From be97a4b63ca8c3ed8f5c3f5606a15a8379c78afb Mon Sep 17 00:00:00 2001 From: Mateusz Guzik Date: Wed, 1 Oct 2025 03:00:10 +0200 Subject: [PATCH] fs: assert on ->i_count in iput_final() Notably make sure the count is 0 after the return from ->drop_inode(), provided we are going to drop. Inspired by suspicious games played by f2fs. Signed-off-by: Mateusz Guzik Signed-off-by: Christian Brauner --- fs/inode.c | 7 +++++++ 1 file changed, 7 insertions(+) diff --git a/fs/inode.c b/fs/inode.c index ec9339024ac36..fa82cb810af44 100644 --- a/fs/inode.c +++ b/fs/inode.c @@ -1879,6 +1879,7 @@ static void iput_final(struct inode *inode) int drop; WARN_ON(inode->i_state & I_NEW); + VFS_BUG_ON_INODE(atomic_read(&inode->i_count) != 0, inode); if (op->drop_inode) drop = op->drop_inode(inode); @@ -1893,6 +1894,12 @@ static void iput_final(struct inode *inode) return; } + /* + * Re-check ->i_count in case the ->drop_inode() hooks played games. + * Note we only execute this if the verdict was to drop the inode. + */ + VFS_BUG_ON_INODE(atomic_read(&inode->i_count) != 0, inode); + state = inode->i_state; if (!drop) { WRITE_ONCE(inode->i_state, state | I_WILL_FREE); -- 2.47.3