Re: [PATCH] cachefiles: fix incorrect dentry refcount in cachefiles_cull()

From: Paulo Alcantara

Date: Thu Mar 26 2026 - 19:17:04 EST


NeilBrown <neilb@xxxxxxxxxxx> writes:

> The patch mentioned below changed cachefiles_bury_object() to expect 2
> references to the 'rep' dentry. Three of the callers were changed to
> use start_removing_dentry() which takes an extra reference so in those
> cases the call gets the expected references.
>
> However there is another call to cachefiles_bury_object() in
> cachefiles_cull() which did not need to be changed to use
> start_removing_dentry() and so was not properly considered.
> It still passed the dentry with just one reference so the net result is
> that a reference is lost.
>
> To meet the expectations of cachefiles_bury_object(), cachefiles_cull()
> must take an extra reference before the call. It will be dropped by
> cachefiles_bury_object().
>
> Reported-by: Marc Dionne <marc.dionne@xxxxxxxxxxxx>
> Fixes: 7bb1eb45e43c ("VFS: introduce start_removing_dentry()")
> Signed-off-by: NeilBrown <neil@xxxxxxxxxx>
> ---
> fs/cachefiles/namei.c | 5 +++++
> 1 file changed, 5 insertions(+)

Acked-by: Paulo Alcantara (Red Hat) <pc@xxxxxxxxxxxxx>