From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-wr1-f41.google.com (mail-wr1-f41.google.com [209.85.221.41]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 905A7386C37 for ; Mon, 1 Jun 2026 07:41:43 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.221.41 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1780299704; cv=none; b=oU+MPZ3Icy8W7Sz3gehdqaJcWjq6LnJByMOeTBCg7qls+srbLkMc5Z6dpNqYtDrIRHWlDwtvExTkWviLQ0A3qNHe7TS/F/stVWick8o9lsmKG/el3ZUwizyvolbQliVaFnw8Az10PQlcrERC5rHbUQbdu4RQCgMpzHHxLSh/k38= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1780299704; c=relaxed/simple; bh=3HrW05YbTvZNEhfW1lK9iWLfR6sVRdLfNdGvlZMSeRw=; h=Date:From:To:Cc:Subject:Message-ID:References:MIME-Version: Content-Type:Content-Disposition:In-Reply-To; b=j2uJGU/3zCZEBstbfPFQuL+KNAZqfdycXqiTcv1s3bAToX0k4OjHZr17CXNWGTRBBMI2Y80EEnj7U9bak8LxkncV9ccYQ3+gRw8r3/YHhFhRDATOvUY7NIP12fooT9QhKr6PuAMy8JfUqVis0/QyzDtjAt0MCR8xv+9ytO1OJaY= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=suse.com; spf=pass smtp.mailfrom=suse.com; dkim=pass (2048-bit key) header.d=suse.com header.i=@suse.com header.b=STMcSX4q; arc=none smtp.client-ip=209.85.221.41 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=suse.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=suse.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=suse.com header.i=@suse.com header.b="STMcSX4q" Received: by mail-wr1-f41.google.com with SMTP id ffacd0b85a97d-45ef0ccccfcso208678f8f.0 for ; Mon, 01 Jun 2026 00:41:43 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=suse.com; s=google; t=1780299702; x=1780904502; darn=vger.kernel.org; h=in-reply-to:content-disposition:mime-version:references:message-id :subject:cc:to:from:date:from:to:cc:subject:date:message-id:reply-to; bh=kS1ypxnVv61QoYz2k4MQaxM89Rj7Jk+DUA2Ar1EHnys=; b=STMcSX4qbwul10gJSwMDy3kCgOPwarFq8gv/eWO61hq97h1FJgxrpgC0iM9QryYbpP gzZiXXaaw+wi7b1LJJtiRRTuuiok3dld3FI7m0iZGd4cj7sGs9lWGs0graPKkZDhE7hZ cdLZPXcTNmwiFZTfut96hOLmSmYPYF8t9gX8WU8VSlWt8zRUD/5tGlt04+nat2p/q+bZ auCs94ShhiamQmErk/il+P1iEc0IRQLa2PGh5Y0qiu6mkgarWLSPIj0G8tW8e7x1P5d0 MusVYIt+QcDkFnZXwsIyE2JSLOpl6cNoQNdLR8+pmxMucD/M5TodIWtjoSY/wek6mDRC 8+NA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1780299702; x=1780904502; h=in-reply-to:content-disposition:mime-version:references:message-id :subject:cc:to:from:date:x-gm-gg:x-gm-message-state:from:to:cc :subject:date:message-id:reply-to; bh=kS1ypxnVv61QoYz2k4MQaxM89Rj7Jk+DUA2Ar1EHnys=; b=Mv6TrPXux1S+B0rTBxLJAg6Fv5hDN+dh3TCjJx0d5AQFM8a4WWUCqLxXjHIAf5Bjey cYjRwBniRV9CYvgs92KGIypMsMvR997bkK+7ivECItS6OFc2iHAlbMbnG1+hf/w7WT6t g6B0DimnyEPZBBOJdv6CPug3bh9Y944Y2AoX05ce945f0IGaMlW/ZKiJGLDUi6d9maQU +iWeswKGGNMWvysIDV74WdnfLstbo5HLrWD39Rc4VpIJB53lFsDi0GSU+tFTZsQTSF3Q jhjwMHOU7xYAaL2ZI8eZ7AptLC/dAfhDlB656R7kNbvRBcTYDfOoLDVsVVEYPLUjL5Ek Gy2w== X-Forwarded-Encrypted: i=1; AFNElJ+JZIfJktU615U8n59j0QV49tvcQS7mcx/6Jwxp8ghAf8QCH/Fo+BkvKbNvX5g1OHZg6462AjGr/A2IZGY=@vger.kernel.org X-Gm-Message-State: AOJu0YwVo8mxIMVhMkdkXi0U+WWpIDHaoxWVC6cB0ndlkbxG4NnFxgQ0 SQm00JDpCPXUqfqJur+dKvc6l29/O+AgHSuzCJan+h2UeUp16bHFzjFOKBqmBjJ1fe4= X-Gm-Gg: Acq92OFntZMYlV5I+mrMVgZ60rNiV5Xe9Ws1Pm2bZHovQCYmjzko4HAVpq1Y+89cyRx H3ZhZUge0u5HnfhFpKJ8U50RqVuADThchrTEIMBUCVzL4leatQOfpYFA2sdaLMbvRHCGLdb7NQz aB1e3q5zqqOo5uQ/DdG9QvN4gR0dvnxYNVIMJPviSMp+Dckc8C0EkfRNKqY5VttJ4GQ8apHe+hJ u4SC1teK26bgUpa6pXcFORNBlOQNyo4Vh4m9PcjlmrzW+ZQCZQ3nxA8xV0Ix4H8jB9PEjSNT1g7 CjIY7etHWsiUfnM7xdJySVipwLl46Kjp6yiNUJVLpt3ysltIE612UNgp7NMT+nptxV0608G2lBY Lc8izbC/tfemEqr8Q0KX/TS1mONFA2ibEJz+de+SZE+tJV4OeqN+HBZ/LJldKky4lxaDP8ZXvR1 zs3e2dieFk32NQ978A4yK11fUCAlHY1Iu/ X-Received: by 2002:a05:600c:1382:b0:48a:5664:f44a with SMTP id 5b1f17b1804b1-490a29e431cmr76061195e9.2.1780299702093; Mon, 01 Jun 2026 00:41:42 -0700 (PDT) Received: from localhost ([202.127.77.110]) by smtp.gmail.com with ESMTPSA id d9443c01a7336-2bf23b001a8sm98422115ad.40.2026.06.01.00.41.40 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 01 Jun 2026 00:41:41 -0700 (PDT) Date: Mon, 1 Jun 2026 15:41:38 +0800 From: Heming Zhao To: Joseph Qi Cc: Andrew Morton , Farhad Alemi , ocfs2-devel@lists.linux.dev, linux-kernel@vger.kernel.org Subject: Re: [PATCH] ocfs2: add journal NULL check in ocfs2_checkpoint_inode() Message-ID: References: <20260531131645.3650299-1-joseph.qi@linux.alibaba.com> <48b50de9-0047-416f-b09d-6e2e0fdeb70d@linux.alibaba.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <48b50de9-0047-416f-b09d-6e2e0fdeb70d@linux.alibaba.com> On Mon, Jun 01, 2026 at 02:50:56PM +0800, Joseph Qi wrote: > > > On 6/1/26 11:32 AM, Heming Zhao wrote: > > On Sun, May 31, 2026 at 09:16:45PM +0800, Joseph Qi wrote: > >> During unmount, ocfs2_journal_shutdown() frees the journal and sets > >> osb->journal to NULL. Later, when VFS evicts remaining cached inodes, > >> ocfs2_evict_inode() -> ocfs2_clear_inode() -> ocfs2_checkpoint_inode() > >> -> ocfs2_ci_fully_checkpointed() dereferences osb->journal, causing a > >> NULL pointer dereference. > >> > >> Fix this by adding a NULL check for osb->journal in > >> ocfs2_checkpoint_inode(). If the journal is NULL, it has already been > >> fully flushed and destroyed during shutdown, so there is nothing to > >> checkpoint. > >> > >> Reported-by: Farhad Alemi > >> Fixes: da5e7c87827e ("ocfs2: cleanup journal init and shutdown") > >> Signed-off-by: Joseph Qi > >> Tested-by: Farhad Alemi > >> --- > >> fs/ocfs2/journal.h | 3 +++ > >> 1 file changed, 3 insertions(+) > >> > >> diff --git a/fs/ocfs2/journal.h b/fs/ocfs2/journal.h > >> index 6397170f302f..f8b3b2a3d630 100644 > >> --- a/fs/ocfs2/journal.h > >> +++ b/fs/ocfs2/journal.h > >> @@ -196,6 +196,9 @@ static inline void ocfs2_checkpoint_inode(struct inode *inode) > >> if (ocfs2_mount_local(osb)) > >> return; > >> > >> + if (!osb->journal) > >> + return; > >> + > > > > In my view, the code is correct for this bug. > > However, the if condition is insufficient if ocfs2_journal_shutdown() sets > > "journal = NULL" immediately after this line. > > > During unmount, journal shutdown happens before final inode eviction is > triggered by generic_shutdown_super() -> evict_inodes(). That means they > run sequentially in the unmount path (same thread context). > > Thanks, > Joseph > Thanks for the explanation. I will provide my Reviewed-by tag. Based on the call stack in Farhad's email attachment, it seems the test case triggered the if (osb->slot_num != OCFS2_INVALID_SLOT) condition in ocfs2_dismount_volume() to skip the released slot_inode. Thanks, Heming