* [PATCH] smb: client: free partially allocated transform folio queue
@ 2026-07-04 5:27 Yichong Chen
2026-07-27 6:16 ` Yichong Chen
2026-07-27 13:30 ` ChenXiaoSong
0 siblings, 2 replies; 4+ messages in thread
From: Yichong Chen @ 2026-07-04 5:27 UTC (permalink / raw)
To: Steve French
Cc: Paulo Alcantara, Ronnie Sahlberg, Shyam Prasad N, Tom Talpey,
Bharath SM, linux-cifs, samba-technical, linux-kernel,
Yichong Chen
netfs_alloc_folioq_buffer() may leave a partially allocated folio
queue attached to the caller's buffer pointer when it returns an error.
smb3_init_transform_rq() stores the buffer in the request only after
allocation succeeds, so the common error path cannot free a partial
allocation. Store the buffer pointer before checking the return value so
err_free releases it.
Signed-off-by: Yichong Chen <chenyichong@uniontech.com>
---
fs/smb/client/smb2ops.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/fs/smb/client/smb2ops.c b/fs/smb/client/smb2ops.c
index 199f6aeb7b33..3fe9f0534e42 100644
--- a/fs/smb/client/smb2ops.c
+++ b/fs/smb/client/smb2ops.c
@@ -4882,10 +4882,10 @@ smb3_init_transform_rq(struct TCP_Server_Info *server, int num_rqst,
size_t cur_size = 0;
rc = netfs_alloc_folioq_buffer(NULL, &buffer, &cur_size,
size, GFP_NOFS);
+ new->rq_buffer = buffer;
if (rc < 0)
goto err_free;
- new->rq_buffer = buffer;
iov_iter_folio_queue(&new->rq_iter, ITER_SOURCE,
buffer, 0, 0, size);
--
2.51.0
^ permalink raw reply [flat|nested] 4+ messages in thread
* Re: [PATCH] smb: client: free partially allocated transform folio queue
2026-07-04 5:27 [PATCH] smb: client: free partially allocated transform folio queue Yichong Chen
@ 2026-07-27 6:16 ` Yichong Chen
2026-07-27 13:30 ` ChenXiaoSong
1 sibling, 0 replies; 4+ messages in thread
From: Yichong Chen @ 2026-07-27 6:16 UTC (permalink / raw)
To: sfrench
Cc: bharathsm, linux-cifs, linux-kernel, pc, ronniesahlberg,
samba-technical, sprasad, tom
Hi,
Ping. Could someone please take a look at this patch?
Thanks,
Yichong
^ permalink raw reply [flat|nested] 4+ messages in thread
* Re: [PATCH] smb: client: free partially allocated transform folio queue
2026-07-04 5:27 [PATCH] smb: client: free partially allocated transform folio queue Yichong Chen
2026-07-27 6:16 ` Yichong Chen
@ 2026-07-27 13:30 ` ChenXiaoSong
2026-07-27 22:35 ` Steve French
1 sibling, 1 reply; 4+ messages in thread
From: ChenXiaoSong @ 2026-07-27 13:30 UTC (permalink / raw)
To: Yichong Chen, Steve French
Cc: Paulo Alcantara, Ronnie Sahlberg, Shyam Prasad N, Tom Talpey,
Bharath SM, linux-cifs, samba-technical, linux-kernel
Reviewed-by: ChenXiaoSong <chenxiaosong@kylinos.cn>
在 2026/7/4 13:27, Yichong Chen 写道:
> netfs_alloc_folioq_buffer() may leave a partially allocated folio
> queue attached to the caller's buffer pointer when it returns an error.
>
> smb3_init_transform_rq() stores the buffer in the request only after
> allocation succeeds, so the common error path cannot free a partial
> allocation. Store the buffer pointer before checking the return value so
> err_free releases it.
>
> Signed-off-by: Yichong Chen <chenyichong@uniontech.com>
> ---
> fs/smb/client/smb2ops.c | 2 +-
> 1 file changed, 1 insertion(+), 1 deletion(-)
>
> diff --git a/fs/smb/client/smb2ops.c b/fs/smb/client/smb2ops.c
> index 199f6aeb7b33..3fe9f0534e42 100644
> --- a/fs/smb/client/smb2ops.c
> +++ b/fs/smb/client/smb2ops.c
> @@ -4882,10 +4882,10 @@ smb3_init_transform_rq(struct TCP_Server_Info *server, int num_rqst,
> size_t cur_size = 0;
> rc = netfs_alloc_folioq_buffer(NULL, &buffer, &cur_size,
> size, GFP_NOFS);
> + new->rq_buffer = buffer;
> if (rc < 0)
> goto err_free;
>
> - new->rq_buffer = buffer;
> iov_iter_folio_queue(&new->rq_iter, ITER_SOURCE,
> buffer, 0, 0, size);
>
--
ChenXiaoSong <chenxiaosong@chenxiaosong.com>
Chinese Homepage: https://chenxiaosong.com
English Homepage: https://chenxiaosong.com/en
^ permalink raw reply [flat|nested] 4+ messages in thread
* Re: [PATCH] smb: client: free partially allocated transform folio queue
2026-07-27 13:30 ` ChenXiaoSong
@ 2026-07-27 22:35 ` Steve French
0 siblings, 0 replies; 4+ messages in thread
From: Steve French @ 2026-07-27 22:35 UTC (permalink / raw)
To: ChenXiaoSong
Cc: Yichong Chen, Paulo Alcantara, Ronnie Sahlberg, Shyam Prasad N,
Tom Talpey, Bharath SM, linux-cifs, samba-technical,
linux-kernel, David Howells
Merged into cifs-2.6.git for-next
On Mon, Jul 27, 2026 at 8:41 AM ChenXiaoSong
<chenxiaosong@chenxiaosong.com> wrote:
>
> Reviewed-by: ChenXiaoSong <chenxiaosong@kylinos.cn>
>
> 在 2026/7/4 13:27, Yichong Chen 写道:
> > netfs_alloc_folioq_buffer() may leave a partially allocated folio
> > queue attached to the caller's buffer pointer when it returns an error.
> >
> > smb3_init_transform_rq() stores the buffer in the request only after
> > allocation succeeds, so the common error path cannot free a partial
> > allocation. Store the buffer pointer before checking the return value so
> > err_free releases it.
> >
> > Signed-off-by: Yichong Chen <chenyichong@uniontech.com>
> > ---
> > fs/smb/client/smb2ops.c | 2 +-
> > 1 file changed, 1 insertion(+), 1 deletion(-)
> >
> > diff --git a/fs/smb/client/smb2ops.c b/fs/smb/client/smb2ops.c
> > index 199f6aeb7b33..3fe9f0534e42 100644
> > --- a/fs/smb/client/smb2ops.c
> > +++ b/fs/smb/client/smb2ops.c
> > @@ -4882,10 +4882,10 @@ smb3_init_transform_rq(struct TCP_Server_Info *server, int num_rqst,
> > size_t cur_size = 0;
> > rc = netfs_alloc_folioq_buffer(NULL, &buffer, &cur_size,
> > size, GFP_NOFS);
> > + new->rq_buffer = buffer;
> > if (rc < 0)
> > goto err_free;
> >
> > - new->rq_buffer = buffer;
> > iov_iter_folio_queue(&new->rq_iter, ITER_SOURCE,
> > buffer, 0, 0, size);
> >
>
> --
> ChenXiaoSong <chenxiaosong@chenxiaosong.com>
> Chinese Homepage: https://chenxiaosong.com
> English Homepage: https://chenxiaosong.com/en
>
>
--
Thanks,
Steve
^ permalink raw reply [flat|nested] 4+ messages in thread
end of thread, other threads:[~2026-07-27 22:36 UTC | newest]
Thread overview: 4+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-07-04 5:27 [PATCH] smb: client: free partially allocated transform folio queue Yichong Chen
2026-07-27 6:16 ` Yichong Chen
2026-07-27 13:30 ` ChenXiaoSong
2026-07-27 22:35 ` Steve French
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®