From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-pj1-f41.google.com (mail-pj1-f41.google.com [209.85.216.41]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 12AC2495023 for ; Wed, 19 Aug 2026 18:06:52 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.216.41 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787162817; cv=none; b=jxOp45C5BWgwIPcgqnhQBkounS1uOd8k161cJ76zFveW7qDYg0uEEBBb08/GYp94L7AzZCqnzCq6KmZpD/M8DCu/wzsBvyLNYWmPY/IS/RB36zqL1mAdS87WjRHsYmKK8FyZiz2NWF0Sr9SEM3lpMTxEqsjqMaT8aG/r7j4EIaI= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787162817; c=relaxed/simple; bh=Vuh4F2Hkn+qxramOw6V2x4Rl7E5NHhxeeBgnVsd19l8=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=ej8nQwNgkGCu2c6dGOnkPskiRQfTjJnwzLMGqSXZ5y2NWfryZwxyUlDBiit5+0gFiXM0g4kujPh9oQDW8e9IeQlP1xwhePIwLi7X7OKfW1bRFwTmhP64gl7dCCY6x6hjzgpufLXsjllJO5A1Iu7aMRw9LDPUTUGlhl4cM6t8TGU= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=pE4D4IKL; arc=none smtp.client-ip=209.85.216.41 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="pE4D4IKL" Received: by mail-pj1-f41.google.com with SMTP id 98e67ed59e1d1-38e041ea211so1417681a91.0 for ; Wed, 19 Aug 2026 11:06:52 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1787162812; x=1787767612; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to:content-type; bh=8GIX06LK7ExT+q3Aigt+SM74hjeyo4GTr/pSIL5HQvw=; b=pE4D4IKLTDGjYBuD9EDoGc9N5wnWx8TiCcqKtyyUaT43tk4XiYeJQWBCYfWQYGXfhm nOQZ5K6b8VFTqXztnG6J3xT30y9/3bCpvs0WPEjKKBFZvB1xm9/9jeQj7Pw7V1vtE3X1 I0hU24FK4ewo64uQibgUynuRY3ufPP1qxi6L9OrwOaQRkzO8VMRCcafyM0dAKmIvMAnM HRNCL/FpVVTTaPNjgrxxU76gcjExQjP2olQ5Et1oqzz3MxJFfLjHsjWhYCKtVgM0oF18 guB1S0kgKJCmHNbBZAkA5WIZ9jfyZxA1bb4mG9N3+yAJLTRDnGuYMgDiid+3uEaXE749 8CnA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787162812; x=1787767612; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=8GIX06LK7ExT+q3Aigt+SM74hjeyo4GTr/pSIL5HQvw=; b=gV2jc5aG7mh/5WdNHMZuBYyGknT1qkaQ6bS0Qtt2GElz0Bbek5rDFtA3s5qpoazLuI UHpX9bYM6cdtCP2dUb7rNW4MxphEmgee0oMNMUMIeWAS7IaQlRtglc8pjRaFlNIw4YVq 68QBfGRjCjnPcirFI7r+GjB6/8w44+Az0V9H5wK6wc4DKxHIGOVzStkYpCyHMBrIGdDY gArs/+ioU9LK84dEbK34s374RS1t5H81lVS7Q2UnmhO0dOmDPmN3J50ozGu9Wo1XU+zu sDzQBK+xnCphnH5VNN2S4KTlPz5rc5sODQ6C9vFMX7QSj+MxAPwI50SBrTQ1vry4c+XD zZfw== X-Gm-Message-State: AFuF++kX5nC6hADB/5eGhHIG+XkHTua8f+VHlo9jqAyZvBxD2m3iIv4u gnNl74uejI/m19EGxxkOL/0bsyFHwvunO3SeoibhvyJl4MpGeEO96RkbT7T/5w== X-Gm-Gg: AR+sD13LajrV94E175+4lr1kvirX6P5zRlWxOWsdzjTzdyk/J3Y6ve15rmmdgnm+G6k 7irkx7BC19AhglGK/P3hqsfCegalmL8hryUHhFcouApgIOCVruY0OlV99rjlk5/1abVHqDN4p1L 6nMRRIPHI0x3ojpMRUGbeLVWLX8rXT2fuKuPJOIX3gAd4V2MeOZMkIi7yCSyECKFlnBIuet5fkf Ys0bpk0pOuCmihutZ8CvnuNLAcT10cg+T2NGXA8PRsjXHfC8usevRHjiOu7flRwg4+r3GC/+E7P YvMZtqVNzR1k1UXI+VOh6qfczH2QDL6poL1b9xcza/qGEq6W7v1dAL+GpaXjJ+b3eUO840QRJya hrlx79i73Gq8NZ/F7zCIxXLOMCPsHZ8f3baoxo5tDsnjIgc07b1/M7lVvah9uNteCy+9G9LOzV5 zVRrVgB0forIA3/BESya90pTXVK+ly53VrOof0HJhnYqANgsDHUxqnFcBxUA/1zBwZyhBdRz9/s kLoMZX7sK1IbhfLZxFQjbewIArmro2mutJSLUOZdPYnF380/MdFcozpvZVaPsAoeA9NQLPMRn8Z JuGXYtX98OfQ82UadulgN0E= X-Received: by 2002:a17:90b:5105:b0:37f:fb1d:63fa with SMTP id 98e67ed59e1d1-39581070da4mr12594675a91.15.1787162811435; Wed, 19 Aug 2026 11:06:51 -0700 (PDT) Received: from daehojeong-desktop.mtv.corp.google.com ([2a00:79e0:2e7c:8:f24b:89c3:b14:d945]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-327bef7a0easm10426663eec.12.2026.08.19.11.06.49 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 19 Aug 2026 11:06:50 -0700 (PDT) From: Daeho Jeong To: linux-kernel@vger.kernel.org, linux-f2fs-devel@lists.sourceforge.net, kernel-team@android.com Cc: Daeho Jeong , stable@vger.kernel.org, Sunmin Jeong Subject: [PATCH] f2fs: fix to migrate all curseg types during free_segment_range Date: Wed, 19 Aug 2026 11:06:35 -0700 Message-ID: <20260819180635.1165300-1-daeho43@gmail.com> X-Mailer: git-send-email 2.55.0.691.gc56d675ccc-goog Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit From: Daeho Jeong In free_segment_range(), the curseg evacuation loop only iterates up to NR_CURSEG_PERSIST_TYPE (0..5), missing non-persistent in-memory curseg types such as CURSEG_COLD_DATA_PINNED and CURSEG_ALL_DATA_ATGC. Even though these in-memory curseg types are not saved in the on-disk checkpoint header, they still occupy active physical segments at runtime. If an active in-memory curseg happens to be allocated within the segment range being truncated during filesystem shrink, failing to evacuate it will cause subsequent writes to the curseg attempting out-of-bounds I/O on the truncated storage range. Fix this by expanding the curseg evacuation loop upper bound to NR_CURSEG_TYPE to ensure all active curseg types are safely migrated out of the target range. Fixes: d0b9e42ab615 ("f2fs: introduce inmem curseg") Cc: stable@vger.kernel.org Signed-off-by: Daeho Jeong Signed-off-by: Sunmin Jeong --- fs/f2fs/gc.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/fs/f2fs/gc.c b/fs/f2fs/gc.c index ffaa7ba76a1b..192b16ac02f8 100644 --- a/fs/f2fs/gc.c +++ b/fs/f2fs/gc.c @@ -2222,7 +2222,7 @@ static int free_segment_range(struct f2fs_sb_info *sbi, mutex_unlock(&DIRTY_I(sbi)->seglist_lock); /* Move out cursegs from the target range */ - for (type = CURSEG_HOT_DATA; type < NR_CURSEG_PERSIST_TYPE; type++) { + for (type = CURSEG_HOT_DATA; type < NR_CURSEG_TYPE; type++) { err = f2fs_allocate_segment_for_resize(sbi, type, start, end); if (err) goto out; -- 2.55.0.691.gc56d675ccc-goog