mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: Hui Peng <benquike@gmail.com>
To: Anders Larsen <al@alarsen.net>
Cc: Matthias Goergens <matthias.goergens@gmail.com>,
	linux-fsdevel@vger.kernel.org, linux-kernel@vger.kernel.org,
	stable@vger.kernel.org, Hui Peng <benquike@gmail.com>
Subject: [PATCH v4 3/6] qnx6: avoid double brelse() and fix sb_buf leak on error path in qnx6_fill_super()
Date: Wed, 30 Sep 2026 03:16:01 +0000	[thread overview]
Message-ID: <20260930031604.70544-4-benquike@gmail.com> (raw)
In-Reply-To: <20260924073920.2782917-1-benquike@gmail.com>

In qnx6_fill_super(), when active superblock selection chooses sb1 or
sb2, it calls brelse() on the inactive buffer head without setting its
pointer to NULL. If an error occurs later (e.g. Inode.levels validation
failure), label out: calls brelse(bh1) and brelse(bh2), resulting in a
double free of the inactive buffer head.

Additionally, if mmi_fs path is used, sbi->sb_buf is set by
qnx6_mmi_fill_super(), but on failure after mmi_success:,
brelse(sbi->sb_buf) is never called.

Set bh2 = NULL or bh1 = NULL after releasing the inactive buffer head,
and release sbi->sb_buf on error paths at label out:.

Tested in QEMU against tip of mainline commit 62f4c998b297 ("Merge tag 'parisc-for-7.3-rc5' of git://git.kernel.org/pub/scm/linux/kernel/git/deller/parisc-linux")
using a loop-device reproducer mounting with mmi_fs option: on the
unfixed kernel, failure after mmi_success leaked sbi->sb_buf
(sb_buf_page0_leaked=1); whereas with this fix applied, sbi->sb_buf is
released on error (sb_buf_page0_leaked=0).

Fixes: 5d026c724220 ("fs: initial qnx6fs addition")
Cc: stable@vger.kernel.org
Assisted-by: LLM
Signed-off-by: Hui Peng <benquike@gmail.com>
---
Changes in v4:
- Rebased cleanly onto upstream mainline commit 62f4c998b297.
- Added QEMU test procedure and verification details in commit message body.

 fs/qnx6/inode.c | 6 ++++++
 1 file changed, 6 insertions(+)

diff --git a/fs/qnx6/inode.c b/fs/qnx6/inode.c
index 080f7698a5e0..d425daee090c 100644
--- a/fs/qnx6/inode.c
+++ b/fs/qnx6/inode.c
@@ -399,6 +399,7 @@ static int qnx6_fill_super(struct super_block *s, struct fs_context *fc)
 		sbi->sb_buf = bh1;
 		sbi->sb = (struct qnx6_super_block *)bh1->b_data;
 		brelse(bh2);
+		bh2 = NULL;
 		pr_info("superblock #1 active\n");
 	} else {
 		/* superblock #2 active */
@@ -405,5 +406,6 @@ static int qnx6_fill_super(struct super_block *s, struct fs_context *fc)
 		sbi->sb = (struct qnx6_super_block *)bh2->b_data;
 		brelse(bh1);
+		bh1 = NULL;
 		pr_info("superblock #2 active\n");
 	}
 mmi_success:
@@ -467,6 +469,10 @@ static int qnx6_fill_super(struct super_block *s, struct fs_context *fc)
 out1:
 	iput(sbi->inodes);
 out:
+	if (sbi && sbi->sb_buf && !bh1 && !bh2) {
+		brelse(sbi->sb_buf);
+		sbi->sb_buf = NULL;
+	}
 	brelse(bh1);
 	brelse(bh2);
 outnobh:
-- 
2.55.0.1082.g2b9226bbc0-goog

  parent reply	other threads:[~2026-09-30  3:16 UTC|newest]

Thread overview: 34+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-19 22:25 [PATCH] qnx6: validate di_filelevels in qnx6_iget() and fix mount error handling Hui Peng
2026-09-20  4:02 ` Damien Le Moal
2026-09-21  4:25   ` [PATCH v2 1/6] qnx6: validate di_filelevels in qnx6_iget() Hui Peng
2026-09-21  4:25     ` [PATCH v2 2/6] qnx6: release buffer_head on error in qnx6_block_map() Hui Peng
2026-09-24  4:31       ` Matthias Goergens
2026-09-24  7:39       ` [PATCH v3 1/6] qnx6: validate di_filelevels in qnx6_iget() before accessing level pointers Hui Peng
2026-09-21  4:25     ` [PATCH v2 3/6] qnx6: avoid double brelse() on error path in qnx6_fill_super() Hui Peng
2026-09-24  4:31       ` Matthias Goergens
2026-09-24  7:39       ` [PATCH v3 2/6] qnx6: release bh on error path in qnx6_block_map() Hui Peng
2026-09-21  4:25     ` [PATCH v2 4/6] qnx6: release sb_buf on mmi_fs error path in qnx6_fill_super() Hui Peng
2026-09-24  4:31       ` Matthias Goergens
2026-09-24  7:39       ` [PATCH v3 3/6] qnx6: avoid double brelse() on " Hui Peng
2026-09-21  4:25     ` [PATCH v2 5/6] qnx6: abort mount on superblock magic mismatch when silent is set Hui Peng
2026-09-24  4:31       ` Matthias Goergens
2026-09-24  7:39       ` [PATCH v3 4/6] qnx6: release sb_buf on mmi_fs error path in qnx6_fill_super() Hui Peng
2026-09-21  4:25     ` [PATCH v2 6/6] qnx6: validate sb_blocksize before dividing in qnx6_mmi_fill_super() Hui Peng
2026-09-24  4:31       ` Matthias Goergens
2026-09-24  7:39       ` [PATCH v3 5/6] qnx6: abort mount on superblock magic mismatch when silent is set Hui Peng
2026-09-24  4:31     ` [PATCH v2 1/6] qnx6: validate di_filelevels in qnx6_iget() Matthias Goergens
2026-09-24  7:39     ` [PATCH v3 0/6] fs/qnx6: fix buffer head leaks, double free, and inode validation Hui Peng
2026-09-24 10:11       ` Matthias Goergens
2026-09-30  3:15       ` [PATCH v4 " Hui Peng
2026-09-30  7:22         ` Matthias Goergens
2026-09-30  3:15       ` [PATCH v4 1/6] qnx6: validate di_filelevels in qnx6_iget() before accessing level pointers Hui Peng
2026-09-30  7:22         ` Matthias Goergens
2026-09-30  3:16       ` [PATCH v4 2/6] qnx6: release bh on error path in qnx6_block_map() Hui Peng
2026-09-30  7:22         ` Matthias Goergens
2026-09-30  3:16       ` Hui Peng [this message]
2026-09-30  3:16       ` [PATCH v4 4/6] qnx6: release bh2/bh1 on active superblock selection in qnx6_mmi_fill_super() Hui Peng
2026-09-30  3:16       ` [PATCH v4 5/6] qnx6: abort mount on superblock magic mismatch when silent is set " Hui Peng
2026-09-30  7:22         ` Matthias Goergens
2026-09-30  3:16       ` [PATCH v4 6/6] qnx6: validate sb_blocksize before dividing " Hui Peng
2026-09-30  7:22         ` Matthias Goergens
     [not found]     ` <20260921042511.1473629-7-benquike@gmail.com>
2026-09-24  7:39       ` [PATCH v3 " Hui Peng

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260930031604.70544-4-benquike@gmail.com \
    --to=benquike@gmail.com \
    --cc=al@alarsen.net \
    --cc=linux-fsdevel@vger.kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=matthias.goergens@gmail.com \
    --cc=stable@vger.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®