diff options
| author | Guanghui Yang <3497809730@qq.com> | 2026-08-10 20:16:04 +0800 |
|---|---|---|
| committer | David Sterba <dsterba@suse.com> | 2026-09-02 00:01:38 +0200 |
| commit | c93b3c43df561cd9f592cee20ae058b563f9e5b6 (patch) | |
| tree | d8e742e701d59b5464ff1822f071980881415d25 /fs | |
| parent | 40fe154ba049a33f063c0058cd185d7f682088f3 (diff) | |
| download | linux-c93b3c43df561cd9f592cee20ae058b563f9e5b6.tar.gz linux-c93b3c43df561cd9f592cee20ae058b563f9e5b6.zip | |
btrfs: detach failed sprout device from transaction update list
When creating the first metadata chunk for a sprout filesystem,
create_chunk() adds the new device to the transaction dev_update_list
through device->post_commit_list.
If the subsequent system chunk creation fails, btrfs_init_new_device()
aborts the transaction and releases the device while post_commit_list is
still linked. This triggers a warning in btrfs_free_device() and leaves
the transaction list referencing freed memory.
Detach the device while holding chunk_mutex before releasing it.
Fixes: bbbf7243d62d ("btrfs: combine device update operations during transaction commit")
Assisted-by: Codex:gpt-5
Reviewed-by: Qu Wenruo <wqu@suse.com>
Signed-off-by: Guanghui Yang <3497809730@qq.com>
Reviewed-by: David Sterba <dsterba@suse.com>
Signed-off-by: David Sterba <dsterba@suse.com>
Diffstat (limited to 'fs')
| -rw-r--r-- | fs/btrfs/volumes.c | 2 |
1 files changed, 2 insertions, 0 deletions
diff --git a/fs/btrfs/volumes.c b/fs/btrfs/volumes.c index a8e27db8e4bc..cbb491c6d4be 100644 --- a/fs/btrfs/volumes.c +++ b/fs/btrfs/volumes.c @@ -3036,6 +3036,8 @@ error_sysfs: btrfs_sysfs_remove_device(device); mutex_lock(&fs_info->fs_devices->device_list_mutex); mutex_lock(&fs_info->chunk_mutex); + if (!list_empty(&device->post_commit_list)) + list_del_init(&device->post_commit_list); list_del_rcu(&device->dev_list); list_del(&device->dev_alloc_list); fs_info->fs_devices->num_devices--; |
