From nobody Fri Dec 19 17:14:24 2025 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-1.web.codeaurora.org [10.30.226.201]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 8B45723817D for ; Tue, 14 Oct 2025 07:32:54 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=10.30.226.201 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1760427174; cv=none; b=gkZ40a3lI7Yqrwjv5OOgmOZ/uA+cQVHDr8RMVEJap8LfzkY6XXw/8A9z7tE8AIQe2vb7fi6CA2B8kFDlhanJ7/adXoO0Rh/RMrqgNdsglW/qmfAdcy09D5B4bVPVI9X622J47gPfzWsuCDmWo0cUilYdMK7qXxQvilOAjtnT/sA= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1760427174; c=relaxed/simple; bh=zLFlHyMhc4frXkCjW8nh91AAlQjG+/KFAKkCfv1oTWA=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version:Content-Type; b=BYbJmOH7x3IzxOiEDQX+hXrivmjEvRSGztPknUz2vKRWcWRGTLaX/JLml2HCDNQTVGJX9HkdRsYwZ3z+P2Dtdd8l3eoGaDM7BMBIU58YEGbCNsAtzipUmQKBNuLDhxL4RNqSYu00WFCPOrK9J4w7Fc8QvOYp7H5Sobymj3cpKKY= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=l4dc5d1R; arc=none smtp.client-ip=10.30.226.201 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="l4dc5d1R" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 85C81C4CEE7; Tue, 14 Oct 2025 07:32:52 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=kernel.org; s=k20201202; t=1760427174; bh=zLFlHyMhc4frXkCjW8nh91AAlQjG+/KFAKkCfv1oTWA=; h=From:To:Cc:Subject:Date:From; b=l4dc5d1RMmxtxN/FkNNGPLTAoAr8CioZg769prRird3tLcGqTFnmg/gLXGCk4aIOT KQE8+zn9HvK7AsBoxwsjEcTDGZsJ7/VhzEwc/mOAcOkMXsa2ZPzBQLDQeEv2Fb95f0 ASte+CiN6PKoNJQ8itD9RlwKglvgAyLbV+6vChwHAa3h10DqKGuRTtvQoLBM0zDCc+ Hy0auRVMtQvNM3NpDTEr4T+ugfxdjxM64BkdOo2CAS/I/j9Ie0DGTUUhqlZeRhOhW4 rL8faB0XofuhaqNAi3u9XTZCgdcXtEzJYa0OAmCxISOVaSLfM8Llk5gpUqGpN+DgDm v2Rg0yv1t7yvA== From: Chao Yu To: jaegeuk@kernel.org Cc: linux-f2fs-devel@lists.sourceforge.net, linux-kernel@vger.kernel.org, Chao Yu , stable@kernel.org, Hong Yun Subject: [PATCH] f2fs: use global inline_xattr_slab instead of per-sb slab cache Date: Tue, 14 Oct 2025 15:32:48 +0800 Message-ID: <20251014073248.1769839-1-chao@kernel.org> X-Mailer: git-send-email 2.51.0.760.g7b8bcc2412-goog Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable As Hong Yun reported in mailing list: loop7: detected capacity change from 0 to 131072 Reported-by: Hong Yun Tested-by: Hong Yun ------------[ cut here ]------------ kmem_cache of name 'f2fs_xattr_entry-7:7' already exists WARNING: CPU: 0 PID: 24426 at mm/slab_common.c:110 kmem_cache_sanity_check = mm/slab_common.c:109 [inline] WARNING: CPU: 0 PID: 24426 at mm/slab_common.c:110 __kmem_cache_create_args= +0xa6/0x320 mm/slab_common.c:307 CPU: 0 UID: 0 PID: 24426 Comm: syz.7.1370 Not tainted 6.17.0-rc4 #1 PREEMPT= (full) Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.13.0-1ubuntu1= .1 04/01/2014 RIP: 0010:kmem_cache_sanity_check mm/slab_common.c:109 [inline] RIP: 0010:__kmem_cache_create_args+0xa6/0x320 mm/slab_common.c:307 Call Trace: =C2=A0__kmem_cache_create include/linux/slab.h:353 [inline] =C2=A0f2fs_kmem_cache_create fs/f2fs/f2fs.h:2943 [inline] =C2=A0f2fs_init_xattr_caches+0xa5/0xe0 fs/f2fs/xattr.c:843 =C2=A0f2fs_fill_super+0x1645/0x2620 fs/f2fs/super.c:4918 =C2=A0get_tree_bdev_flags+0x1fb/0x260 fs/super.c:1692 =C2=A0vfs_get_tree+0x43/0x140 fs/super.c:1815 =C2=A0do_new_mount+0x201/0x550 fs/namespace.c:3808 =C2=A0do_mount fs/namespace.c:4136 [inline] =C2=A0__do_sys_mount fs/namespace.c:4347 [inline] =C2=A0__se_sys_mount+0x298/0x2f0 fs/namespace.c:4324 =C2=A0do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline] =C2=A0do_syscall_64+0x8e/0x3a0 arch/x86/entry/syscall_64.c:94 =C2=A0entry_SYSCALL_64_after_hwframe+0x76/0x7e The bug can be reproduced w/ below scripts: - mount /dev/vdb /mnt1 - mount /dev/vdc /mnt2 - umount /mnt1 - mounnt /dev/vdb /mnt1 The reason is if we created two slab caches, named f2fs_xattr_entry-7:3 and f2fs_xattr_entry-7:7, and they have the same slab size. Actually, slab system will only create one slab cache core structure which has slab name of "f2fs_xattr_entry-7:3", and two slab caches share the same structure and cache address. So, if we destroy f2fs_xattr_entry-7:3 cache w/ cache address, it will decrease reference count of slab cache, rather than release slab cache entirely, since there is one more user has referenced the cache. Then, if we try to create slab cache w/ name "f2fs_xattr_entry-7:3" again, slab system will find that there is existed cache which has the same name and trigger the warning. Let's changes to use global inline_xattr_slab instead of per-sb slab cache for fixing. Fixes: a999150f4fe3 ("f2fs: use kmem_cache pool during inline xattr lookups= ") Cc: stable@kernel.org Reported-by: Hong Yun Tested-by: Hong Yun Signed-off-by: Chao Yu --- fs/f2fs/f2fs.h | 3 --- fs/f2fs/super.c | 17 ++++++++--------- fs/f2fs/xattr.c | 32 +++++++++++--------------------- fs/f2fs/xattr.h | 10 ++++++---- 4 files changed, 25 insertions(+), 37 deletions(-) diff --git a/fs/f2fs/f2fs.h b/fs/f2fs/f2fs.h index 839032a4da39..c589aed069d9 100644 --- a/fs/f2fs/f2fs.h +++ b/fs/f2fs/f2fs.h @@ -1892,9 +1892,6 @@ struct f2fs_sb_info { spinlock_t error_lock; /* protect errors/stop_reason array */ bool error_dirty; /* errors of sb is dirty */ =20 - struct kmem_cache *inline_xattr_slab; /* inline xattr entry */ - unsigned int inline_xattr_slab_size; /* default inline xattr slab size */ - /* For reclaimed segs statistics per each GC mode */ unsigned int gc_segment_mode; /* GC state for reclaimed segments */ unsigned int gc_reclaimed_segs[MAX_GC_MODE]; /* Reclaimed segs for each m= ode */ diff --git a/fs/f2fs/super.c b/fs/f2fs/super.c index 6e52e36c1f1a..2ae341768a39 100644 --- a/fs/f2fs/super.c +++ b/fs/f2fs/super.c @@ -2027,7 +2027,6 @@ static void f2fs_put_super(struct super_block *sb) kfree(sbi->raw_super); =20 f2fs_destroy_page_array_cache(sbi); - f2fs_destroy_xattr_caches(sbi); #ifdef CONFIG_QUOTA for (i =3D 0; i < MAXQUOTAS; i++) kfree(F2FS_OPTION(sbi).s_qf_names[i]); @@ -5016,13 +5015,9 @@ static int f2fs_fill_super(struct super_block *sb, s= truct fs_context *fc) if (err) goto free_iostat; =20 - /* init per sbi slab cache */ - err =3D f2fs_init_xattr_caches(sbi); - if (err) - goto free_percpu; err =3D f2fs_init_page_array_cache(sbi); if (err) - goto free_xattr_cache; + goto free_percpu; =20 /* get an inode for meta space */ sbi->meta_inode =3D f2fs_iget(sb, F2FS_META_INO(sbi)); @@ -5351,8 +5346,6 @@ static int f2fs_fill_super(struct super_block *sb, st= ruct fs_context *fc) sbi->meta_inode =3D NULL; free_page_array_cache: f2fs_destroy_page_array_cache(sbi); -free_xattr_cache: - f2fs_destroy_xattr_caches(sbi); free_percpu: destroy_percpu_info(sbi); free_iostat: @@ -5555,10 +5548,15 @@ static int __init init_f2fs_fs(void) err =3D f2fs_create_casefold_cache(); if (err) goto free_compress_cache; - err =3D register_filesystem(&f2fs_fs_type); + err =3D f2fs_init_xattr_cache(); if (err) goto free_casefold_cache; + err =3D register_filesystem(&f2fs_fs_type); + if (err) + goto free_xattr_cache; return 0; +free_xattr_cache: + f2fs_destroy_xattr_cache(); free_casefold_cache: f2fs_destroy_casefold_cache(); free_compress_cache: @@ -5599,6 +5597,7 @@ static int __init init_f2fs_fs(void) static void __exit exit_f2fs_fs(void) { unregister_filesystem(&f2fs_fs_type); + f2fs_destroy_xattr_cache(); f2fs_destroy_casefold_cache(); f2fs_destroy_compress_cache(); f2fs_destroy_compress_mempool(); diff --git a/fs/f2fs/xattr.c b/fs/f2fs/xattr.c index 58632a2b6613..9f20b67e90d1 100644 --- a/fs/f2fs/xattr.c +++ b/fs/f2fs/xattr.c @@ -23,11 +23,12 @@ #include "xattr.h" #include "segment.h" =20 +struct kmem_cache *inline_xattr_slab; static void *xattr_alloc(struct f2fs_sb_info *sbi, int size, bool *is_inli= ne) { - if (likely(size =3D=3D sbi->inline_xattr_slab_size)) { + if (likely(size =3D=3D DEFAULT_XATTR_SLAB_SIZE)) { *is_inline =3D true; - return f2fs_kmem_cache_alloc(sbi->inline_xattr_slab, + return f2fs_kmem_cache_alloc(inline_xattr_slab, GFP_F2FS_ZERO, false, sbi); } *is_inline =3D false; @@ -38,7 +39,7 @@ static void xattr_free(struct f2fs_sb_info *sbi, void *xa= ttr_addr, bool is_inline) { if (is_inline) - kmem_cache_free(sbi->inline_xattr_slab, xattr_addr); + kmem_cache_free(inline_xattr_slab, xattr_addr); else kfree(xattr_addr); } @@ -830,25 +831,14 @@ int f2fs_setxattr(struct inode *inode, int index, con= st char *name, return err; } =20 -int f2fs_init_xattr_caches(struct f2fs_sb_info *sbi) +int __init f2fs_init_xattr_cache(void) { - dev_t dev =3D sbi->sb->s_bdev->bd_dev; - char slab_name[32]; - - sprintf(slab_name, "f2fs_xattr_entry-%u:%u", MAJOR(dev), MINOR(dev)); - - sbi->inline_xattr_slab_size =3D F2FS_OPTION(sbi).inline_xattr_size * - sizeof(__le32) + XATTR_PADDING_SIZE; - - sbi->inline_xattr_slab =3D f2fs_kmem_cache_create(slab_name, - sbi->inline_xattr_slab_size); - if (!sbi->inline_xattr_slab) - return -ENOMEM; - - return 0; + inline_xattr_slab =3D f2fs_kmem_cache_create("f2fs_xattr_entry", + DEFAULT_XATTR_SLAB_SIZE); + return inline_xattr_slab ? 0 : -ENOMEM; } =20 -void f2fs_destroy_xattr_caches(struct f2fs_sb_info *sbi) +void f2fs_destroy_xattr_cache(void) { - kmem_cache_destroy(sbi->inline_xattr_slab); -} + kmem_cache_destroy(inline_xattr_slab); +} \ No newline at end of file diff --git a/fs/f2fs/xattr.h b/fs/f2fs/xattr.h index 4fc0b2305fbd..bce3d93e4755 100644 --- a/fs/f2fs/xattr.h +++ b/fs/f2fs/xattr.h @@ -89,6 +89,8 @@ struct f2fs_xattr_entry { F2FS_TOTAL_EXTRA_ATTR_SIZE / sizeof(__le32) - \ DEF_INLINE_RESERVED_SIZE - \ MIN_INLINE_DENTRY_SIZE / sizeof(__le32)) +#define DEFAULT_XATTR_SLAB_SIZE (DEFAULT_INLINE_XATTR_ADDRS * \ + sizeof(__le32) + XATTR_PADDING_SIZE) =20 /* * On-disk structure of f2fs_xattr @@ -132,8 +134,8 @@ int f2fs_setxattr(struct inode *, int, const char *, co= nst void *, int f2fs_getxattr(struct inode *, int, const char *, void *, size_t, struct folio *); ssize_t f2fs_listxattr(struct dentry *, char *, size_t); -int f2fs_init_xattr_caches(struct f2fs_sb_info *); -void f2fs_destroy_xattr_caches(struct f2fs_sb_info *); +int __init f2fs_init_xattr_cache(void); +void f2fs_destroy_xattr_cache(void); #else =20 #define f2fs_xattr_handlers NULL @@ -150,8 +152,8 @@ static inline int f2fs_getxattr(struct inode *inode, in= t index, { return -EOPNOTSUPP; } -static inline int f2fs_init_xattr_caches(struct f2fs_sb_info *sbi) { retur= n 0; } -static inline void f2fs_destroy_xattr_caches(struct f2fs_sb_info *sbi) { } +static inline int __init f2fs_init_xattr_cache(void) { return 0; } +static inline void f2fs_destroy_xattr_cache(void) { } #endif =20 #ifdef CONFIG_F2FS_FS_SECURITY --=20 2.49.0