]> git.ipfire.org Git - thirdparty/kernel/stable.git/commitdiff
block: free copied pages when blk_rq_map_kern() fails
authorJackie Liu <liuyun01@kylinos.cn>
Wed, 15 Jul 2026 07:35:18 +0000 (15:35 +0800)
committerJens Axboe <axboe@kernel.dk>
Thu, 16 Jul 2026 12:08:14 +0000 (06:08 -0600)
bio_copy_kern() allocates pages that are normally freed by the bio
completion callback. If blk_rq_append_bio() rejects the bio, however,
blk_rq_map_kern() only drops the bio reference. Since bio_put() does not
free pages referenced by the bio vectors, those pages leak.

This can happen when the bio exceeds the queue segment constraints or
when a later mapping cannot be merged into a request built by earlier
calls. Track whether the buffer was copied and free those pages before
dropping the rejected bio.

Fixes: 3a5a39276d2a ("block: allow blk_rq_map_kern to append to requests")
Assisted-by: Codex:gpt-5.6-sol
Signed-off-by: Jackie Liu <liuyun01@kylinos.cn>
Reviewed-by: Christoph Hellwig <hch@lst.de>
Link: https://patch.msgid.link/20260715073518.96042-1-liu.yun@linux.dev
Signed-off-by: Jens Axboe <axboe@kernel.dk>
block/blk-map.c

index 768549f19f97ec1da849a1eabf62c8575d40e303..d1d6bbe0ecf1f963196ed7406b715e697084e25f 100644 (file)
@@ -653,6 +653,7 @@ int blk_rq_map_kern(struct request *rq, void *kbuf, unsigned int len,
                gfp_t gfp_mask)
 {
        unsigned long addr = (unsigned long) kbuf;
+       bool do_copy;
        struct bio *bio;
        int ret;
 
@@ -661,7 +662,8 @@ int blk_rq_map_kern(struct request *rq, void *kbuf, unsigned int len,
        if (!len || !kbuf)
                return -EINVAL;
 
-       if (!blk_rq_aligned(rq->q, addr, len) || object_is_on_stack(kbuf))
+       do_copy = !blk_rq_aligned(rq->q, addr, len) || object_is_on_stack(kbuf);
+       if (do_copy)
                bio = bio_copy_kern(rq, kbuf, len, gfp_mask);
        else
                bio = bio_map_kern(rq, kbuf, len, gfp_mask);
@@ -670,8 +672,11 @@ int blk_rq_map_kern(struct request *rq, void *kbuf, unsigned int len,
                return PTR_ERR(bio);
 
        ret = blk_rq_append_bio(rq, bio);
-       if (unlikely(ret))
+       if (unlikely(ret)) {
+               if (do_copy)
+                       bio_free_pages(bio);
                blk_mq_map_bio_put(bio);
+       }
        return ret;
 }
 EXPORT_SYMBOL(blk_rq_map_kern);