From: Chao Yu <chao@kernel.org>
To: jaegeuk@kernel.org
Cc: linux-f2fs-devel@lists.sourceforge.net,
linux-kernel@vger.kernel.org, Chao Yu <chao@kernel.org>
Subject: [PATCH 2/2] f2fs: cache: pin cached block in f2fs_unlock_cache()
Date: Wed, 30 Sep 2026 23:54:35 +0000 [thread overview]
Message-ID: <20260930235435.3789910-2-chao@kernel.org> (raw)
In-Reply-To: <20260930235435.3789910-1-chao@kernel.org>
From: Chao Yu <chao@kernel.org>
During asynchronous read readahead (e.g., in f2fs_ra_node_cache()), the
caller drops its own reference via f2fs_put_cache(entry, false) immediately
after issuing the read bio, leaving only the radix tree holding an active
reference during I/O flight.
In f2fs_unlock_cache(), clear_and_wake_up_bit() executes two steps:
1. clear_bit_unlock(F2FS_BLOCK_LOCKED, &entry->state): clears the bit.
2. wake_up_bit(&entry->state, F2FS_BLOCK_LOCKED): hashes &entry->state
to find the waitqueue and wake sleeping waiters.
Once step 1 clears the bit, a concurrent waiter in f2fs_lock_cache()
(such as in f2fs_truncate_cache() or f2fs_drop_cache()) is immediately
unblocked. The waiter can acquire the lock, delete the entry from the
radix tree, drop the remaining reference, and kfree() the entry before
step 2 completes. This causes wake_up_bit() to dereference freed memory:
CPU 0 (Read I/O completion) CPU 1 (f2fs_drop_cache / Truncation)
- f2fs_cache_read_end_io()
- f2fs_unlock_cache(entry)
- clear_and_wake_up_bit()
- clear_bit_unlock(LOCKED)
: bit is cleared!
- f2fs_lock_cache(entry)
: acquires lock!
- f2fs_truncate_locked_cache(entry)
- radix_tree_delete(&cache->root, ...)
- entry->cache = NULL;
- atomic_dec(&entry->refcount);
- f2fs_unlock_cache(entry);
- f2fs_put_cache(entry, false);
- atomic_dec_and_test(&refcount) == 0
- f2fs_do_free_cache(entry)
- kfree(entry->data);
- kfree(entry); <--- FREED!
- smp_mb__after_atomic()
- wake_up_bit(&entry->state, ...)
: Dereferences &entry->state on freed entry! (UAF)
Like commit ("f2fs: cache: pin cached block in f2fs_end_cache_writeback()"),
acquire a temporary reference via f2fs_cache_get() before clear_and_wake_up_bit()
and release it with f2fs_cache_put() once wake_up_bit() completes.
This fixes commit 399410a90ca7 ("f2fs: cache: implement metadata cache")
Signed-off-by: Chao Yu <chao@kernel.org>
---
fs/f2fs/cache.c | 14 ++++++++++++++
1 file changed, 14 insertions(+)
diff --git a/fs/f2fs/cache.c b/fs/f2fs/cache.c
index 7831e53f5678..04b5408cbc58 100644
--- a/fs/f2fs/cache.c
+++ b/fs/f2fs/cache.c
@@ -18,6 +18,8 @@
#include <trace/events/f2fs.h>
#include "segment.h"
+static bool f2fs_cache_put(struct f2fs_cached_block *entry);
+
void f2fs_cache_wait_writeback_cond(struct f2fs_cached_block *entry,
enum page_type type)
{
@@ -314,7 +316,19 @@ void f2fs_lock_cache(struct f2fs_cached_block *entry)
void f2fs_unlock_cache(struct f2fs_cached_block *entry)
{
+ /*
+ * In asynchronous read I/O completion (e.g. from f2fs_ra_node_cache()),
+ * the I/O completion does not hold a reference of its own. Once
+ * clear_and_wake_up_bit() clears F2FS_BLOCK_LOCKED, a concurrent waiter
+ * in f2fs_lock_cache() (e.g. from f2fs_truncate_cache()) can wake up,
+ * truncate the entry, and drop the final reference before wake_up_bit()
+ * finishes.
+ * Pin the entry here to make sure it is not freed before wake_up_bit()
+ * completes.
+ */
+ f2fs_cache_get(entry);
clear_and_wake_up_bit(F2FS_BLOCK_LOCKED, &entry->state);
+ f2fs_cache_put(entry);
}
bool f2fs_put_cache(struct f2fs_cached_block *entry, bool unlock)
--
2.49.0
prev parent reply other threads:[~2026-09-30 23:54 UTC|newest]
Thread overview: 2+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-30 23:54 [PATCH 1/2] f2fs: cache: pin cached block in f2fs_end_cache_writeback() Chao Yu
2026-09-30 23:54 ` Chao Yu [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260930235435.3789910-2-chao@kernel.org \
--to=chao@kernel.org \
--cc=jaegeuk@kernel.org \
--cc=linux-f2fs-devel@lists.sourceforge.net \
--cc=linux-kernel@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®