From: Vasily Gorbik Date: Sun, 22 Mar 2026 02:35:10 +0000 (+0100) Subject: block: fix bio_alloc_bioset slowpath GFP handling X-Git-Url: http://git.ipfire.org/gitweb.cgi?a=commitdiff_plain;h=67807fbaf12719fca46a622d759484652b79c7c3;p=thirdparty%2Flinux.git block: fix bio_alloc_bioset slowpath GFP handling bio_alloc_bioset() first strips __GFP_DIRECT_RECLAIM from the optimistic fast allocation attempt with try_alloc_gfp(). If that fast path fails, the slowpath checks saved_gfp to decide whether blocking allocation is allowed, but then still calls mempool_alloc() with the stripped gfp mask. That can lead to a NULL bio pointer being passed into bio_init(). Fix the slowpath by using saved_gfp for the bio and bvec mempool allocations. Fixes: b520c4eef83d ("block: split bio_alloc_bioset more clearly into a fast and slowpath") Reported-by: syzbot+09ddb593eea76a158f42@syzkaller.appspotmail.com Signed-off-by: Vasily Gorbik Reviewed-by: Christoph Hellwig Link: https://patch.msgid.link/p01.gc6e9ad5845ad.ttca29g@ub.hpns Signed-off-by: Jens Axboe --- diff --git a/block/bio.c b/block/bio.c index 5057047194c49..77067fa346d35 100644 --- a/block/bio.c +++ b/block/bio.c @@ -581,11 +581,11 @@ struct bio *bio_alloc_bioset(struct block_device *bdev, unsigned short nr_vecs, */ opf &= ~REQ_ALLOC_CACHE; - p = mempool_alloc(&bs->bio_pool, gfp); + p = mempool_alloc(&bs->bio_pool, saved_gfp); bio = p + bs->front_pad; if (nr_vecs > BIO_INLINE_VECS) { nr_vecs = BIO_MAX_VECS; - bvecs = mempool_alloc(&bs->bvec_pool, gfp); + bvecs = mempool_alloc(&bs->bvec_pool, saved_gfp); } }