From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from out-189.mta0.migadu.com (out-189.mta0.migadu.com [91.218.175.189]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 303BF2D6409 for ; Mon, 27 Jul 2026 13:30:28 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=91.218.175.189 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785159033; cv=none; b=QXMLJlyEgm+Y3iUA33x6RtRC+Dndd9y9Y0LXCjzlFSJnqnhlfURNfVXSmf++/Y+RUk7nfrAEgXUTsKUU3QYF7YB+Iw/5YbrrMQgzJgyrsea64SN/320nNe7n4qjU2P11wVnl7Qq1CKAwGHrE0qwViA3f631uOKdaqoa9xTZeupI= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785159033; c=relaxed/simple; bh=tw8mWDAdFoS6B5c1gd9DQWUBypy+ZmSSsSwcfuQk42A=; h=Message-ID:Date:MIME-Version:Subject:To:Cc:References:From: In-Reply-To:Content-Type; b=o5RlnPzcyqfPsXPntxtnQSiBruqyuPrRpdY4ulfLKf8YI16SZ8U3VtG5/k1GFdMsVmvZ072/v1AwPb2MrqKxbMd7g/OYQrZC45fuum4cQzYq+Uc0WmgZc/7QXLRzBpuc7z+EFLEc+iz2T36SoCMMdqI7UKaaVDMC+8Tj/N8sRw4= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=chenxiaosong.com; spf=pass smtp.mailfrom=chenxiaosong.com; dkim=pass (2048-bit key) header.d=chenxiaosong.com header.i=@chenxiaosong.com header.b=UoP2/gY8; arc=none smtp.client-ip=91.218.175.189 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=chenxiaosong.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=chenxiaosong.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=chenxiaosong.com header.i=@chenxiaosong.com header.b="UoP2/gY8" Message-ID: <02e13173-b4b1-4de2-a58a-b5627799b94d@chenxiaosong.com> DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=chenxiaosong.com; s=key1; t=1785159026; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=Cn3U9SUi7cQpdQpK0cbUf6QZl6pCgdH3mtPucanWDXI=; b=UoP2/gY8Olm4YKhbfadDIBYSxGE/Ah3xJauYLJ80LffJg+HZxcv2+suW4Lem1gAABnV7Ru ExlwjG+uTvlLZLPoH6+6NjDHhs25F82BbEIKCFvkcWar17fU5SK2gF9SqPoGDB7cqjirsB V1DuBr/FKYaBStS9/vOovTBOrk4fT6NnpxdJRiNKRHLJ3vbifFWlfJSeW3hegafOiU0lv7 X7KyVTWDPFzRcf/zNIxUeG4u06sLZ3TqC2v7mS3cbciTDCWEnPJEBU5YRr4vpIRBve2Zj0 R3sjkgEq1YhOEap2ZGL7mzNf1bzXsg4JtRfbY7zxhiubl+ECuIXQ/TGkOunbYg== Date: Mon, 27 Jul 2026 21:30:25 +0800 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Subject: Re: [PATCH] smb: client: free partially allocated transform folio queue To: Yichong Chen , Steve French Cc: Paulo Alcantara , Ronnie Sahlberg , Shyam Prasad N , Tom Talpey , Bharath SM , linux-cifs@vger.kernel.org, samba-technical@lists.samba.org, linux-kernel@vger.kernel.org References: <20260704052714.428561-1-chenyichong@uniontech.com> X-Report-Abuse: Please report any abuse attempt to abuse@migadu.com and include these headers. From: ChenXiaoSong In-Reply-To: <20260704052714.428561-1-chenyichong@uniontech.com> Content-Type: text/plain; charset=UTF-8; format=flowed Content-Transfer-Encoding: 8bit X-Migadu-Flow: FLOW_OUT Reviewed-by: ChenXiaoSong 在 2026/7/4 13:27, Yichong Chen 写道: > netfs_alloc_folioq_buffer() may leave a partially allocated folio > queue attached to the caller's buffer pointer when it returns an error. > > smb3_init_transform_rq() stores the buffer in the request only after > allocation succeeds, so the common error path cannot free a partial > allocation. Store the buffer pointer before checking the return value so > err_free releases it. > > Signed-off-by: Yichong Chen > --- > fs/smb/client/smb2ops.c | 2 +- > 1 file changed, 1 insertion(+), 1 deletion(-) > > diff --git a/fs/smb/client/smb2ops.c b/fs/smb/client/smb2ops.c > index 199f6aeb7b33..3fe9f0534e42 100644 > --- a/fs/smb/client/smb2ops.c > +++ b/fs/smb/client/smb2ops.c > @@ -4882,10 +4882,10 @@ smb3_init_transform_rq(struct TCP_Server_Info *server, int num_rqst, > size_t cur_size = 0; > rc = netfs_alloc_folioq_buffer(NULL, &buffer, &cur_size, > size, GFP_NOFS); > + new->rq_buffer = buffer; > if (rc < 0) > goto err_free; > > - new->rq_buffer = buffer; > iov_iter_folio_queue(&new->rq_iter, ITER_SOURCE, > buffer, 0, 0, size); > -- ChenXiaoSong Chinese Homepage: https://chenxiaosong.com English Homepage: https://chenxiaosong.com/en