xfs: fix buffer lookup vs release race
authorChristoph Hellwig <hch@lst.de>
Thu, 16 Jan 2025 06:01:42 +0000 (07:01 +0100)
committerCarlos Maiolino <cem@kernel.org>
Thu, 16 Jan 2025 09:19:59 +0000 (10:19 +0100)
commitee10f6fcdb961e810d7b16be1285319c15c78ef6
tree922781843c3071785b84fdb05fc6171c5010b0f9
parent07eae0fa67ca4bbb199ad85645e0f9dfaef931cd
xfs: fix buffer lookup vs release race

Since commit 298f34224506 ("xfs: lockless buffer lookup") the buffer
lookup fastpath is done without a hash-wide lock (then pag_buf_lock, now
bc_lock) and only under RCU protection.  But this means that nothing
serializes lookups against the temporary 0 reference count for buffers
that are added to the LRU after dropping the last regular reference,
and a concurrent lookup would fail to find them.

Fix this by doing all b_hold modifications under b_lock.  We're already
doing this for release so this "only" ~ doubles the b_lock round trips.
We'll later look into the lockref infrastructure to optimize the number
of lock round trips again.

Signed-off-by: Christoph Hellwig <hch@lst.de>
Reviewed-by: Darrick J. Wong <djwong@kernel.org>
Signed-off-by: Carlos Maiolino <cem@kernel.org>
fs/xfs/xfs_buf.c
fs/xfs/xfs_buf.h
fs/xfs/xfs_trace.h