summaryrefslogtreecommitdiff
path: root/fs
diff options
context:
space:
mode:
authorGuanghui Yang <3497809730@qq.com>2026-08-10 20:16:04 +0800
committerDavid Sterba <dsterba@suse.com>2026-09-02 00:01:38 +0200
commitc93b3c43df561cd9f592cee20ae058b563f9e5b6 (patch)
treed8e742e701d59b5464ff1822f071980881415d25 /fs
parent40fe154ba049a33f063c0058cd185d7f682088f3 (diff)
downloadlinux-c93b3c43df561cd9f592cee20ae058b563f9e5b6.tar.gz
linux-c93b3c43df561cd9f592cee20ae058b563f9e5b6.zip
btrfs: detach failed sprout device from transaction update list
When creating the first metadata chunk for a sprout filesystem, create_chunk() adds the new device to the transaction dev_update_list through device->post_commit_list. If the subsequent system chunk creation fails, btrfs_init_new_device() aborts the transaction and releases the device while post_commit_list is still linked. This triggers a warning in btrfs_free_device() and leaves the transaction list referencing freed memory. Detach the device while holding chunk_mutex before releasing it. Fixes: bbbf7243d62d ("btrfs: combine device update operations during transaction commit") Assisted-by: Codex:gpt-5 Reviewed-by: Qu Wenruo <wqu@suse.com> Signed-off-by: Guanghui Yang <3497809730@qq.com> Reviewed-by: David Sterba <dsterba@suse.com> Signed-off-by: David Sterba <dsterba@suse.com>
Diffstat (limited to 'fs')
-rw-r--r--fs/btrfs/volumes.c2
1 files changed, 2 insertions, 0 deletions
diff --git a/fs/btrfs/volumes.c b/fs/btrfs/volumes.c
index a8e27db8e4bc..cbb491c6d4be 100644
--- a/fs/btrfs/volumes.c
+++ b/fs/btrfs/volumes.c
@@ -3036,6 +3036,8 @@ error_sysfs:
btrfs_sysfs_remove_device(device);
mutex_lock(&fs_info->fs_devices->device_list_mutex);
mutex_lock(&fs_info->chunk_mutex);
+ if (!list_empty(&device->post_commit_list))
+ list_del_init(&device->post_commit_list);
list_del_rcu(&device->dev_list);
list_del(&device->dev_alloc_list);
fs_info->fs_devices->num_devices--;