[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Message-ID: <1a2445d1-6fbb-4133-b5b7-72254e96d815@gmail.com>
Date: Fri, 14 Nov 2025 18:15:16 +0100
From: Mehdi Ben Hadj Khelifa <mehdi.benhadjkhelifa@...il.com>
To: Christian Brauner <brauner@...nel.org>
Cc: syzbot+ad45f827c88778ff7df6@...kaller.appspotmail.com, frank.li@...o.com,
glaubitz@...sik.fu-berlin.de, linux-fsdevel@...r.kernel.org,
linux-kernel@...r.kernel.org, slava@...eyko.com,
syzkaller-bugs@...glegroups.com
Subject: Re: [PATCH] fs/super: fix memory leak of s_fs_info on
setup_bdev_super failure
On 11/14/25 12:55 PM, Christian Brauner wrote:
> On Fri, Nov 14, 2025 at 06:12:12AM +0100, Mehdi Ben Hadj Khelifa wrote:
>> #syz test
>>
>> diff --git a/fs/super.c b/fs/super.c
>> index 5bab94fb7e03..a99e5281b057 100644
>> --- a/fs/super.c
>> +++ b/fs/super.c
>> @@ -1690,6 +1690,11 @@ int get_tree_bdev_flags(struct fs_context *fc,
>> if (!error)
>> error = fill_super(s, fc);
>> if (error) {
>> + /*
>> + * return back sb_info ownership to fc to be freed by put_fs_context()
>> + */
>> + fc->s_fs_info = s->s_fs_info;
>> + s->s_fs_info = NULL;
>> deactivate_locked_super(s);
>> return error;
>> }
>> --
>> 2.51.2
>>
>
> No, either free it in hfs_fill_super() when it fails or add a wrapper
> around kill_block_super() for hfs and free it after ->kill_sb() has run.
Sorry for the noise,Resending with proper CCs:
I forgot to mention. I was giving back the ownership to the filesystem
context because upon setup_bdev_super fails put_fs_context still gets
called even if I would free s_fs_info in the kill_sb,so hfs_free_fc
would get a NULL pointer to kfree as a result..I don't think that would
be desirable.
I would be sending my patch out for more discussion.
Best Regards,
Mehdi Ben Hadj Khelifa
Powered by blists - more mailing lists