]> git.ipfire.org Git - thirdparty/kernel/linux.git/commitdiff
ceph: fix writeback_count leak in write_folio_nounlock()
authorWentao Liang <vulab@iscas.ac.cn>
Thu, 4 Jun 2026 02:19:51 +0000 (02:19 +0000)
committerIlya Dryomov <idryomov@gmail.com>
Thu, 23 Jul 2026 18:29:41 +0000 (20:29 +0200)
write_folio_nounlock() increments fsc->writeback_count to track
in-flight writeback operations. On several error paths where the
function returns early (folio lookup failure, snapshot context
allocation failure, and writepages submission failure), the function
returns without calling atomic_long_dec_return() to decrement the
counter.

Each leaked increment keeps the counter above zero, which can prevent
the filesystem from cleanly unmounting or suspending writes.

Add atomic_long_dec_return() calls on all error paths that currently
return without decrementing the counter.

Cc: stable@vger.kernel.org
Fixes: d55207717ded ("ceph: add encryption support to writepage and writepages")
Signed-off-by: Wentao Liang <vulab@iscas.ac.cn>
Reviewed-by: Viacheslav Dubeyko <Slava.Dubeyko@ibm.com>
Signed-off-by: Ilya Dryomov <idryomov@gmail.com>
fs/ceph/addr.c

index 61bd6d92ff257afd01753a3cf9f06e57db79a702..ecf33b66610c87b0ae54b03b8f0e59c065e5e13f 100644 (file)
@@ -790,6 +790,9 @@ static int write_folio_nounlock(struct folio *folio,
                                    ceph_wbc.truncate_size, true);
        if (IS_ERR(req)) {
                folio_redirty_for_writepage(wbc, folio);
+               if (atomic_long_dec_return(&fsc->writeback_count) <
+                               CONGESTION_OFF_THRESH(fsc->mount_options->congestion_kb))
+                       fsc->write_congested = false;
                return PTR_ERR(req);
        }
 
@@ -809,6 +812,9 @@ static int write_folio_nounlock(struct folio *folio,
                        folio_redirty_for_writepage(wbc, folio);
                        folio_end_writeback(folio);
                        ceph_osdc_put_request(req);
+                       if (atomic_long_dec_return(&fsc->writeback_count) <
+                                       CONGESTION_OFF_THRESH(fsc->mount_options->congestion_kb))
+                               fsc->write_congested = false;
                        return PTR_ERR(bounce_page);
                }
        }
@@ -847,6 +853,9 @@ static int write_folio_nounlock(struct folio *folio,
                              ceph_vinop(inode), folio);
                        folio_redirty_for_writepage(wbc, folio);
                        folio_end_writeback(folio);
+                       if (atomic_long_dec_return(&fsc->writeback_count) <
+                                       CONGESTION_OFF_THRESH(fsc->mount_options->congestion_kb))
+                               fsc->write_congested = false;
                        return err;
                }
                if (err == -EBLOCKLISTED)