From: Shuangpeng Bai <shuangpeng.kernel@gmail.com>
To: Dongsheng Yang <dongsheng.yang@linux.dev>, Zheng Gu <cengku@gmail.com>
Cc: Mikulas Patocka <mpatocka@redhat.com>,
dm-devel@lists.linux.dev, linux-kernel@vger.kernel.org,
Shuangpeng Bai <shuangpeng.kernel@gmail.com>
Subject: [PATCH] dm-pcache: fix use-after-free during cache replay
Date: Wed, 5 Aug 2026 13:16:37 -0400 [thread overview]
Message-ID: <20260805171637.3557122-1-shuangpeng.kernel@gmail.com> (raw)
kset_replay() drops the last reference to a stale cache key before
using key->cache_pos to acquire a reference to its cache segment. This
can dereference the freed key.
Segment references account for key records that have not yet been
consumed by key-log garbage collection. A reference is acquired for
every successfully recorded key, and the GC path drops one for every
record, including records whose segment generation has become stale.
Replay therefore has to restore the segment reference before deciding
whether the decoded key should be inserted into the request-key tree.
Move cache_seg_get() before the generation check. This preserves the
get/put accounting for stale records while ensuring that the key is not
accessed after cache_key_put().
Fixes: 1d57628ff95b ("dm-pcache: add persistent cache target in device-mapper")
Signed-off-by: Shuangpeng Bai <shuangpeng.kernel@gmail.com>
---
drivers/md/dm-pcache/cache_key.c | 3 +--
1 file changed, 1 insertion(+), 2 deletions(-)
diff --git a/drivers/md/dm-pcache/cache_key.c b/drivers/md/dm-pcache/cache_key.c
index e068e878231b..b37d899f2d3c 100644
--- a/drivers/md/dm-pcache/cache_key.c
+++ b/drivers/md/dm-pcache/cache_key.c
@@ -729,6 +729,7 @@ static int kset_replay(struct pcache_cache *cache, struct pcache_cache_kset_onme
}
__set_bit(key->cache_pos.cache_seg->cache_seg_id, cache->seg_map);
+ cache_seg_get(key->cache_pos.cache_seg);
/* Check if the segment generation is valid for insertion. */
if (key->seg_gen < key->cache_pos.cache_seg->gen) {
@@ -739,8 +740,6 @@ static int kset_replay(struct pcache_cache *cache, struct pcache_cache_kset_onme
cache_key_insert(&cache->req_key_tree, key, true);
spin_unlock(&cache_subtree->tree_lock);
}
-
- cache_seg_get(key->cache_pos.cache_seg);
}
return 0;
--
2.43.0
next reply other threads:[~2026-08-05 17:16 UTC|newest]
Thread overview: 3+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-05 17:16 Shuangpeng Bai [this message]
2026-08-06 11:48 ` Mikulas Patocka
2026-08-06 14:44 ` Shuangpeng
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260805171637.3557122-1-shuangpeng.kernel@gmail.com \
--to=shuangpeng.kernel@gmail.com \
--cc=cengku@gmail.com \
--cc=dm-devel@lists.linux.dev \
--cc=dongsheng.yang@linux.dev \
--cc=linux-kernel@vger.kernel.org \
--cc=mpatocka@redhat.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®