Re: [PATCH] dm-pcache: fix use-after-free during cache replay

Mikulas Patocka <[email protected]> Thu, 6 Aug 2026 13:48:08 +0200 (CEST)
Newsgroups dev.linux.lists.dm-devel,org.kernel.vger.linux-kernel
Message-ID <[email protected]>
Hi

This patch doesn't apply to the current device mapper working tree because 
another patch was already committed there: c2e894eac398 ("dm-pcache: fix 
use-after-free and invalid seg operations in kset_replay()").

Please, download the current device mapper repository from 
git://git.kernel.org/pub/scm/linux/kernel/git/device-mapper/linux-dm.git

Checkout the branch for-next.

Verify that the bug is still present there.

If yes, send the patch against the "for-next" branch.

Mikulas



On Wed, 5 Aug 2026, Shuangpeng Bai wrote:

> kset_replay() drops the last reference to a stale cache key before
> using key->cache_pos to acquire a reference to its cache segment. This
> can dereference the freed key.
> 
> Segment references account for key records that have not yet been
> consumed by key-log garbage collection. A reference is acquired for
> every successfully recorded key, and the GC path drops one for every
> record, including records whose segment generation has become stale.
> Replay therefore has to restore the segment reference before deciding
> whether the decoded key should be inserted into the request-key tree.
> 
> Move cache_seg_get() before the generation check. This preserves the
> get/put accounting for stale records while ensuring that the key is not
> accessed after cache_key_put().
> 
> Fixes: 1d57628ff95b ("dm-pcache: add persistent cache target in device-mapper")
> 
> Signed-off-by: Shuangpeng Bai <[email protected]>
> ---
>  drivers/md/dm-pcache/cache_key.c | 3 +--
>  1 file changed, 1 insertion(+), 2 deletions(-)
> 
> diff --git a/drivers/md/dm-pcache/cache_key.c b/drivers/md/dm-pcache/cache_key.c
> index e068e878231b..b37d899f2d3c 100644
> --- a/drivers/md/dm-pcache/cache_key.c
> +++ b/drivers/md/dm-pcache/cache_key.c
> @@ -729,6 +729,7 @@ static int kset_replay(struct pcache_cache *cache, struct pcache_cache_kset_onme
>  		}
>  
>  		__set_bit(key->cache_pos.cache_seg->cache_seg_id, cache->seg_map);
> +		cache_seg_get(key->cache_pos.cache_seg);
>  
>  		/* Check if the segment generation is valid for insertion. */
>  		if (key->seg_gen < key->cache_pos.cache_seg->gen) {
> @@ -739,8 +740,6 @@ static int kset_replay(struct pcache_cache *cache, struct pcache_cache_kset_onme
>  			cache_key_insert(&cache->req_key_tree, key, true);
>  			spin_unlock(&cache_subtree->tree_lock);
>  		}
> -
> -		cache_seg_get(key->cache_pos.cache_seg);
>  	}
>  
>  	return 0;
> -- 
> 2.43.0
>