPSz5049+HNk380su8=; b=owGbwMvMwCRo6H6F97bub03G02pJDFlLIsvV/wVeXnpgzrTzc5cc2tHRaWMgYnT2G/f/uokl+ 9S5p/6W6IhlYRBkYpAVU2T5so3n6P6KQ4pehranYeawMoEMYeDiFICJsN9lmGfWe4tHeG7dzgKB 46Zywr5KossfxDLMj9i695P191QF+3taijsytVfGZG3yBQA= X-Developer-Key: i=gregkh@linuxfoundation.org; a=openpgp; fpr=F4B60CC5BF78C2214A313DCB3147D40DDB2DFB29 Content-Transfer-Encoding: 8bit From: Greg Kroah-Hartman Description =========== In the Linux kernel, the following vulnerability has been resolved: ceph: do not repeat ceph_trim_dentries() if no progress possible ceph_cap_reclaim_work() re-queues itself for as long as ceph_trim_dentries() returns -EAGAIN, which happens whenever a lease walk exhausts its `nr_to_scan` budget. This creates a busy loop that consumes CPU without making any progress when there is nothing to reclaim: with no cap pressure (`count==0`) and every scanned lease still valid, each pass runs the full scan budget down to zero and returns `-EAGAIN`, only to be queued again immediately. The dir-lease walk made this worse. When `expire_dir_lease` is `false` (i.e. we have no intention of reclaiming dir leases), __dir_lease_check() returned `TOUCH` for every valid lease. `TOUCH` moves the dentry to the tail of the list and resets `di->time` via __dentry_dir_lease_touch(), so a walk over N valid leases pointlessly rewrote the list, refreshed the timestamps (preventing them from ever aging out) and always drained `nr_to_scan`, guaranteeing the `-EAGAIN` requeue. Fix this in three steps: - Return `KEEP` instead of `TOUCH` when `expire_dir_lease` is `false`. If we are not going to reclaim the lease, leave it in place instead of churning the list and resetting its timestamp; the walk then terminates naturally (or via `STOP` at the first fresh lease). - Only return `-EAGAIN` from the first (dentry-lease) walk when something was actually freed. A full batch that frees nothing means retrying the same list immediately is futile; fall through to the dir-lease walk instead. - After both walks, bail out with success (0) when nothing was freed and there is no cap pressure (`count==0`). There is no reason to keep retrying when we are not over the cap limit and made no progress. Under real cap pressure (`count>0`) the reclaim path is unchanged and still retries via `-EAGAIN`. Without this patch, I saw 500 ceph_trim_dentries() calls per second on our web servers. This is very visible in `/proc/lock_stat` (5 minute capture): class name con-bounces contentions waittime-min waittime-max waittime-total waittime-avg acq-bounces acquisitions holdtime-min holdtime-max holdtime-total holdtime-avg &mdsc->dentry_list_lock: 126180 128218 0.04 8063.44 15986965.20 124.69 1573354 5296812 0.04 8291.28 74164526.48 14.00 ----------------------- &mdsc->dentry_list_lock 111736 [<000000007b11e319>] __ceph_dentry_dir_lease_touch+0x7c/0xa8 &mdsc->dentry_list_lock 2631 [<0000000050597999>] __dentry_leases_walk+0x64/0x2c8 &mdsc->dentry_list_lock 3878 [<00000000c0022f62>] __ceph_dentry_lease_touch+0x5c/0xa8 &mdsc->dentry_list_lock 9973 [<000000002f27cb6f>] __dentry_lease_unlist+0x50/0xa0 ----------------------- &mdsc->dentry_list_lock 123621 [<0000000050597999>] __dentry_leases_walk+0x64/0x2c8 &mdsc->dentry_list_lock 1822 [<000000007b11e319>] __ceph_dentry_dir_lease_touch+0x7c/0xa8 &mdsc->dentry_list_lock 2720 [<000000002f27cb6f>] __dentry_lease_unlist+0x50/0xa0 &mdsc->dentry_list_lock 55 [<00000000c0022f62>] __ceph_dentry_lease_touch+0x5c/0xa8 With this patch: class name con-bounces contentions waittime-min waittime-max waittime-total waittime-avg acq-bounces acquisitions holdtime-min holdtime-max holdtime-total holdtime-avg &mdsc->dentry_list_lock: 1203 1215 0.16 408.88 33082.88 27.23 4320501 7357389 0.04 500.64 1961578.00 0.27 ----------------------- &mdsc->dentry_list_lock 1029 [<000000003c9aea8a>] __ceph_dentry_dir_lease_touch+0x7c/0xa8 &mdsc->dentry_list_lock 169 [<000000002038c577>] __dentry_lease_unlist+0x50/0xa0 &mdsc->dentry_list_lock 16 [<00000000c991106d>] __ceph_dentry_lease_touch+0x5c/0xa8 &mdsc->dentry_list_lock 1 [<00000000612fe15f>] __dentry_leases_walk+0x64/0x2c8 ----------------------- &mdsc->dentry_list_lock 158 [<000000002038c577>] __dentry_lease_unlist+0x50/0xa0 &mdsc->dentry_list_lock 858 [<000000003c9aea8a>] __ceph_dentry_dir_lease_touch+0x7c/0xa8 &mdsc->dentry_list_lock 182 [<00000000612fe15f>] __dentry_leases_walk+0x64/0x2c8 &mdsc->dentry_list_lock 17 [<00000000c991106d>] __ceph_dentry_lease_touch+0x5c/0xa8 __dentry_leases_walk() is almost gone. The total wait time is reduced by a factor of 483. That will give some latency gains to ceph_readdir(). The Linux kernel CVE team has assigned CVE-2026-89647 to this issue. Affected and fixed versions =========================== Issue introduced in 5.1 with commit 37c4efc1ddf98ba8b234d116d863a9464445901e and fixed in 6.12.109 with commit 5a541eb401acb89d791da41189d7a79220164b93 Issue introduced in 5.1 with commit 37c4efc1ddf98ba8b234d116d863a9464445901e and fixed in 6.18.50 with commit 37d6edb2f03b29399a3a337fae78674de51e1695 Issue introduced in 5.1 with commit 37c4efc1ddf98ba8b234d116d863a9464445901e and fixed in 7.2.4 with commit 3d122b2feb1dd76bb5041bdea5e1e1b007d8d415 Issue introduced in 5.1 with commit 37c4efc1ddf98ba8b234d116d863a9464445901e and fixed in 7.3-rc1 with commit e7d7aa7b730178278109c41fa1b17b06873065d5 Please see https://www.kernel.org for a full list of currently supported kernel versions by the kernel community. Unaffected versions might change over time as fixes are backported to older supported kernel versions. The official CVE entry at https://cve.org/CVERecord/?id=CVE-2026-89647 will be updated if fixes are backported, please check that for the most up to date information about this issue. Affected files ============== The file(s) affected by this issue are: fs/ceph/dir.c Mitigation ========== The Linux kernel CVE team recommends that you update to the latest stable kernel version for this, and many other bugfixes. Individual changes are never tested alone, but rather are part of a larger kernel release. Cherry-picking individual commits is not recommended or supported by the Linux kernel community at all. If however, updating to the latest release is impossible, the individual changes to resolve this issue can be found at these commits: https://git.kernel.org/stable/c/5a541eb401acb89d791da41189d7a79220164b93 https://git.kernel.org/stable/c/37d6edb2f03b29399a3a337fae78674de51e1695 https://git.kernel.org/stable/c/3d122b2feb1dd76bb5041bdea5e1e1b007d8d415 https://git.kernel.org/stable/c/e7d7aa7b730178278109c41fa1b17b06873065d5