Yangtao Li
0807e4ac59
hfsplus: remove mutex_lock check in hfsplus_free_extents
...
[ Upstream commit fcb96956c921f1aae7e7b477f2435c56f77a31b4 ]
Syzbot reported an issue in hfsplus filesystem:
------------[ cut here ]------------
WARNING: CPU: 0 PID: 4400 at fs/hfsplus/extents.c:346
hfsplus_free_extents+0x700/0xad0
Call Trace:
<TASK>
hfsplus_file_truncate+0x768/0xbb0 fs/hfsplus/extents.c:606
hfsplus_write_begin+0xc2/0xd0 fs/hfsplus/inode.c:56
cont_expand_zero fs/buffer.c:2383 [inline]
cont_write_begin+0x2cf/0x860 fs/buffer.c:2446
hfsplus_write_begin+0x86/0xd0 fs/hfsplus/inode.c:52
generic_cont_expand_simple+0x151/0x250 fs/buffer.c:2347
hfsplus_setattr+0x168/0x280 fs/hfsplus/inode.c:263
notify_change+0xe38/0x10f0 fs/attr.c:420
do_truncate+0x1fb/0x2e0 fs/open.c:65
do_sys_ftruncate+0x2eb/0x380 fs/open.c:193
do_syscall_x64 arch/x86/entry/common.c:50 [inline]
do_syscall_64+0x3d/0xb0 arch/x86/entry/common.c:80
entry_SYSCALL_64_after_hwframe+0x63/0xcd
To avoid deadlock, Commit 31651c6071 ("hfsplus: avoid deadlock
on file truncation") unlock extree before hfsplus_free_extents(),
and add check wheather extree is locked in hfsplus_free_extents().
However, when operations such as hfsplus_file_release,
hfsplus_setattr, hfsplus_unlink, and hfsplus_get_block are executed
concurrently in different files, it is very likely to trigger the
WARN_ON, which will lead syzbot and xfstest to consider it as an
abnormality.
The comment above this warning also describes one of the easy
triggering situations, which can easily trigger and cause
xfstest&syzbot to report errors.
[task A] [task B]
->hfsplus_file_release
->hfsplus_file_truncate
->hfs_find_init
->mutex_lock
->mutex_unlock
->hfsplus_write_begin
->hfsplus_get_block
->hfsplus_file_extend
->hfsplus_ext_read_extent
->hfs_find_init
->mutex_lock
->hfsplus_free_extents
WARN_ON(mutex_is_locked) !!!
Several threads could try to lock the shared extents tree.
And warning can be triggered in one thread when another thread
has locked the tree. This is the wrong behavior of the code and
we need to remove the warning.
Fixes: 31651c6071 ("hfsplus: avoid deadlock on file truncation")
Reported-by: syzbot+8c0bc9f818702ff75b76@syzkaller.appspotmail.com
Closes: https://lore.kernel.org/all/00000000000057fa4605ef101c4c@google.com/
Signed-off-by: Yangtao Li <frank.li@vivo.com>
Reviewed-by: Viacheslav Dubeyko <slava@dubeyko.com>
Signed-off-by: Viacheslav Dubeyko <slava@dubeyko.com>
Link: https://lore.kernel.org/r/20250529061807.2213498-1-frank.li@vivo.com
Signed-off-by: Viacheslav Dubeyko <slava@dubeyko.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2025-08-28 16:21:18 +02:00
..
9p
fs/9p: drop inodes immediately on non-.L too
2024-05-17 11:43:53 +02:00
adfs
affs
affs: don't write overlarge OFS data block size fields
2025-04-10 14:29:42 +02:00
afs
afs: Fix directory format encoding struct
2025-03-13 12:42:52 +01:00
autofs
autofs: fix memory leak of waitqueues in autofs_catatonic_mode
2023-09-23 11:00:02 +02:00
befs
bfs
btrfs
btrfs: use btrfs_record_snapshot_destroy() during rmdir
2025-07-17 18:24:59 +02:00
cachefiles
cachefiles: fix memory leak in cachefiles_add_cache()
2024-03-06 14:36:10 +00:00
ceph
ceph: fix possible integer overflow in ceph_zero_objects()
2025-07-17 18:24:50 +02:00
cifs
cifs: Fix cifs_query_path_info() for Windows NT servers
2025-07-17 18:24:49 +02:00
coda
coda: Avoid partial allocation of sig_inputArgs
2023-03-11 16:43:56 +01:00
configfs
configfs: Do not override creating attribute file failure in populate_attrs()
2025-06-27 11:02:50 +01:00
cramfs
crypto
debugfs
new helper: lookup_positive_unlocked()
2023-09-23 10:59:40 +02:00
devpts
dlm
dlm: fix plock lookup when using multiple lockspaces
2023-09-23 10:59:55 +02:00
ecryptfs
ecryptfs: Fix buffer size for tag 66 packet
2024-06-16 13:28:32 +02:00
efivarfs
efivarfs: Fix error on non-existent file
2025-01-09 13:23:28 +01:00
efs
erofs
erofs: fix incorrect symlink detection in fast symlink
2025-01-09 13:23:27 +01:00
exportfs
ext2
ext2: fix datatype of block number in ext2_xattr_set2()
2023-09-23 11:00:04 +02:00
ext4
ext4: fix calculation of credits for extent tree modification
2025-06-27 11:02:51 +01:00
f2fs
f2fs: prevent kernel warning due to negative i_nlink from corrupted image
2025-06-27 11:02:51 +01:00
fat
fat: fix uninitialized variable
2024-11-08 16:20:47 +01:00
freevxfs
fscache
fuse
virtiofs: add filesystem context source name check
2025-05-02 07:39:21 +02:00
gfs2
gfs2: move msleep to sleepable context
2025-06-27 11:02:50 +01:00
hfs
hfs/hfsplus: fix slab-out-of-bounds in hfs_bnode_read_key
2025-05-02 07:39:20 +02:00
hfsplus
hfsplus: remove mutex_lock check in hfsplus_free_extents
2025-08-28 16:21:18 +02:00
hostfs
hpfs
hugetlbfs
fs,hugetlb: fix NULL pointer dereference in hugetlbs_fill_super
2024-03-06 14:36:10 +00:00
iomap
iomap: Set all uptodate bits for an Uptodate page
2024-03-01 13:13:35 +01:00
isofs
isofs: Verify inode mode when loading from disk
2025-08-28 16:21:15 +02:00
jbd2
jbd2: fix data-race and null-ptr-deref in jbd2_journal_dirty_metadata()
2025-06-27 11:02:58 +01:00
jffs2
jffs2: check jffs2_prealloc_raw_node_refs() result in few other places
2025-06-27 11:02:56 +01:00
jfs
jfs: validate AG parameters in dbMount() to prevent crashes
2025-07-17 18:24:52 +02:00
kernfs
fs/kernfs/dir: obey S_ISGID
2024-02-23 08:25:03 +01:00
lockd
fs: lockd: avoid possible wrong NULL parameter
2023-09-23 10:59:48 +02:00
minix
nfs
NFSv4/flexfiles: Fix handling of NFS level errors in I/O
2025-07-17 18:25:04 +02:00
nfs_common
nfsd
nfsd: nfsd4_spo_must_allow() must check this is a v4 compound request
2025-06-27 11:02:51 +01:00
nilfs2
nilfs2: reject invalid file types when reading inodes
2025-08-28 16:21:18 +02:00
nls
fs/nls: make load_nls() take a const parameter
2023-09-23 10:59:38 +02:00
notify
fanotify: disallow mount/sb marks on kernel internal pseudo fs
2023-07-27 08:37:26 +02:00
ntfs
ocfs2
ocfs2: stop quota recovery before disabling quotas
2025-06-04 14:32:27 +02:00
omfs
treewide: Remove uninitialized_var() usage
2023-06-09 10:29:01 +02:00
openpromfs
openpromfs: finish conversion to the new mount API
2024-06-16 13:28:32 +02:00
orangefs
orangefs: Do not truncate file size
2025-06-04 14:32:32 +02:00
overlayfs
ovl: Check for NULL d_inode() in ovl_dentry_upper()
2025-07-17 18:24:51 +02:00
proc
fix proc_sys_compare() handling of in-lookup dentries
2025-07-17 18:25:01 +02:00
pstore
pstore/ram: Fix crash when setting number of cpus to an odd number
2024-02-23 08:24:55 +01:00
qnx4
qnx6
quota
quota: flush quota_release_work upon quota writeback
2024-12-14 19:44:42 +01:00
ramfs
reiserfs
reiserfs: Check the return value from __getblk()
2023-09-23 10:59:40 +02:00
romfs
squashfs
Squashfs: check return result of sb_min_blocksize
2025-06-27 11:02:47 +01:00
sysfs
fs: sysfs: Fix reference leak in sysfs_break_active_protection()
2024-05-02 16:18:32 +02:00
sysv
sysv: don't call sb_bread() with pointers_lock held
2024-04-13 12:51:38 +02:00
tracefs
tracefs: Add missing lockdown check to tracefs_create_dir()
2023-09-23 11:00:06 +02:00
ubifs
ubifs: skip dumping tnc tree when zroot is null
2025-03-13 12:42:59 +01:00
udf
udf: Fix use of check_add_overflow() with mixed type arguments
2025-03-13 12:42:51 +01:00
ufs
unicode
Revert "unicode: Don't special case ignorable code points"
2024-12-14 19:44:55 +01:00
verity
fsverity: skip PKCS#7 parser when keyring is empty
2023-09-23 10:59:55 +02:00
xfs
xfs: don't drop errno values when we fail to ficlone the entire range
2024-12-19 18:05:03 +01:00
aio.c
fs/aio: Check IOCB_AIO_RW before the struct aio_kiocb conversion
2024-04-13 12:51:29 +02:00
anon_inodes.c
attr.c
attr: block mode changes of symlinks
2023-09-23 11:00:06 +02:00
bad_inode.c
binfmt_aout.c
binfmt_elf.c
binfmt_elf_fdpic.c
fs: binfmt_elf_efpic: don't use missing interpreter's properties
2024-09-04 13:14:54 +02:00
binfmt_em86.c
binfmt_flat.c
binfmt_flat: Fix integer overflow bug on 32 bit systems
2025-03-13 12:43:07 +01:00
binfmt_misc.c
binfmt_misc: cleanup on filesystem umount
2024-09-04 13:14:53 +02:00
binfmt_script.c
block_dev.c
block: Don't invalidate pagecache for invalid falloc modes
2024-01-08 11:29:48 +01:00
buffer.c
char_dev.c
compat.c
compat_binfmt_elf.c
compat_ioctl.c
lsm: new security_file_ioctl_compat() hook
2024-02-23 08:25:15 +01:00
coredump.c
coredump: hand a pidfd to the usermode coredump helper
2025-06-04 14:32:36 +02:00
d_path.c
dax.c
dcache.c
fs: better handle deep ancestor chains in is_subdir()
2024-07-27 10:38:32 +02:00
dcookies.c
direct-io.c
drop_caches.c
eventfd.c
eventfd: prevent underflow for eventfd semaphores
2023-09-23 10:59:40 +02:00
eventpoll.c
epoll: Add synchronous wakeup support for ep_poll_callback
2025-01-09 13:23:32 +01:00
exec.c
parisc: Fix stack start for ADDR_NO_RANDOMIZE personality
2024-11-08 16:20:40 +01:00
fcntl.c
fs: Fix file_set_fowner LSM hook inconsistencies
2024-11-08 16:20:34 +01:00
fhandle.c
do_sys_name_to_handle(): use kzalloc() to fix kernel-infoleak
2024-03-26 18:22:13 -04:00
file.c
fix bitmap corruption on close_range() with CLOSE_RANGE_UNSHARE
2024-09-04 13:14:50 +02:00
file_table.c
filesystems.c
fs/filesystems: Fix potential unsigned integer underflow in fs_name()
2025-06-27 11:02:50 +01:00
fs-writeback.c
writeback: fix call of incorrect macro
2023-05-17 11:35:58 +02:00
fs_context.c
fs: avoid empty option when generating legacy mount string
2023-07-27 08:37:25 +02:00
fs_parser.c
fs_pin.c
fs_struct.c
fs_types.c
fsopen.c
inode.c
vfs: fix race between evice_inodes() and find_inode()&iput()
2024-11-08 16:20:34 +01:00
internal.h
fs: Establish locking order for unrelated directories
2023-07-27 08:37:26 +02:00
io_uring.c
io_uring: fail NOP if non-zero op flags is passed in
2024-06-16 13:28:48 +02:00
ioctl.c
Kconfig
nfs: add missing selections of CONFIG_CRC32
2025-05-02 07:39:20 +02:00
Kconfig.binfmt
libfs.c
locks.c
filelock: Correct the filelock owner in fcntl_setlk/fcntl_setlk64
2024-09-04 13:15:02 +02:00
Makefile
mbcache.c
mbcache: Avoid nesting of cache->c_list_lock under bit locks
2023-01-18 11:41:59 +01:00
mount.h
mpage.c
namei.c
fuse: don't truncate cached, mutated symlink
2025-04-10 14:29:36 +02:00
namespace.c
attach_recursive_mnt(): do not lock the covering tree when sliding something under it
2025-07-17 18:24:53 +02:00
no-block.c
nsfs.c
open.c
ftruncate: pass a signed offset
2024-07-05 09:08:31 +02:00
pipe.c
pnode.c
pnode.h
posix_acl.c
proc_namespace.c
read_write.c
readdir.c
select.c
fs/select: rework stack allocation hack for clang
2024-03-26 18:22:13 -04:00
seq_file.c
signalfd.c
splice.c
stack.c
stat.c
statfs.c
statfs: enforce statfs[64] structure initialization
2023-05-30 12:44:07 +01:00
super.c
fs: explicitly unregister per-superblock BDIs
2024-11-08 16:20:26 +01:00
sync.c
ovl: skip overlayfs superblocks at global sync
2023-12-08 08:44:27 +01:00
timerfd.c
userfaultfd.c
utimes.c
xattr.c