From: Joseph Qi <joseph.qi@linux.alibaba.com>
To: Andrew Morton <akpm@linux-foundation.org>,
Mark Fasheh <mark@fasheh.com>, Joel Becker <jlbec@evilplan.org>,
Heming Zhao <heming.zhao@suse.com>
Cc: ocfs2-devel@lists.linux.dev, linux-kernel@vger.kernel.org
Subject: [PATCH] ocfs2: fix circular locking dependency in reflink
Date: Fri, 31 Jul 2026 19:34:25 +0800 [thread overview]
Message-ID: <20260731113425.4130293-1-joseph.qi@linux.alibaba.com> (raw)
Lockdep reports a possible deadlock involving ip_alloc_sem,
j_trans_barrier, and ip_xattr_sem:
Chain exists of:
&oi->ip_alloc_sem --> &journal->j_trans_barrier --> &oi->ip_xattr_sem
Possible unsafe locking scenario:
CPU0 CPU1
---- ----
lock(&oi->ip_xattr_sem);
lock(&journal->j_trans_barrier);
lock(&oi->ip_xattr_sem);
lock(&oi->ip_alloc_sem);
*** DEADLOCK ***
ocfs2_reflink() and ocfs2_try_remove_refcount_tree() acquire
ip_xattr_sem before ip_alloc_sem. This is the reverse of the
established system-wide ordering where ip_alloc_sem is outer:
- Write paths (e.g. ocfs2_write_begin_nolock) hold ip_alloc_sem
and call ocfs2_start_trans(), which takes j_trans_barrier.
- ocfs2_mknod() calls ocfs2_start_trans() (j_trans_barrier) then
ocfs2_init_acl(), which takes ip_xattr_sem on the parent dir.
Fix by swapping the lock order in both functions to acquire
ip_alloc_sem before ip_xattr_sem, consistent with the rest of the
codebase.
Fixes: 09bf27a00020 ("ocfs2: Implement ocfs2_reflink.")
Fixes: 8b2c0dba5159 ("ocfs2: Call refcount tree remove process properly.")
Reported-by: syzbot+e42eae29bba35810f43c@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=e42eae29bba35810f43c
Signed-off-by: Joseph Qi <joseph.qi@linux.alibaba.com>
---
fs/ocfs2/refcounttree.c | 8 ++++----
1 file changed, 4 insertions(+), 4 deletions(-)
diff --git a/fs/ocfs2/refcounttree.c b/fs/ocfs2/refcounttree.c
index d9f22b4a2654..c734ce295bf0 100644
--- a/fs/ocfs2/refcounttree.c
+++ b/fs/ocfs2/refcounttree.c
@@ -955,8 +955,8 @@ int ocfs2_try_remove_refcount_tree(struct inode *inode,
struct ocfs2_inode_info *oi = OCFS2_I(inode);
struct ocfs2_dinode *di = (struct ocfs2_dinode *)di_bh->b_data;
- down_write(&oi->ip_xattr_sem);
down_write(&oi->ip_alloc_sem);
+ down_write(&oi->ip_xattr_sem);
if (oi->ip_clusters)
goto out;
@@ -972,8 +972,8 @@ int ocfs2_try_remove_refcount_tree(struct inode *inode,
if (ret)
mlog_errno(ret);
out:
- up_write(&oi->ip_alloc_sem);
up_write(&oi->ip_xattr_sem);
+ up_write(&oi->ip_alloc_sem);
return 0;
}
@@ -4292,12 +4292,12 @@ static int ocfs2_reflink(struct dentry *old_dentry, struct inode *dir,
goto out;
}
- down_write(&OCFS2_I(inode)->ip_xattr_sem);
down_write(&OCFS2_I(inode)->ip_alloc_sem);
+ down_write(&OCFS2_I(inode)->ip_xattr_sem);
error = __ocfs2_reflink(old_dentry, old_bh,
new_orphan_inode, preserve);
- up_write(&OCFS2_I(inode)->ip_alloc_sem);
up_write(&OCFS2_I(inode)->ip_xattr_sem);
+ up_write(&OCFS2_I(inode)->ip_alloc_sem);
ocfs2_inode_unlock(inode, 1);
ocfs2_rw_unlock(inode, 1);
--
2.39.3
next reply other threads:[~2026-07-31 11:34 UTC|newest]
Thread overview: 4+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-07-31 11:34 Joseph Qi [this message]
2026-07-31 18:21 ` Andrew Morton
2026-08-02 13:02 ` Joseph Qi
2026-08-04 6:46 ` Joseph Qi
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260731113425.4130293-1-joseph.qi@linux.alibaba.com \
--to=joseph.qi@linux.alibaba.com \
--cc=akpm@linux-foundation.org \
--cc=heming.zhao@suse.com \
--cc=jlbec@evilplan.org \
--cc=linux-kernel@vger.kernel.org \
--cc=mark@fasheh.com \
--cc=ocfs2-devel@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®