From nobody Sat Jul 25 02:58:28 2026 Received: from mail-pl1-f180.google.com (mail-pl1-f180.google.com [209.85.214.180]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 391223B3C1B for ; Mon, 20 Jul 2026 06:55:23 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.214.180 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784530524; cv=none; b=DoF4BMlQ9k6v/w/PcarMj1sWC9q2PcM0z7iwywRKGKUlo/tsZAdniqMfN9JegLIRdg3X1WtgqMVKUOC+SE047LdOIrKgus2LYrTH/Tx+fb72AAkIKz15X9n+CcuwnNrj8VofTRk2eI8Qf7ZS20z+CN2/aVqCc4YCBAUClYbaVDo= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784530524; c=relaxed/simple; bh=W7ZYjjP/Jvn9R55ZRQhyN+Oi0wv97eiYtUx5k3Wlk00=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version:Content-Type; b=YqKIvZeUNc2VjaIXhqkHfXDFCDqsyUMblOEVMQXGPPxbp0siPzrw4Hc5NdS5FytRmN8PuV2cSH+VqEr3i6aX43+f3B3EeQlYdr8BFyiCwpKMZV6bd7Wl+hVS4vKkeTgIxVz1hTMgJJ9/9Kc5Jx6MVDhYn5j4JyPqP68N0gIfBK4= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=S3+QFL7m; arc=none smtp.client-ip=209.85.214.180 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="S3+QFL7m" Received: by mail-pl1-f180.google.com with SMTP id d9443c01a7336-2caced6038eso46930035ad.0 for ; Sun, 19 Jul 2026 23:55:23 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1784530522; x=1785135322; darn=vger.kernel.org; h=content-transfer-encoding:content-type:mime-version:message-id:date :subject:cc:to:from:from:to:cc:subject:date:message-id:reply-to :content-type; bh=0p7pbJ0cZ8Uv0TYgYDuze87535aan42INqj1pm0xIVw=; b=S3+QFL7mZvZQhifKwWinssEyPKCFZm/7lBrV3cX8fPwsD4UV4tNfodsPeu5f4OReNW bRCQXPtQiy1wRIBgmYYugy753eTE3eyA2TwbZMhQ7r32c3hQsdURbdpMIDbCLtcKWp3F sX5ylfYzNks5MtxSRQwMOTzyWyKaKwfGNMAC4f636EG37ha1D6DDLy6kIyDrFJ9mp0Jh li9caawzXBZhV2EdG9nlXrRIzb/iminmiVVHDLriibb/+Ar8K5NkJQloGukUQExlHvxH b52i1ntfPVtmDruxix+yov9nSX30RNazaPQwth3+lIhI9PTVMf3oexx+RqBxvrECks2W 10fA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784530522; x=1785135322; h=content-transfer-encoding:content-type:mime-version:message-id:date :subject:cc:to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject :date:message-id:reply-to:content-type; bh=0p7pbJ0cZ8Uv0TYgYDuze87535aan42INqj1pm0xIVw=; b=ONOdGMZQ7ijwL8ukSm0QxkYVbgwQX8cVTnijW1pFCq4dBeDCSMIlY1Q0H25nEjTzpQ aTGoDotAkpGMrRhFy/bkiCse2YaTFLzI+6JyGzhMaTrmLvEFiPlbCODYeAlVRTlweQdZ GqByTJe5efXSbu4RLv9lVsX1ePMSXLfve2PjJnCP4m7sRqhsxi4NNG5CnTHUi9Dg1OJr RNai8yLQxMhHF2RTW7y+0b2rwGwGpCk+bNpRLJA3wTOwk5yERZydZJXhcYgEjwKPXmj7 fKKCXdFZnQSl2DFh8cxCssbWMj7YiQESUrxh3g2rdadGAVCU3JDyCB9Kacvb34HUZWx8 09nQ== X-Forwarded-Encrypted: i=1; AHgh+Rp0okkCDzmV5n5v+QorAyHTonH4k09JAR2hPeNa+NCDhI9R2LT9BpT4bEEeGNrNXg5funJzITr1gVO1M3Y=@vger.kernel.org X-Gm-Message-State: AOJu0YzNICFwuM/FzAh090gtiBG4w+hDJ1vjUCP2HlKy+LaN3YisAlzz VF0vqKjYHiNAdXsQRNmsAJHDvgHg9r4qeOoQPwLmK2J51Y5hCm7ELcp223IIniB6syM= X-Gm-Gg: AfdE7cnfP/lexAU+NRp+DiNoE0ULaQ955x+aQLsLWXDbp8GMmlf6aN29Z1JHWaeO6J2 gQZE7uV+oiuTEkpM52QNZcogTwPx2u8cwxFjyhm9Y0E1PNuZk5IBsZqDCRnPeP5EVkZpTgMqIik zMlAE5jtFum98LC0jdbzsZS2Cx4AvMfusz0iVKk4p2HX7Rw+eecaOs8NkgD9fYSxrfnnmXyQGKl dI5bCFr5G2c6VVSBHu9zFmJU5MQwEUMrN2IqHFiJryKnEMJ9j0h8/S5RU83AWbibY+7rTMdOWMb C10ZGrWIHR2UrMDkVri63WzaF222u07KX2QdXJTkt9SWAE0OwHQfpTV7tLJvZm9Gqm71dvTdgan vDIzBUm0SDggtK3DctrtVoYz3pL7Mv5YrLF5mqtjfK2H0BY8HimMh6ssuS2nqwUSMgGSXsXvkq2 HE+A== X-Received: by 2002:a17:903:2990:b0:2cc:bdb9:3c04 with SMTP id d9443c01a7336-2cf1f4b9bf1mr173789445ad.17.1784530522497; Sun, 19 Jul 2026 23:55:22 -0700 (PDT) Received: from tradnomic.. ([2601:646:8300:7570:f139:f861:e318:4f58]) by smtp.gmail.com with ESMTPSA id d9443c01a7336-2cf347119dfsm51034595ad.56.2026.07.19.23.55.21 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 19 Jul 2026 23:55:22 -0700 (PDT) From: rafad900 To: tytso@mit.edu, adilger.kernel@dilger.ca, libaokun@linux.alibaba.com, jack@suse.cz Cc: linux-ext4@vger.kernel.org, linux-kernel@vger.kernel.org, rafad900 Subject: [PATCH v2] ext4: fix race in ext4_mb_check_group_pa Date: Sun, 19 Jul 2026 23:54:59 -0700 Message-ID: <20260720065505.4019225-1-rafad900@gmail.com> X-Mailer: git-send-email 2.43.0 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable ext4_mb_check_group_pa drops the reference count on the previous best PA using atomic_dec(&cpa->pa_count) without holding the cpa->pa_lock. This causes race with ext4_discard_preallocations() which checks pa_count to decide whether a PA is still in use. If the pa_count is dec between the check and the discard, the PA can be freed while ext4_mb_check_group_pa() still holds a reference to it. Fix this by taking the cpa->pa_lock around the atomic_dec. Similar to pa->pa_lock which is taken outside of the ext4_mb_check_group_pa() function. The race was found while testing a change related to a Coccinelle warning from atomic_as_refcounter.cocci. The refcount conversion was found to be incorrect but the change had revealed the pre-exiting race condition. Signed-off-by: rafad900 --- Changes in v2: - Identified correct race location: ext4_mb_check_group_pa rather than ext4_mb_use_preallocated (the inode PA path already holds pa_lock correctly) - Dropped refcount_t conversion =E2=80=94 incompatible with PA lifecycle where count=3D0 represents an idle but reusable PA - Added spin_lock(&cpa->pa_lock) around atomic_dec in ext4_mb_check_group_pa fs/ext4/mballoc.c | 2 ++ 1 file changed, 2 insertions(+) diff --git a/fs/ext4/mballoc.c b/fs/ext4/mballoc.c index ed1bd00e11cd..c9a118ae4658 100644 --- a/fs/ext4/mballoc.c +++ b/fs/ext4/mballoc.c @@ -4833,7 +4833,9 @@ ext4_mb_check_group_pa(ext4_fsblk_t goal_block, return cpa; =20 /* drop the previous reference */ + spin_lock(&cpa->pa_lock); atomic_dec(&cpa->pa_count); + spin_unlock(&cpa->pa_lock); atomic_inc(&pa->pa_count); return pa; } --=20 2.43.0