Re: [PATCH] dm-pcache: fix use-after-free during cache replay

Shuangpeng <[email protected]> Thu, 6 Aug 2026 10:44:39 -0400
Newsgroups dev.linux.lists.dm-devel,org.kernel.vger.linux-kernel
Message-ID <[email protected]>

> On Aug 6, 2026, at 07:48, Mikulas Patocka <[email protected]> wrote:
>=20
> Hi
>=20
> This patch doesn't apply to the current device mapper working tree =
because=20
> another patch was already committed there: c2e894eac398 ("dm-pcache: =
fix=20
> use-after-free and invalid seg operations in kset_replay()").
>=20
> Please, download the current device mapper repository from=20
> =
git://git.kernel.org/pub/scm/linux/kernel/git/device-mapper/linux-dm.git
>=20
> Checkout the branch for-next.
>=20
> Verify that the bug is still present there.

Thanks for pointing this out. Please ignore this patch.
Sorry for the noise.

Shuangpeng

>=20
> If yes, send the patch against the "for-next" branch.
>=20
> Mikulas
>=20
>=20
>=20
> On Wed, 5 Aug 2026, Shuangpeng Bai wrote:
>=20
>> kset_replay() drops the last reference to a stale cache key before
>> using key->cache_pos to acquire a reference to its cache segment. =
This
>> can dereference the freed key.
>>=20
>> Segment references account for key records that have not yet been
>> consumed by key-log garbage collection. A reference is acquired for
>> every successfully recorded key, and the GC path drops one for every
>> record, including records whose segment generation has become stale.
>> Replay therefore has to restore the segment reference before deciding
>> whether the decoded key should be inserted into the request-key tree.
>>=20
>> Move cache_seg_get() before the generation check. This preserves the
>> get/put accounting for stale records while ensuring that the key is =
not
>> accessed after cache_key_put().
>>=20
>> Fixes: 1d57628ff95b ("dm-pcache: add persistent cache target in =
device-mapper")
>>=20
>> Signed-off-by: Shuangpeng Bai <[email protected]>
>> ---
>> drivers/md/dm-pcache/cache_key.c | 3 +--
>> 1 file changed, 1 insertion(+), 2 deletions(-)
>>=20
>> diff --git a/drivers/md/dm-pcache/cache_key.c =
b/drivers/md/dm-pcache/cache_key.c
>> index e068e878231b..b37d899f2d3c 100644
>> --- a/drivers/md/dm-pcache/cache_key.c
>> +++ b/drivers/md/dm-pcache/cache_key.c
>> @@ -729,6 +729,7 @@ static int kset_replay(struct pcache_cache =
*cache, struct pcache_cache_kset_onme
>> }
>>=20
>> __set_bit(key->cache_pos.cache_seg->cache_seg_id, cache->seg_map);
>> + cache_seg_get(key->cache_pos.cache_seg);
>>=20
>> /* Check if the segment generation is valid for insertion. */
>> if (key->seg_gen < key->cache_pos.cache_seg->gen) {
>> @@ -739,8 +740,6 @@ static int kset_replay(struct pcache_cache =
*cache, struct pcache_cache_kset_onme
>> cache_key_insert(&cache->req_key_tree, key, true);
>> spin_unlock(&cache_subtree->tree_lock);
>> }
>> -
>> - cache_seg_get(key->cache_pos.cache_seg);
>> }
>>=20
>> return 0;
>> --=20
>> 2.43.0
>>=20
>=20