]> git.ipfire.org Git - thirdparty/linux.git/commitdiff
btrfs: fix NULL pointer dereference in do_abort_log_replay()
authorSuchit Karunakaran <suchitkarunakaran@gmail.com>
Fri, 19 Dec 2025 17:14:34 +0000 (22:44 +0530)
committerDavid Sterba <dsterba@suse.com>
Tue, 6 Jan 2026 00:23:00 +0000 (01:23 +0100)
Coverity reported a NULL pointer dereference issue (CID 1666756) in
do_abort_log_replay(). When btrfs_alloc_path() fails in
replay_one_buffer(), wc->subvol_path is NULL, but btrfs_abort_log_replay()
calls do_abort_log_replay() which unconditionally dereferences
wc->subvol_path when attempting to print debug information. Fix this by
adding a NULL check before dereferencing wc->subvol_path in
do_abort_log_replay().

Fixes: 2753e4917624 ("btrfs: dump detailed info and specific messages on log replay failures")
Reviewed-by: Filipe Manana <fdmanana@suse.com>
Signed-off-by: Suchit Karunakaran <suchitkarunakaran@gmail.com>
Signed-off-by: Filipe Manana <fdmanana@suse.com>
Signed-off-by: David Sterba <dsterba@suse.com>
fs/btrfs/tree-log.c

index 5831754bb01c4830a7f3ba08a198445991af4df5..2d9d38b82daa2a64a2f03a82d75cf97bb24d2690 100644 (file)
@@ -190,7 +190,7 @@ static void do_abort_log_replay(struct walk_control *wc, const char *function,
 
        btrfs_abort_transaction(wc->trans, error);
 
-       if (wc->subvol_path->nodes[0]) {
+       if (wc->subvol_path && wc->subvol_path->nodes[0]) {
                btrfs_crit(fs_info,
                           "subvolume (root %llu) leaf currently being processed:",
                           btrfs_root_id(wc->root));