[PATCH v2 0/2] hfsplus, hfs: fix B-tree node leak on hfs_btree_open() error path
From: Mahmut Emin Kurhan
Date: Wed Sep 30 2026 - 20:36:08 EST
This is v2 of the hfsplus B-tree node leak fix.
Slava, thanks for the review. Addressing your points:
- HFS: you are right. The classic HFS driver has the identical leak:
__hfs_bnode_create() hashes the node before reading its pages,
hfs_bnode_put() only frees a node when HFS_BNODE_DELETED is set, and
hfs_btree_open() does a bare kfree(tree) on its error path. Fixed in
patch 2/2.
- Dropped the inline block and the duplicate variable declarations. The
freeing loop is now a small helper, hfs_bnode_hash_free(), reused by
both hfs_btree_close() and the hfs_btree_open() error path, so nothing
extra is declared at the call site.
- hash_lock: correct -- it is not taken because hfs_btree_open() has not
published the tree yet (it is only returned on success), so no other
thread can reach node_hash. hfs_btree_close() omits it for the same
reason.
v1: https://lore.kernel.org/linux-fsdevel/20260930185033.1335238-1-guvenlik@xxxxxxxxxx
Changes since v1:
- factor the node-hash freeing into hfs_bnode_hash_free() (Slava Dubeyko)
- no inline braces / no duplicate declarations (Slava Dubeyko)
- add the equivalent fix for the classic HFS driver (Slava Dubeyko)
Mahmut Emin Kurhan (2):
hfsplus: free cached B-tree nodes on hfs_btree_open() error path
hfs: free cached B-tree nodes on hfs_btree_open() error path
fs/hfs/btree.c | 34 ++++++++++++++++++++--------------
fs/hfsplus/btree.c | 35 ++++++++++++++++++++---------------
2 files changed, 40 insertions(+), 29 deletions(-)
--
2.43.0