* [PATCH 01/12] xfs: flag excessive delalloc rt extents as corruption
2026-10-05 5:55 [PATCHSET] xfs: LLM-inspired bug fixes, part 20 Darrick J. Wong
@ 2026-10-05 5:55 ` Darrick J. Wong
2026-10-07 13:03 ` Christoph Hellwig
2026-10-05 5:55 ` [PATCH 02/12] xfs: zero out di_metatype when removing the metadir file iflag Darrick J. Wong
` (11 subsequent siblings)
12 siblings, 1 reply; 26+ messages in thread
From: Darrick J. Wong @ 2026-10-05 5:55 UTC (permalink / raw)
To: cem, djwong; +Cc: stable, linux-xfs
From: Darrick J. Wong <djwong@kernel.org>
LOLLM observed that we should not allow repairs to proceed if the count
of delayed-allocation realtime extents exceeds the number of free rt
extents because we can't install negative numbers into the superblock.
It's unclear how we could end up in that state in real life, but let's
at least complain loudly about it if we ever encounter it.
Cc: <stable@vger.kernel.org> # v6.2
Fixes: e74331d6fa2c21 ("xfs: online checking of the free rt extent count")
Signed-off-by: "Darrick J. Wong" <djwong@kernel.org>
Assisted-by: LOLLM # finding obvious bugs
---
fs/xfs/scrub/fscounters.c | 7 +++++++
1 file changed, 7 insertions(+)
diff --git a/fs/xfs/scrub/fscounters.c b/fs/xfs/scrub/fscounters.c
index b3fb1b4227659d..eb1a095a0fa9b9 100644
--- a/fs/xfs/scrub/fscounters.c
+++ b/fs/xfs/scrub/fscounters.c
@@ -609,6 +609,13 @@ xchk_fscounters(
try_again = true;
}
+ if (!xfs_has_zoned(mp) && fsc->frextents < fsc->frextents_delayed) {
+ if (fsc->frozen)
+ xchk_set_incomplete(sc);
+ else
+ try_again = true;
+ }
+
if (!xfs_has_zoned(mp) &&
!xchk_fscount_within_range(sc, frextents,
&mp->m_free[XC_FREE_RTEXTENTS].count,
^ permalink raw reply related [flat|nested] 26+ messages in thread* Re: [PATCH 01/12] xfs: flag excessive delalloc rt extents as corruption
2026-10-05 5:55 ` [PATCH 01/12] xfs: flag excessive delalloc rt extents as corruption Darrick J. Wong
@ 2026-10-07 13:03 ` Christoph Hellwig
0 siblings, 0 replies; 26+ messages in thread
From: Christoph Hellwig @ 2026-10-07 13:03 UTC (permalink / raw)
To: Darrick J. Wong; +Cc: cem, stable, linux-xfs
On Sun, Oct 04, 2026 at 10:55:33PM -0700, Darrick J. Wong wrote:
> From: Darrick J. Wong <djwong@kernel.org>
>
> LOLLM observed that we should not allow repairs to proceed if the count
> of delayed-allocation realtime extents exceeds the number of free rt
> extents because we can't install negative numbers into the superblock.
> It's unclear how we could end up in that state in real life, but let's
> at least complain loudly about it if we ever encounter it.
Looks good:
Reviewed-by: Christoph Hellwig <hch@lst.de>
^ permalink raw reply [flat|nested] 26+ messages in thread
* [PATCH 02/12] xfs: zero out di_metatype when removing the metadir file iflag
2026-10-05 5:55 [PATCHSET] xfs: LLM-inspired bug fixes, part 20 Darrick J. Wong
2026-10-05 5:55 ` [PATCH 01/12] xfs: flag excessive delalloc rt extents as corruption Darrick J. Wong
@ 2026-10-05 5:55 ` Darrick J. Wong
2026-10-07 13:03 ` Christoph Hellwig
2026-10-05 5:56 ` [PATCH 03/12] xfs: forcibly reset quota timers when upgrading to bigtime during repair Darrick J. Wong
` (10 subsequent siblings)
12 siblings, 1 reply; 26+ messages in thread
From: Darrick J. Wong @ 2026-10-05 5:55 UTC (permalink / raw)
To: cem, djwong; +Cc: stable, linux-xfs
From: Darrick J. Wong <djwong@kernel.org>
LOLLM pointed out that we should zero di_metatype (fka di_onlink) when
we're clearing the METADIR inode flag because the file is no longer a
metadata file.
Cc: <stable@vger.kernel.org> # v6.13
Fixes: 7297fd0bebbd70 ("xfs: enforce metadata inode flag")
Signed-off-by: "Darrick J. Wong" <djwong@kernel.org>
Assisted-by: LOLLM # finding obvious bugs
---
fs/xfs/scrub/inode_repair.c | 4 +++-
1 file changed, 3 insertions(+), 1 deletion(-)
diff --git a/fs/xfs/scrub/inode_repair.c b/fs/xfs/scrub/inode_repair.c
index b047abd28bd341..5ecccc75af2500 100644
--- a/fs/xfs/scrub/inode_repair.c
+++ b/fs/xfs/scrub/inode_repair.c
@@ -579,8 +579,10 @@ xrep_dinode_flags(
fa = xfs_dinode_verify_metadir(sc->mp, dip, mode, flags,
flags2);
- if (fa)
+ if (fa) {
flags2 &= ~XFS_DIFLAG2_METADATA;
+ dip->di_metatype = cpu_to_be16(XFS_METAFILE_UNKNOWN);
+ }
}
dip->di_flags = cpu_to_be16(flags);
^ permalink raw reply related [flat|nested] 26+ messages in thread* [PATCH 03/12] xfs: forcibly reset quota timers when upgrading to bigtime during repair
2026-10-05 5:55 [PATCHSET] xfs: LLM-inspired bug fixes, part 20 Darrick J. Wong
2026-10-05 5:55 ` [PATCH 01/12] xfs: flag excessive delalloc rt extents as corruption Darrick J. Wong
2026-10-05 5:55 ` [PATCH 02/12] xfs: zero out di_metatype when removing the metadir file iflag Darrick J. Wong
@ 2026-10-05 5:56 ` Darrick J. Wong
2026-10-07 13:03 ` Christoph Hellwig
2026-10-05 5:56 ` [PATCH 04/12] xfs: don't pass iget failures up when marking ondisk inodes Darrick J. Wong
` (9 subsequent siblings)
12 siblings, 1 reply; 26+ messages in thread
From: Darrick J. Wong @ 2026-10-05 5:56 UTC (permalink / raw)
To: cem, djwong; +Cc: stable, linux-xfs
From: Darrick J. Wong <djwong@kernel.org>
If we decide to upgrade a dquot to BIGTIME as part of repairing it, we
should zero out the timer fields so that they are re-evaluated and reset
in bigtime format instead of letting through whatever was in there
before.
Cc: <stable@vger.kernel.org> # v6.8
Fixes: a5b91555403e3a ("xfs: repair quotas")
Signed-off-by: "Darrick J. Wong" <djwong@kernel.org>
Assisted-by: LOLLM # finding obvious bugs
---
fs/xfs/scrub/quota_repair.c | 17 ++++++++++++++++-
1 file changed, 16 insertions(+), 1 deletion(-)
diff --git a/fs/xfs/scrub/quota_repair.c b/fs/xfs/scrub/quota_repair.c
index 0afce258d5d2e6..a37fcd3fb6629b 100644
--- a/fs/xfs/scrub/quota_repair.c
+++ b/fs/xfs/scrub/quota_repair.c
@@ -343,6 +343,8 @@ xrep_quota_block(
bp->b_ops = &xfs_dquot_buf_ops;
for (i = 0; i < qi->qi_dqperchunk; i++, dqblk++) {
struct xfs_disk_dquot *ddq = &dqblk->dd_diskdq;
+ bool was_bigtime =
+ !!(ddq->d_type & XFS_DQTYPE_BIGTIME);
trace_xrep_disk_dquot(sc->mp, dqtype, id + i);
@@ -351,8 +353,21 @@ xrep_quota_block(
ddq->d_type = dqtype;
ddq->d_id = cpu_to_be32(id + i);
- if (xfs_has_bigtime(sc->mp) && ddq->d_id)
+ if (xfs_has_bigtime(sc->mp) && ddq->d_id) {
+ /*
+ * If something was broken with this dquot and it was a
+ * non-bigtime dquot, we'll grant everyone a fresh
+ * grace period by zeroing the timer field rather than
+ * try to interpret what might be garbage.
+ */
+ if (!was_bigtime) {
+ ddq->d_btimer = 0;
+ ddq->d_itimer = 0;
+ ddq->d_rtbtimer = 0;
+ }
+
ddq->d_type |= XFS_DQTYPE_BIGTIME;
+ }
xrep_quota_fix_timer(sc->mp, ddq, ddq->d_blk_softlimit,
ddq->d_bcount, &ddq->d_btimer,
^ permalink raw reply related [flat|nested] 26+ messages in thread* [PATCH 04/12] xfs: don't pass iget failures up when marking ondisk inodes
2026-10-05 5:55 [PATCHSET] xfs: LLM-inspired bug fixes, part 20 Darrick J. Wong
` (2 preceding siblings ...)
2026-10-05 5:56 ` [PATCH 03/12] xfs: forcibly reset quota timers when upgrading to bigtime during repair Darrick J. Wong
@ 2026-10-05 5:56 ` Darrick J. Wong
2026-10-07 13:03 ` Christoph Hellwig
2026-10-05 5:56 ` [PATCH 05/12] xfs: always reset incore attr fork buffer when resetting fork Darrick J. Wong
` (8 subsequent siblings)
12 siblings, 1 reply; 26+ messages in thread
From: Darrick J. Wong @ 2026-10-05 5:56 UTC (permalink / raw)
To: cem, djwong; +Cc: stable, linux-xfs
From: Darrick J. Wong <djwong@kernel.org>
LOLLM observes a couple of problems with this callsite -- an ENOMEM
return is completely ignored and a subsequent run through the loop body
obliterates the return value completely. Also, an error value
indicating that the list is corrupt can get passed up (thus terminating
the repair) even though we can handle corrupt lists. Fix the callsite
not to have these problems.
Cc: <stable@vger.kernel.org> # v6.10
Fixes: ab97f4b1c03075 ("xfs: repair AGI unlinked inode bucket lists")
Signed-off-by: "Darrick J. Wong" <djwong@kernel.org>
Assisted-by: LOLLM # finding obvious bugs
---
| 6 +++++-
1 file changed, 5 insertions(+), 1 deletion(-)
--git a/fs/xfs/scrub/agheader_repair.c b/fs/xfs/scrub/agheader_repair.c
index 2b0cd7d1ad0389..497701cf96940e 100644
--- a/fs/xfs/scrub/agheader_repair.c
+++ b/fs/xfs/scrub/agheader_repair.c
@@ -1348,8 +1348,12 @@ xrep_iunlink_mark_ondisk_rec(
*/
error = xchk_iget(ragi->sc, xfs_agino_to_ino(sc->sa.pag, agino),
&ip);
- if (error)
+ if (error == -ENOMEM)
+ return error;
+ if (error) {
+ error = 0;
continue;
+ }
trace_xrep_iunlink_reload_ondisk(ip);
^ permalink raw reply related [flat|nested] 26+ messages in thread* Re: [PATCH 04/12] xfs: don't pass iget failures up when marking ondisk inodes
2026-10-05 5:56 ` [PATCH 04/12] xfs: don't pass iget failures up when marking ondisk inodes Darrick J. Wong
@ 2026-10-07 13:03 ` Christoph Hellwig
0 siblings, 0 replies; 26+ messages in thread
From: Christoph Hellwig @ 2026-10-07 13:03 UTC (permalink / raw)
To: Darrick J. Wong; +Cc: cem, stable, linux-xfs
On Sun, Oct 04, 2026 at 10:56:20PM -0700, Darrick J. Wong wrote:
> From: Darrick J. Wong <djwong@kernel.org>
>
> LOLLM observes a couple of problems with this callsite -- an ENOMEM
> return is completely ignored and a subsequent run through the loop body
> obliterates the return value completely. Also, an error value
> indicating that the list is corrupt can get passed up (thus terminating
> the repair) even though we can handle corrupt lists. Fix the callsite
> not to have these problems.
Looks good:
Reviewed-by: Christoph Hellwig <hch@lst.de>
^ permalink raw reply [flat|nested] 26+ messages in thread
* [PATCH 05/12] xfs: always reset incore attr fork buffer when resetting fork
2026-10-05 5:55 [PATCHSET] xfs: LLM-inspired bug fixes, part 20 Darrick J. Wong
` (3 preceding siblings ...)
2026-10-05 5:56 ` [PATCH 04/12] xfs: don't pass iget failures up when marking ondisk inodes Darrick J. Wong
@ 2026-10-05 5:56 ` Darrick J. Wong
2026-10-07 13:04 ` Christoph Hellwig
2026-10-05 5:56 ` [PATCH 06/12] xfs: propagate errors while checking null siblings Darrick J. Wong
` (7 subsequent siblings)
12 siblings, 1 reply; 26+ messages in thread
From: Darrick J. Wong @ 2026-10-05 5:56 UTC (permalink / raw)
To: cem, djwong; +Cc: stable, linux-xfs
From: Darrick J. Wong <djwong@kernel.org>
LOLLM noticed that the local format attr fork verifier depends on
if_bytes being set correctly. However, the fork reset function doesn't
reset that correctly, which can cause post-repair verifier failures.
Fix that.
Cc: <stable@vger.kernel.org> # v6.10
Fixes: e5d7ce0364d8ee ("xfs: replay unlocked parent pointer updates that accrue during xattr repair")
Signed-off-by: "Darrick J. Wong" <djwong@kernel.org>
Assisted-by: LOLLM # finding obvious bugs
---
fs/xfs/scrub/attr_repair.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/fs/xfs/scrub/attr_repair.c b/fs/xfs/scrub/attr_repair.c
index 387ad909e20bb9..98a74066b24000 100644
--- a/fs/xfs/scrub/attr_repair.c
+++ b/fs/xfs/scrub/attr_repair.c
@@ -840,11 +840,11 @@ xrep_xattr_full_reset(
ASSERT(ifp->if_bytes == 0);
ifp->if_format = XFS_DINODE_FMT_LOCAL;
- xfs_idata_realloc(sc->tempip, sizeof(*hdr), XFS_ATTR_FORK);
}
/* Reinitialize the attr fork to an empty shortform structure. */
- hdr = ifp->if_data;
+ hdr = xfs_idata_realloc(sc->tempip,
+ (int64_t)sizeof(*hdr) - ifp->if_bytes, XFS_ATTR_FORK);
memset(hdr, 0, sizeof(*hdr));
hdr->totsize = cpu_to_be16(sizeof(*hdr));
xfs_trans_log_inode(sc->tp, sc->tempip, XFS_ILOG_CORE | XFS_ILOG_ADATA);
^ permalink raw reply related [flat|nested] 26+ messages in thread* [PATCH 06/12] xfs: propagate errors while checking null siblings
2026-10-05 5:55 [PATCHSET] xfs: LLM-inspired bug fixes, part 20 Darrick J. Wong
` (4 preceding siblings ...)
2026-10-05 5:56 ` [PATCH 05/12] xfs: always reset incore attr fork buffer when resetting fork Darrick J. Wong
@ 2026-10-05 5:56 ` Darrick J. Wong
2026-10-07 13:04 ` Christoph Hellwig
2026-10-05 5:57 ` [PATCH 07/12] xfs: don't try to scrub self-referential dirent in metapath checker Darrick J. Wong
` (6 subsequent siblings)
12 siblings, 1 reply; 26+ messages in thread
From: Darrick J. Wong @ 2026-10-05 5:56 UTC (permalink / raw)
To: cem, djwong; +Cc: stable, linux-xfs
From: Darrick J. Wong <djwong@kernel.org>
LOLLM observes that if xfs_da3_path_shift returns an error here, scrub
doesn't handle it the way that it handles most runtime errors. Instead,
it drops the error and keeps going, even though that's not how that's
supposed to work. Fix that by calling xchk_da_process_error to set
corruption flags and then jump out of the flow of execution.
Cc: <stable@vger.kernel.org> # v4.15
Fixes: 7c4a07a424c18d ("xfs: scrub directory/attribute btrees")
Signed-off-by: "Darrick J. Wong" <djwong@kernel.org>
Assisted-by: LOLLM # finding obvious bugs
---
fs/xfs/scrub/dabtree.c | 5 +++--
1 file changed, 3 insertions(+), 2 deletions(-)
diff --git a/fs/xfs/scrub/dabtree.c b/fs/xfs/scrub/dabtree.c
index 639228601cc6bc..bbf6ece58828ca 100644
--- a/fs/xfs/scrub/dabtree.c
+++ b/fs/xfs/scrub/dabtree.c
@@ -253,9 +253,10 @@ xchk_da_btree_block_check_sibling(
if (sibling == 0) {
error = xfs_da3_path_shift(ds->state, altpath, direction,
false, &retval);
- if (error == 0 && retval == 0)
+ if (!xchk_da_process_error(ds, level, &error))
+ goto out;
+ if (retval == 0)
xchk_da_set_corrupt(ds, level);
- error = 0;
goto out;
}
^ permalink raw reply related [flat|nested] 26+ messages in thread* Re: [PATCH 06/12] xfs: propagate errors while checking null siblings
2026-10-05 5:56 ` [PATCH 06/12] xfs: propagate errors while checking null siblings Darrick J. Wong
@ 2026-10-07 13:04 ` Christoph Hellwig
0 siblings, 0 replies; 26+ messages in thread
From: Christoph Hellwig @ 2026-10-07 13:04 UTC (permalink / raw)
To: Darrick J. Wong; +Cc: cem, stable, linux-xfs
On Sun, Oct 04, 2026 at 10:56:51PM -0700, Darrick J. Wong wrote:
> From: Darrick J. Wong <djwong@kernel.org>
>
> LOLLM observes that if xfs_da3_path_shift returns an error here, scrub
> doesn't handle it the way that it handles most runtime errors. Instead,
> it drops the error and keeps going, even though that's not how that's
> supposed to work. Fix that by calling xchk_da_process_error to set
> corruption flags and then jump out of the flow of execution.
Looks good:
Reviewed-by: Christoph Hellwig <hch@lst.de>
^ permalink raw reply [flat|nested] 26+ messages in thread
* [PATCH 07/12] xfs: don't try to scrub self-referential dirent in metapath checker
2026-10-05 5:55 [PATCHSET] xfs: LLM-inspired bug fixes, part 20 Darrick J. Wong
` (5 preceding siblings ...)
2026-10-05 5:56 ` [PATCH 06/12] xfs: propagate errors while checking null siblings Darrick J. Wong
@ 2026-10-05 5:57 ` Darrick J. Wong
2026-10-07 13:05 ` Christoph Hellwig
2026-10-05 5:57 ` [PATCH 08/12] xfs: don't allow sm_agno for non-group metadir path checking Darrick J. Wong
` (5 subsequent siblings)
12 siblings, 1 reply; 26+ messages in thread
From: Darrick J. Wong @ 2026-10-05 5:57 UTC (permalink / raw)
To: cem, djwong; +Cc: stable, linux-xfs
From: Darrick J. Wong <djwong@kernel.org>
LOLLM observes that the _ilock_both helper will loop forever trying to
double-lock the same inode if mpath->dp == sc->ip. Callers are not
supposed to call us with parent == child because that makes no sense.
Trigger an assertion, mark the scan incomplete, and return IO error
so that this fails noisily.
Cc: <stable@vger.kernel.org> # v6.13
Fixes: b3c03efa5972f0 ("xfs: check metadata directory file path connectivity")
Signed-off-by: "Darrick J. Wong" <djwong@kernel.org>
Assisted-by: LOLLM # finding obvious bugs
---
fs/xfs/scrub/metapath.c | 7 +++++++
1 file changed, 7 insertions(+)
diff --git a/fs/xfs/scrub/metapath.c b/fs/xfs/scrub/metapath.c
index e0ee7d9b903ff0..4cc0d37b529f97 100644
--- a/fs/xfs/scrub/metapath.c
+++ b/fs/xfs/scrub/metapath.c
@@ -319,6 +319,13 @@ xchk_metapath(
return 0;
}
+ /* Callers should not set the parent to the child. */
+ if (mpath->dp == sc->ip) {
+ ASSERT(mpath->dp != sc->ip);
+ xchk_set_incomplete(sc);
+ return -EIO;
+ }
+
xchk_trans_alloc_empty(sc);
error = xchk_metapath_ilock_both(mpath);
^ permalink raw reply related [flat|nested] 26+ messages in thread* [PATCH 08/12] xfs: don't allow sm_agno for non-group metadir path checking
2026-10-05 5:55 [PATCHSET] xfs: LLM-inspired bug fixes, part 20 Darrick J. Wong
` (6 preceding siblings ...)
2026-10-05 5:57 ` [PATCH 07/12] xfs: don't try to scrub self-referential dirent in metapath checker Darrick J. Wong
@ 2026-10-05 5:57 ` Darrick J. Wong
2026-10-07 13:05 ` Christoph Hellwig
2026-10-05 5:57 ` [PATCH 09/12] xfs: init inode number for tracepoint Darrick J. Wong
` (4 subsequent siblings)
12 siblings, 1 reply; 26+ messages in thread
From: Darrick J. Wong @ 2026-10-05 5:57 UTC (permalink / raw)
To: cem, djwong; +Cc: stable, linux-xfs
From: Darrick J. Wong <djwong@kernel.org>
LOLLM noticed that the metadata directory tree path checker accepts
non-zero values in the sm_agno field for non-group metadata. Make that
case return -EINVAL.
Cc: <stable@vger.kernel.org> # v6.13
Fixes: a74923333d9c3b ("xfs: scrub metadir paths for rtgroup metadata")
Signed-off-by: "Darrick J. Wong" <djwong@kernel.org>
Assisted-by: LOLLM # finding obvious bugs
---
fs/xfs/scrub/metapath.c | 6 ++++++
1 file changed, 6 insertions(+)
diff --git a/fs/xfs/scrub/metapath.c b/fs/xfs/scrub/metapath.c
index 4cc0d37b529f97..1488c8bcb52490 100644
--- a/fs/xfs/scrub/metapath.c
+++ b/fs/xfs/scrub/metapath.c
@@ -129,6 +129,8 @@ static int
xchk_setup_metapath_rtdir(
struct xfs_scrub *sc)
{
+ if (sc->sm->sm_agno)
+ return -EINVAL;
if (!sc->mp->m_rtdirip)
return -ENOENT;
@@ -176,6 +178,8 @@ xchk_setup_metapath_quotadir(
{
struct xfs_quotainfo *qi = sc->mp->m_quotainfo;
+ if (sc->sm->sm_agno)
+ return -EINVAL;
if (!qi || !qi->qi_dirip)
return -ENOENT;
@@ -192,6 +196,8 @@ xchk_setup_metapath_dqinode(
struct xfs_quotainfo *qi = sc->mp->m_quotainfo;
struct xfs_inode *ip = NULL;
+ if (sc->sm->sm_agno)
+ return -EINVAL;
if (!qi)
return -ENOENT;
^ permalink raw reply related [flat|nested] 26+ messages in thread* [PATCH 09/12] xfs: init inode number for tracepoint
2026-10-05 5:55 [PATCHSET] xfs: LLM-inspired bug fixes, part 20 Darrick J. Wong
` (7 preceding siblings ...)
2026-10-05 5:57 ` [PATCH 08/12] xfs: don't allow sm_agno for non-group metadir path checking Darrick J. Wong
@ 2026-10-05 5:57 ` Darrick J. Wong
2026-10-07 13:06 ` Christoph Hellwig
2026-10-05 5:57 ` [PATCH 10/12] xfs: release ip after unlinked list store failure Darrick J. Wong
` (3 subsequent siblings)
12 siblings, 1 reply; 26+ messages in thread
From: Darrick J. Wong @ 2026-10-05 5:57 UTC (permalink / raw)
To: cem, djwong; +Cc: stable, linux-xfs
From: Darrick J. Wong <djwong@kernel.org>
LOLLM complains that if the xchk_dir_lookup call fails, it won't set ino
to anything. ino is then passed into the tracepoint function, which
means that it reports random stack garbage. Set it to NULLFSINO instead
so that the circumstance is more obvious.
Cc: <stable@vger.kernel.org> # v6.13
Fixes: 0d2c636e489c11 ("xfs: repair metadata directory file path connectivity")
Signed-off-by: "Darrick J. Wong" <djwong@kernel.org>
Assisted-by: LOLLM # finding obvious bugs
---
fs/xfs/scrub/metapath.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/fs/xfs/scrub/metapath.c b/fs/xfs/scrub/metapath.c
index 1488c8bcb52490..eb987f8c994d25 100644
--- a/fs/xfs/scrub/metapath.c
+++ b/fs/xfs/scrub/metapath.c
@@ -522,7 +522,7 @@ xrep_metapath_try_link(
xfs_ino_t *alleged_child)
{
struct xfs_scrub *sc = mpath->sc;
- xfs_ino_t ino;
+ xfs_ino_t ino = NULLFSINO;
int error;
/* Allocate transaction, lock inodes, join to transaction. */
@@ -621,7 +621,7 @@ xrep_metapath_try_unlink(
{
struct xfs_scrub *sc = mpath->sc;
struct xfs_inode *ip = NULL;
- xfs_ino_t ino;
+ xfs_ino_t ino = NULLFSINO;
int error;
ASSERT(*alleged_child != I_INO(sc->ip));
^ permalink raw reply related [flat|nested] 26+ messages in thread* [PATCH 10/12] xfs: release ip after unlinked list store failure
2026-10-05 5:55 [PATCHSET] xfs: LLM-inspired bug fixes, part 20 Darrick J. Wong
` (8 preceding siblings ...)
2026-10-05 5:57 ` [PATCH 09/12] xfs: init inode number for tracepoint Darrick J. Wong
@ 2026-10-05 5:57 ` Darrick J. Wong
2026-10-07 13:06 ` Christoph Hellwig
2026-10-05 5:58 ` [PATCH 11/12] xfs: always zero the whole shortform header when zeroing attr fork Darrick J. Wong
` (2 subsequent siblings)
12 siblings, 1 reply; 26+ messages in thread
From: Darrick J. Wong @ 2026-10-05 5:57 UTC (permalink / raw)
To: cem, djwong; +Cc: stable, linux-xfs
From: Darrick J. Wong <djwong@kernel.org>
If, while processing an unlinked list we see an inode that has nonzero
link count, we fail to store the incore prev/next pointers, we should
release the incore inode instead of leaking it. This was in the llm
fixes branch but fell out for -rc7. Weird.
Cc: <stable@vger.kernel.org> # v7.2-rc7
Fixes: 0052633527158b ("xfs: don't ignore runtime errors in xrep_iunlink_reload_next")
Signed-off-by: "Darrick J. Wong" <djwong@kernel.org>
---
| 7 ++-----
1 file changed, 2 insertions(+), 5 deletions(-)
--git a/fs/xfs/scrub/agheader_repair.c b/fs/xfs/scrub/agheader_repair.c
index 497701cf96940e..32dd09ac3a55de 100644
--- a/fs/xfs/scrub/agheader_repair.c
+++ b/fs/xfs/scrub/agheader_repair.c
@@ -1104,12 +1104,9 @@ xrep_iunlink_reload_next(
if (VFS_I(ip)->i_nlink != 0) {
error = xrep_iunlink_store_next(ragi, agino, NULLAGINO);
if (error)
- return error;
+ goto rele;
error = xrep_iunlink_store_prev(ragi, agino, LINKED_AGINO);
- if (error)
- return error;
-
goto rele;
}
@@ -1123,7 +1120,7 @@ xrep_iunlink_reload_next(
*/
rele:
xchk_irele(sc, ip);
- return 0;
+ return error;
}
/*
^ permalink raw reply related [flat|nested] 26+ messages in thread* [PATCH 11/12] xfs: always zero the whole shortform header when zeroing attr fork
2026-10-05 5:55 [PATCHSET] xfs: LLM-inspired bug fixes, part 20 Darrick J. Wong
` (9 preceding siblings ...)
2026-10-05 5:57 ` [PATCH 10/12] xfs: release ip after unlinked list store failure Darrick J. Wong
@ 2026-10-05 5:58 ` Darrick J. Wong
2026-10-07 13:06 ` Christoph Hellwig
2026-10-05 5:58 ` [PATCH 12/12] xfs: always forget cached ACLs if the attr fork swap succeeds Darrick J. Wong
2026-10-08 13:32 ` [PATCHSET] xfs: LLM-inspired bug fixes, part 20 Carlos Maiolino
12 siblings, 1 reply; 26+ messages in thread
From: Darrick J. Wong @ 2026-10-05 5:58 UTC (permalink / raw)
To: cem, djwong; +Cc: stable, linux-xfs
From: Darrick J. Wong <djwong@kernel.org>
LOLLM noticed that xrep_xattr_fork_remove can decide to reset the attr
fork contents to an empty shortform header, but then fails to zero the
padding byte in the header. Fix that.
Cc: <stable@vger.kernel.org> # v6.10
Fixes: e47dcf113ae348 ("xfs: repair extended attributes")
Signed-off-by: "Darrick J. Wong" <djwong@kernel.org>
Assisted-by: LOLLM # finding obvious bugs
---
fs/xfs/scrub/attr_repair.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/fs/xfs/scrub/attr_repair.c b/fs/xfs/scrub/attr_repair.c
index 98a74066b24000..4a6124b592b525 100644
--- a/fs/xfs/scrub/attr_repair.c
+++ b/fs/xfs/scrub/attr_repair.c
@@ -970,7 +970,7 @@ xrep_xattr_fork_remove(
ifp->if_format = XFS_DINODE_FMT_LOCAL;
hdr = xfs_idata_realloc(ip, (int)sizeof(*hdr) - ifp->if_bytes,
XFS_ATTR_FORK);
- hdr->count = 0;
+ memset(hdr, 0, sizeof(*hdr));
hdr->totsize = cpu_to_be16(sizeof(*hdr));
xfs_trans_log_inode(sc->tp, ip,
XFS_ILOG_CORE | XFS_ILOG_ADATA);
^ permalink raw reply related [flat|nested] 26+ messages in thread* [PATCH 12/12] xfs: always forget cached ACLs if the attr fork swap succeeds
2026-10-05 5:55 [PATCHSET] xfs: LLM-inspired bug fixes, part 20 Darrick J. Wong
` (10 preceding siblings ...)
2026-10-05 5:58 ` [PATCH 11/12] xfs: always zero the whole shortform header when zeroing attr fork Darrick J. Wong
@ 2026-10-05 5:58 ` Darrick J. Wong
2026-10-07 13:07 ` Christoph Hellwig
2026-10-08 13:32 ` [PATCHSET] xfs: LLM-inspired bug fixes, part 20 Carlos Maiolino
12 siblings, 1 reply; 26+ messages in thread
From: Darrick J. Wong @ 2026-10-05 5:58 UTC (permalink / raw)
To: cem, djwong; +Cc: stable, linux-xfs
From: Darrick J. Wong <djwong@kernel.org>
LOLLM complains that xrep_xattr_rebuild_tree omits the xfs_forget_acl
call if the attr fork swap succeeds (and hence the acls might have
changed) but reaping the old attr fork fails. Fix it so that we always
purge the cached acls if the swap succeeds, even if subsequent steps do
not. This avoids some cache coherency problems with access controls.
Cc: <stable@vger.kernel.org> # v6.10
Fixes: e47dcf113ae348 ("xfs: repair extended attributes")
Signed-off-by: "Darrick J. Wong" <djwong@kernel.org>
Assisted-by: LOLLM # finding obvious bugs
---
fs/xfs/scrub/attr_repair.c | 6 +++---
1 file changed, 3 insertions(+), 3 deletions(-)
diff --git a/fs/xfs/scrub/attr_repair.c b/fs/xfs/scrub/attr_repair.c
index 4a6124b592b525..c7695d4cc8e7cc 100644
--- a/fs/xfs/scrub/attr_repair.c
+++ b/fs/xfs/scrub/attr_repair.c
@@ -1491,7 +1491,7 @@ xrep_xattr_rebuild_tree(
error = xrep_xattr_reset_tempfile_fork(sc);
if (error)
- return error;
+ goto forget_acls;
/*
* Roll to get a transaction without any inodes joined to it. Then we
@@ -1500,7 +1500,7 @@ xrep_xattr_rebuild_tree(
*/
error = xfs_trans_roll(&sc->tp);
if (error)
- return error;
+ goto forget_acls;
xrep_tempfile_iunlock(sc);
xrep_tempfile_iounlock(sc);
@@ -1509,7 +1509,7 @@ xrep_xattr_rebuild_tree(
/* Invalidate cached ACLs now that we've reloaded all the xattrs. */
xfs_forget_acl(VFS_I(sc->ip), SGI_ACL_FILE);
xfs_forget_acl(VFS_I(sc->ip), SGI_ACL_DEFAULT);
- return 0;
+ return error;
}
/* Tear down all the incore scan stuff we created. */
^ permalink raw reply related [flat|nested] 26+ messages in thread* Re: [PATCHSET] xfs: LLM-inspired bug fixes, part 20
2026-10-05 5:55 [PATCHSET] xfs: LLM-inspired bug fixes, part 20 Darrick J. Wong
` (11 preceding siblings ...)
2026-10-05 5:58 ` [PATCH 12/12] xfs: always forget cached ACLs if the attr fork swap succeeds Darrick J. Wong
@ 2026-10-08 13:32 ` Carlos Maiolino
12 siblings, 0 replies; 26+ messages in thread
From: Carlos Maiolino @ 2026-10-08 13:32 UTC (permalink / raw)
To: Darrick J. Wong; +Cc: stable, linux-xfs
On Sun, 04 Oct 2026 22:55:27 -0700, Darrick J. Wong wrote:
> Here's a twentieth batch of xfs fixes resulting from a LLaMma. Mwa
> mwa mwa...
>
> If you're going to start using this code, I strongly recommend pulling
> from my git trees, which are linked below.
>
> With a bit of luck, this should all go splendidly.
> Comments and questions are, as always, welcome.
>
> [...]
Applied to for-next, thanks!
[01/12] xfs: flag excessive delalloc rt extents as corruption
commit: 2b47be015a5e54f4a3d62afa636ba593de9b67f6
[02/12] xfs: zero out di_metatype when removing the metadir file iflag
commit: f5b4d8c8ce16675f77c25a4ff06caaa9a2739f31
[03/12] xfs: forcibly reset quota timers when upgrading to bigtime during repair
commit: 780212c8d8105eadb5f56b4c7aafb94937755582
[04/12] xfs: don't pass iget failures up when marking ondisk inodes
commit: 7f5e8bf335e5e257fb82cf5b3521980ded60e863
[05/12] xfs: always reset incore attr fork buffer when resetting fork
commit: 71cb13685e72a3c5d118732559c727a0c9090b7f
[06/12] xfs: propagate errors while checking null siblings
commit: e5bde75a816b3549942f4b09a8bf09006b7ea9de
[07/12] xfs: don't try to scrub self-referential dirent in metapath checker
commit: 1e7337a3ecebab1bb2ba02187d88b94e5146e4f0
[08/12] xfs: don't allow sm_agno for non-group metadir path checking
commit: 20c5a56bc4f2329872d21561e4a2d4b8576004c9
[09/12] xfs: init inode number for tracepoint
commit: e98643f794d0d7a7fde8b29276d74e09fa0d5d19
[10/12] xfs: release ip after unlinked list store failure
commit: 9a263723d7c9ab0615bab3f5cc145d3d24454a5c
[11/12] xfs: always zero the whole shortform header when zeroing attr fork
commit: 52aa50cea408e27454d206cccecbe4f694a6c1e1
[12/12] xfs: always forget cached ACLs if the attr fork swap succeeds
commit: 41ee987f53785b9443388a756912b1a0fe3c9592
Best regards,
--
Carlos Maiolino <cem@kernel.org>
^ permalink raw reply [flat|nested] 26+ messages in thread