Re: [PATCH] dm-pcache: fix use-after-free during cache replay
Shuangpeng <[email protected]> Thu, 6 Aug 2026 10:44:39 -0400
| Newsgroups | dev.linux.lists.dm-devel,org.kernel.vger.linux-kernel |
|---|---|
| Message-ID | <[email protected]> |
> On Aug 6, 2026, at 07:48, Mikulas Patocka <[email protected]> wrote: >=20 > Hi >=20 > This patch doesn't apply to the current device mapper working tree = because=20 > another patch was already committed there: c2e894eac398 ("dm-pcache: = fix=20 > use-after-free and invalid seg operations in kset_replay()"). >=20 > Please, download the current device mapper repository from=20 > = git://git.kernel.org/pub/scm/linux/kernel/git/device-mapper/linux-dm.git >=20 > Checkout the branch for-next. >=20 > Verify that the bug is still present there. Thanks for pointing this out. Please ignore this patch. Sorry for the noise. Shuangpeng >=20 > If yes, send the patch against the "for-next" branch. >=20 > Mikulas >=20 >=20 >=20 > On Wed, 5 Aug 2026, Shuangpeng Bai wrote: >=20 >> kset_replay() drops the last reference to a stale cache key before >> using key->cache_pos to acquire a reference to its cache segment. = This >> can dereference the freed key. >>=20 >> Segment references account for key records that have not yet been >> consumed by key-log garbage collection. A reference is acquired for >> every successfully recorded key, and the GC path drops one for every >> record, including records whose segment generation has become stale. >> Replay therefore has to restore the segment reference before deciding >> whether the decoded key should be inserted into the request-key tree. >>=20 >> Move cache_seg_get() before the generation check. This preserves the >> get/put accounting for stale records while ensuring that the key is = not >> accessed after cache_key_put(). >>=20 >> Fixes: 1d57628ff95b ("dm-pcache: add persistent cache target in = device-mapper") >>=20 >> Signed-off-by: Shuangpeng Bai <[email protected]> >> --- >> drivers/md/dm-pcache/cache_key.c | 3 +-- >> 1 file changed, 1 insertion(+), 2 deletions(-) >>=20 >> diff --git a/drivers/md/dm-pcache/cache_key.c = b/drivers/md/dm-pcache/cache_key.c >> index e068e878231b..b37d899f2d3c 100644 >> --- a/drivers/md/dm-pcache/cache_key.c >> +++ b/drivers/md/dm-pcache/cache_key.c >> @@ -729,6 +729,7 @@ static int kset_replay(struct pcache_cache = *cache, struct pcache_cache_kset_onme >> } >>=20 >> __set_bit(key->cache_pos.cache_seg->cache_seg_id, cache->seg_map); >> + cache_seg_get(key->cache_pos.cache_seg); >>=20 >> /* Check if the segment generation is valid for insertion. */ >> if (key->seg_gen < key->cache_pos.cache_seg->gen) { >> @@ -739,8 +740,6 @@ static int kset_replay(struct pcache_cache = *cache, struct pcache_cache_kset_onme >> cache_key_insert(&cache->req_key_tree, key, true); >> spin_unlock(&cache_subtree->tree_lock); >> } >> - >> - cache_seg_get(key->cache_pos.cache_seg); >> } >>=20 >> return 0; >> --=20 >> 2.43.0 >>=20 >=20