Re: [PATCH v4 1/4] blk-cgroup: protect q->blkg_list iteration in blkg_destroy_all() with blkcg_mutex
From: Tao Cui
Date: Sun Aug 02 2026 - 07:45:42 EST
于 2026年8月2日 GMT+08:00 19:25:17,Yu Kuai <yukuai@xxxxxxxxxx> 写道:
>From: Yu Kuai <yukuai@xxxxxxx>
>
>blkg_destroy_all() iterates q->blkg_list without holding blkcg_mutex,
>which can race with blkg_free_workfn() that removes blkgs from the list
>while holding blkcg_mutex.
>
>Add blkcg_mutex protection around the q->blkg_list iteration to prevent
>potential list corruption or use-after-free issues.
>
>Reviewed-by: Tang Yizhou <yizhou.tang@xxxxxxxxxx>
>Signed-off-by: Yu Kuai <yukuai@xxxxxxx>
>---
> block/blk-cgroup.c | 3 +++
> 1 file changed, 3 insertions(+)
>
>diff --git a/block/blk-cgroup.c b/block/blk-cgroup.c
>index d9676126c5b5..eb0cfb10b859 100644
>--- a/block/blk-cgroup.c
>+++ b/block/blk-cgroup.c
>@@ -569,6 +569,7 @@ static void blkg_destroy_all(struct gendisk *disk)
> int i;
>
> restart:
>+ mutex_lock(&q->blkcg_mutex);
> spin_lock_irq(&q->queue_lock);
> list_for_each_entry(blkg, &q->blkg_list, q_node) {
> struct blkcg *blkcg = blkg->blkcg;
>@@ -587,6 +588,7 @@ static void blkg_destroy_all(struct gendisk *disk)
> if (!(--count)) {
> count = BLKG_DESTROY_BATCH_SIZE;
> spin_unlock_irq(&q->queue_lock);
>+ mutex_unlock(&q->blkcg_mutex);
> cond_resched();
> goto restart;
> }
>@@ -606,6 +608,7 @@ static void blkg_destroy_all(struct gendisk *disk)
>
> q->root_blkg = NULL;
> spin_unlock_irq(&q->queue_lock);
>+ mutex_unlock(&q->blkcg_mutex);
>
> wake_up_var(&q->root_blkg);
> }
Reviewed-by: Tao Cui <cuitao@xxxxxxxxxx>