* [PATCH] btrfs: preserve caller ownership of anon_dev on root insert retry
@ 2026-10-05 21:23 sungbyeongchan
2026-10-05 21:39 ` Qu Wenruo
0 siblings, 1 reply; 2+ messages in thread
From: sungbyeongchan @ 2026-10-05 21:23 UTC (permalink / raw)
To: David Sterba, Chris Mason; +Cc: linux-btrfs, linux-kernel
create_subvol() preallocates an anonymous block-device ID and passes it to
btrfs_get_new_fs_root(). On a cache miss, btrfs_get_root_ref() assigns that ID
to a temporary root before attempting to insert the root in the cache.
If another caller inserts the same root first, the creator gets -EEXIST and
drops the temporary root. The final put frees root->anon_dev, but the caller's
*anon_dev still contains the same ID. The retry finds the cached root and
frees the caller's ID again, producing an ida_free warning.
Keep ownership with the caller across the retry by clearing the losing
temporary root's anon_dev when the ID was supplied by the caller. Roots that
allocated their own ID retain the existing destruction behavior.
The unfixed sequence was reproduced in two clean boots. With this change the
creator-side -EEXIST branch was exercised twice, each caller-owned ID was
released exactly once on retry, no ida_free warning occurred, and ordinary
subvolume creation, writes, qgroup display, and clean unmount passed.
Fixes: 2dfb1e43f57d ("btrfs: preallocate anon block device at first phase of snapshot creation")
Reported-by: sungbyeongchan <tjdqudcks0424@naver.com>
Tested-by: sungbyeongchan <tjdqudcks0424@naver.com>
Assisted-by: LLM
Signed-off-by: sungbyeongchan <tjdqudcks0424@naver.com>
Cc: stable@vger.kernel.org
---
fs/btrfs/disk-io.c | 2 ++
1 file changed, 2 insertions(+)
diff --git a/fs/btrfs/disk-io.c b/fs/btrfs/disk-io.c
index dc7ad92876c0..4a5e43dfde6f 100644
--- a/fs/btrfs/disk-io.c
+++ b/fs/btrfs/disk-io.c
@@ -1355,6 +1355,8 @@ again:
ret = btrfs_insert_fs_root(fs_info, root);
if (ret) {
if (ret == -EEXIST) {
+ if (anon_dev && *anon_dev)
+ root->anon_dev = 0;
btrfs_put_root(root);
goto again;
}
--
2.39.5
^ permalink raw reply [flat|nested] 2+ messages in thread* Re: [PATCH] btrfs: preserve caller ownership of anon_dev on root insert retry
2026-10-05 21:23 [PATCH] btrfs: preserve caller ownership of anon_dev on root insert retry sungbyeongchan
@ 2026-10-05 21:39 ` Qu Wenruo
0 siblings, 0 replies; 2+ messages in thread
From: Qu Wenruo @ 2026-10-05 21:39 UTC (permalink / raw)
To: sungbyeongchan, David Sterba, Chris Mason; +Cc: linux-btrfs, linux-kernel
在 2026/10/6 07:53, sungbyeongchan 写道:
> create_subvol() preallocates an anonymous block-device ID and passes it to
> btrfs_get_new_fs_root(). On a cache miss, btrfs_get_root_ref() assigns that ID
> to a temporary root before attempting to insert the root in the cache.
>
> If another caller inserts the same root first, the creator gets -EEXIST and
> drops the temporary root. The final put frees root->anon_dev, but the caller's
> *anon_dev still contains the same ID. The retry finds the cached root and
> frees the caller's ID again, producing an ida_free warning.
Please provide the warning message.
>
> Keep ownership with the caller across the retry by clearing the losing
> temporary root's anon_dev when the ID was supplied by the caller. Roots that
> allocated their own ID retain the existing destruction behavior.
>
> The unfixed sequence was reproduced in two clean boots.
And reproducer.
> With this change the
> creator-side -EEXIST branch was exercised twice, each caller-owned ID was
> released exactly once on retry, no ida_free warning occurred, and ordinary
> subvolume creation, writes, qgroup display, and clean unmount passed.
>
> Fixes: 2dfb1e43f57d ("btrfs: preallocate anon block device at first phase of snapshot creation")
> Reported-by: sungbyeongchan <tjdqudcks0424@naver.com>
> Tested-by: sungbyeongchan <tjdqudcks0424@naver.com>
> Assisted-by: LLM
> Signed-off-by: sungbyeongchan <tjdqudcks0424@naver.com>
> Cc: stable@vger.kernel.org
> ---
> fs/btrfs/disk-io.c | 2 ++
> 1 file changed, 2 insertions(+)
>
> diff --git a/fs/btrfs/disk-io.c b/fs/btrfs/disk-io.c
> index dc7ad92876c0..4a5e43dfde6f 100644
> --- a/fs/btrfs/disk-io.c
> +++ b/fs/btrfs/disk-io.c
> @@ -1355,6 +1355,8 @@ again:
> ret = btrfs_insert_fs_root(fs_info, root);
> if (ret) {
> if (ret == -EEXIST) {
> + if (anon_dev && *anon_dev)
> + root->anon_dev = 0;
> btrfs_put_root(root);
> goto again;
> }
^ permalink raw reply [flat|nested] 2+ messages in thread
end of thread, other threads:[~2026-10-05 21:40 UTC | newest]
Thread overview: 2+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-10-05 21:23 [PATCH] btrfs: preserve caller ownership of anon_dev on root insert retry sungbyeongchan
2026-10-05 21:39 ` Qu Wenruo
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®