Linux RAID subsystem development
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Matthew Wilcox (Oracle)" <willy@infradead.org>
Cc: yukuai@fygo.io, linux-raid@vger.kernel.org
Subject: Re: [PATCH 3/3] md: Remove the last use of page_buffers()
Date: Mon, 14 Sep 2026 04:29:58 +0000	[thread overview]
Message-ID: <20260914042959.151B71F000FF@smtp.kernel.org> (raw)
In-Reply-To: <20260914041830.2072626-3-willy@infradead.org>

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:

Pre-existing issues:
- [High] Memory leak of bitmap pages in `free_buffers()` when unmapping an internal block-device bitmap or on error paths for file-backed bitmaps.
--

commit 5c27b3beb1da589c8d8b3b4113d43873e56ed7da
Author: Matthew Wilcox (Oracle) <willy@infradead.org>

md: Remove the last use of page_buffers()

This commit converts the page to a folio in write_file_page() and uses
folio_buffers() instead of page_buffers(). This change prepares the
md-bitmap codebase for a later conversion from pages to folios.

> diff --git a/drivers/md/md-bitmap.c b/drivers/md/md-bitmap.c
> index 7b42db87d536d..c2528220c406d 100644
> --- a/drivers/md/md-bitmap.c
> +++ b/drivers/md/md-bitmap.c
> @@ -516,7 +516,8 @@ static void end_bitmap_write(struct bio *bio)
>  
>  static void write_file_page(struct bitmap *bitmap, struct page *page, int wait)
>  {
> -	struct buffer_head *bh = page_buffers(page);
> +	struct folio *folio = page_folio(page);
> +	struct buffer_head *bh = folio_buffers(folio);

[Severity: High]
This is a pre-existing issue, but since this code is being converted to use
folios, does free_buffers() leak the folio when unmapping an internal
block-device bitmap or on error paths for file-backed bitmaps?

In md_bitmap_storage_alloc(), memory for store->filemap is allocated using
alloc_page(), which sets the baseline refcount to 1. For internal
block-device bitmaps, the pages are read using read_sb_page() which does
not attach buffer_head structures or set the folio private flag.

During array teardown, md_bitmap_file_unmap() iterates over store->filemap
and calls free_buffers():

static void free_buffers(struct page *page)
{
	struct folio *folio = page_folio(page);
	struct buffer_head *bh = folio_detach_private(folio);

	if (!bh)
		return;
...
	folio_put(folio);
}

Since folio_detach_private() returns NULL here, the early return skips the
final folio_put(). Over time, this could accumulate to megabytes of leaked
memory if an administrator repeatedly starts and stops md arrays with
internal bitmaps.

Could this early return be updated to ensure the folio reference is properly
dropped even when there are no buffers attached?

>  
>  	while (bh && bh->b_blocknr) {
>  		atomic_inc(&bitmap->pending_writes);

[ ... ]

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260913-remove-pg_private-v4-0-848550f7574e@nvidia.com?part=3

  reply	other threads:[~2026-09-14  4:29 UTC|newest]

Thread overview: 22+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-14  2:23 [PATCH v4 00/16] Remove PG_private by using page/folio->private checks instead Zi Yan
2026-09-14  2:24 ` [PATCH v4 13/16] md/md-bitmap: replace PagePrivate() with page_private() Zi Yan
2026-09-14  2:24 ` [PATCH v4 14/16] buffer: replace page_buffer() with page_private() and delete it Zi Yan
2026-09-14  3:39 ` [PATCH v4 00/16] Remove PG_private by using page/folio->private checks instead Andrew Morton
2026-09-15 17:16   ` Zi Yan
2026-09-14  4:18 ` [PATCH 1/3] md: Use folio_alloc_buffers() Matthew Wilcox (Oracle)
2026-09-14  4:27   ` sashiko-bot
2026-09-14 13:12   ` David Hildenbrand (Arm)
2026-09-14 13:17     ` Matthew Wilcox
2026-09-14 13:20       ` David Hildenbrand (Arm)
2026-09-14 14:36         ` Zi Yan
2026-09-14  4:18 ` [PATCH 2/3] md: Use folio APIs in free_page() Matthew Wilcox (Oracle)
2026-09-14  4:31   ` sashiko-bot
2026-09-14 16:21     ` Matthew Wilcox
2026-09-14 16:25       ` Zi Yan
2026-09-14 13:13   ` David Hildenbrand (Arm)
2026-09-14  4:18 ` [PATCH 3/3] md: Remove the last use of page_buffers() Matthew Wilcox (Oracle)
2026-09-14  4:29   ` sashiko-bot [this message]
2026-09-14 13:14   ` David Hildenbrand (Arm)
2026-09-14  4:21 ` [PATCH v4 00/16] Remove PG_private by using page/folio->private checks instead Matthew Wilcox
2026-09-14 13:10   ` David Hildenbrand (Arm)
2026-09-14 15:30 ` [f2fs-dev] " patchwork-bot+f2fs

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260914042959.151B71F000FF@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=linux-raid@vger.kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    --cc=willy@infradead.org \
    --cc=yukuai@fygo.io \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox