From: liubaolin <liubaolin12138@163.com>
To: Hongbo Li <lihongbo22@huawei.com>, xiang@kernel.org, chao@kernel.org
Cc: zbestahu@gmail.com, jefflexu@linux.alibaba.com,
dhavale@google.com, guochunhai@vivo.com,
linux-erofs@lists.ozlabs.org, linux-kernel@vger.kernel.org,
Baolin Liu <liubaolin@kylinos.cn>
Subject: Re: [PATCH v1] erofs: Fix state inconsistency when updating fsid/domain_id
Date: Tue, 6 Jan 2026 16:11:36 +0800 [thread overview]
Message-ID: <28f3272c-90bf-48a5-a272-244a0481f51a@163.com> (raw)
In-Reply-To: <d5a5b58d-de3d-452a-86de-7e7fb71fe518@huawei.com>
> Dear Hongbo Li,
>
> I have reviewed this carefully, and I agree with your point. The old value will eventually be freed in erofs_sb_free(), and keeping it here does not appear to be necessary. Therefore, this patch does not need to be considered further.
>
> Thank you for your review.
>
> Dear Gao Xiang,
>
> Thank you for your review as well.
>
> Best regards,
> Baolin Liu
>
>
在 2026/1/6 11:30, Hongbo Li 写道:
> Hi,
>
> On 2026/1/6 10:55, Baolin Liu wrote:
>> From: Baolin Liu <liubaolin@kylinos.cn>
>>
>> When updating fsid or domain_id, the code frees the old pointer before
>> allocating a new one. If allocation fails, the pointer becomes NULL
>> while the old value is already freed, causing state inconsistency.
>>
>> Fix by allocating the new value first, and only freeing the old value
>> on success.
>>
>> Signed-off-by: Baolin Liu <liubaolin@kylinos.cn>
>> ---
>> fs/erofs/super.c | 18 ++++++++++++------
>> 1 file changed, 12 insertions(+), 6 deletions(-)
>>
>> diff --git a/fs/erofs/super.c b/fs/erofs/super.c
>> index 937a215f626c..6e083d7e634c 100644
>> --- a/fs/erofs/super.c
>> +++ b/fs/erofs/super.c
>> @@ -509,16 +509,22 @@ static int erofs_fc_parse_param(struct
>> fs_context *fc,
>> break;
>> #ifdef CONFIG_EROFS_FS_ONDEMAND
>> case Opt_fsid:
>> - kfree(sbi->fsid);
>> - sbi->fsid = kstrdup(param->string, GFP_KERNEL);
>> - if (!sbi->fsid)
>> + char *new_fsid;
>> +
>> + new_fsid = kstrdup(param->string, GFP_KERNEL);
>
> May be there is no need to keep the old pointer. Because
> 1) The fsid/domain_id is ignored in reconfiguration.
> 2) Even if memory allocation fails when the user first mounts with multi
> fsid/domain_id options (like -o fsid=xxx1,fsid=xxx2), the old fsid
> pointer would also need to be released in cleanup procedure.
>
> so am I right?
>
> Thanks,
> Hongbo
>
>> + if (!new_fsid)
>> return -ENOMEM;
>> + kfree(sbi->fsid);
>> + sbi->fsid = new_fsid;
>> break;
>> case Opt_domain_id:
>> - kfree(sbi->domain_id);
>> - sbi->domain_id = kstrdup(param->string, GFP_KERNEL);
>> - if (!sbi->domain_id)
>> + char *new_domain_id;
>> +
>> + new_domain_id = kstrdup(param->string, GFP_KERNEL);
>> + if (!new_domain_id)
>> return -ENOMEM;
>> + kfree(sbi->domain_id);
>> + sbi->domain_id = new_domain_id;
>> break;
>> #else
>> case Opt_fsid:
prev parent reply other threads:[~2026-01-06 8:12 UTC|newest]
Thread overview: 4+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-01-06 2:55 Baolin Liu
2026-01-06 3:10 ` Gao Xiang
2026-01-06 3:30 ` Hongbo Li
2026-01-06 8:11 ` liubaolin [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=28f3272c-90bf-48a5-a272-244a0481f51a@163.com \
--to=liubaolin12138@163.com \
--cc=chao@kernel.org \
--cc=dhavale@google.com \
--cc=guochunhai@vivo.com \
--cc=jefflexu@linux.alibaba.com \
--cc=lihongbo22@huawei.com \
--cc=linux-erofs@lists.ozlabs.org \
--cc=linux-kernel@vger.kernel.org \
--cc=liubaolin@kylinos.cn \
--cc=xiang@kernel.org \
--cc=zbestahu@gmail.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®