diff options
| author | Guanghui Yang <3497809730@qq.com> | 2026-08-10 20:16:05 +0800 |
|---|---|---|
| committer | David Sterba <dsterba@suse.com> | 2026-09-02 00:01:40 +0200 |
| commit | e0b54613aabeb8e9da597f23b90c6a03d0981986 (patch) | |
| tree | b11aac549c1214a0a00c3568bc43bac144612d2a /fs | |
| parent | c93b3c43df561cd9f592cee20ae058b563f9e5b6 (diff) | |
| download | linux-e0b54613aabeb8e9da597f23b90c6a03d0981986.tar.gz linux-e0b54613aabeb8e9da597f23b90c6a03d0981986.zip | |
btrfs: restore active device pointers after failed sprout
btrfs_init_new_device() switches latest_dev and possibly s_bdev from the
seed device to the new sprout device before creating the first writable
chunks.
If chunk creation or the subsequent sprout setup fails, the error path
releases the new device without switching those pointers back.
btrfs_show_devname() can then dereference the freed latest_dev and crash.
Restore the active device pointers to the latest seed device before
removing and releasing the failed sprout device.
Fixes: b7cb29e666fe ("btrfs: update latest_dev when we create a sprout device")
Assisted-by: Codex:gpt-5
Reviewed-by: Qu Wenruo <wqu@suse.com>
Signed-off-by: Guanghui Yang <3497809730@qq.com>
Reviewed-by: David Sterba <dsterba@suse.com>
Signed-off-by: David Sterba <dsterba@suse.com>
Diffstat (limited to 'fs')
| -rw-r--r-- | fs/btrfs/volumes.c | 2 |
1 files changed, 2 insertions, 0 deletions
diff --git a/fs/btrfs/volumes.c b/fs/btrfs/volumes.c index cbb491c6d4be..427aa8e24fc3 100644 --- a/fs/btrfs/volumes.c +++ b/fs/btrfs/volumes.c @@ -3035,6 +3035,8 @@ int btrfs_init_new_device(struct btrfs_fs_info *fs_info, const char *device_path error_sysfs: btrfs_sysfs_remove_device(device); mutex_lock(&fs_info->fs_devices->device_list_mutex); + if (seeding_dev) + btrfs_assign_next_active_device(device, seed_devices->latest_dev); mutex_lock(&fs_info->chunk_mutex); if (!list_empty(&device->post_commit_list)) list_del_init(&device->post_commit_list); |
