]> git.ipfire.org Git - thirdparty/kernel/stable.git/commitdiff
btrfs: use btrfs_record_snapshot_destroy() during rmdir
authorFilipe Manana <fdmanana@suse.com>
Fri, 20 Jun 2025 15:37:01 +0000 (16:37 +0100)
committerGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Thu, 10 Jul 2025 13:59:51 +0000 (15:59 +0200)
[ Upstream commit 157501b0469969fc1ba53add5049575aadd79d80 ]

We are setting the parent directory's last_unlink_trans directly which
may result in a concurrent task starting to log the directory not see the
update and therefore can log the directory after we removed a child
directory which had a snapshot within instead of falling back to a
transaction commit. Replaying such a log tree would result in a mount
failure since we can't currently delete snapshots (and subvolumes) during
log replay. This is the type of failure described in commit 1ec9a1ae1e30
("Btrfs: fix unreplayable log after snapshot delete + parent dir fsync").

Fix this by using btrfs_record_snapshot_destroy() which updates the
last_unlink_trans field while holding the inode's log_mutex lock.

Fixes: 44f714dae50a ("Btrfs: improve performance on fsync against new inode after rename/unlink")
Reviewed-by: Johannes Thumshirn <johannes.thumshirn@wdc.com>
Signed-off-by: Filipe Manana <fdmanana@suse.com>
Signed-off-by: David Sterba <dsterba@suse.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
fs/btrfs/inode.c

index f7f97cd3cdf061d3c987d0544aaf301fa56f52f2..5ecc2f3dc3a993f592ccd3d51759bd057d1f4de3 100644 (file)
@@ -4856,7 +4856,6 @@ static int btrfs_rmdir(struct inode *dir, struct dentry *dentry)
        struct btrfs_fs_info *fs_info = BTRFS_I(inode)->root->fs_info;
        int err = 0;
        struct btrfs_trans_handle *trans;
-       u64 last_unlink_trans;
        struct fscrypt_name fname;
 
        if (inode->i_size > BTRFS_EMPTY_DIR_SIZE)
@@ -4891,8 +4890,6 @@ static int btrfs_rmdir(struct inode *dir, struct dentry *dentry)
        if (err)
                goto out;
 
-       last_unlink_trans = BTRFS_I(inode)->last_unlink_trans;
-
        /* now the directory is empty */
        err = btrfs_unlink_inode(trans, BTRFS_I(dir), BTRFS_I(d_inode(dentry)),
                                 &fname.disk_name);
@@ -4909,8 +4906,8 @@ static int btrfs_rmdir(struct inode *dir, struct dentry *dentry)
                 * 5) mkdir foo
                 * 6) fsync foo or some file inside foo
                 */
-               if (last_unlink_trans >= trans->transid)
-                       BTRFS_I(dir)->last_unlink_trans = last_unlink_trans;
+               if (BTRFS_I(inode)->last_unlink_trans >= trans->transid)
+                       btrfs_record_snapshot_destroy(trans, BTRFS_I(dir));
        }
 out:
        btrfs_end_transaction(trans);