]> git.ipfire.org Git - thirdparty/kernel/linux.git/commitdiff
xfs: fix ilock leak on error in xfs_dq_get_next_id
authorLong Li <leo.lilong@huawei.com>
Mon, 27 Jul 2026 02:38:48 +0000 (10:38 +0800)
committerCarlos Maiolino <cem@kernel.org>
Mon, 3 Aug 2026 08:21:33 +0000 (10:21 +0200)
xfs_dq_get_next_id() takes the quota inode ILOCK before calling
xfs_iread_extents().  If xfs_iread_extents() fails, the function returns
immediately without releasing the lock, leaking the quota inode ILOCK.
This can leave the quota inode locked and cause subsequent quota
operations to hang.

Fix this by jumping to a common unlock path on error instead of returning
directly.

Fixes: bda250dbaf39f ("xfs: rewrite xfs_dq_get_next_id using xfs_iext_lookup_extent")
Cc: stable@vger.kernel.org # v4.12
Signed-off-by: Long Li <leo.lilong@huawei.com>
Reviewed-by: Christoph Hellwig <hch@lst.de>
Reviewed-by: Darrick J. Wong <djwong@kernel.org>
Signed-off-by: Carlos Maiolino <cem@kernel.org>
fs/xfs/xfs_dquot.c

index c311f61d9554178defb7f6ec0b1dbc5d4d959da5..b4f6c594808ce9230c16a2bd339f8ce720d3b94e 100644 (file)
@@ -778,7 +778,7 @@ xfs_dq_get_next_id(
        lock_flags = xfs_ilock_data_map_shared(quotip);
        error = xfs_iread_extents(NULL, quotip, XFS_DATA_FORK);
        if (error)
-               return error;
+               goto out_unlock;
 
        if (xfs_iext_lookup_extent(quotip, &quotip->i_df, start, &cur, &got)) {
                /* contiguous chunk, bump startoff for the id calculation */
@@ -789,6 +789,7 @@ xfs_dq_get_next_id(
                error = -ENOENT;
        }
 
+out_unlock:
        xfs_iunlock(quotip, lock_flags);
 
        return error;