Re: [PATCH] btrfs: preserve caller ownership of anon_dev on root insert retry
From: Qu Wenruo
Date: Mon Oct 05 2026 - 17:42:07 EST
在 2026/10/6 07:53, sungbyeongchan 写道:
create_subvol() preallocates an anonymous block-device ID and passes it to
btrfs_get_new_fs_root(). On a cache miss, btrfs_get_root_ref() assigns that ID
to a temporary root before attempting to insert the root in the cache.
If another caller inserts the same root first, the creator gets -EEXIST and
drops the temporary root. The final put frees root->anon_dev, but the caller's
*anon_dev still contains the same ID. The retry finds the cached root and
frees the caller's ID again, producing an ida_free warning.
Please provide the warning message.
Keep ownership with the caller across the retry by clearing the losing
temporary root's anon_dev when the ID was supplied by the caller. Roots that
allocated their own ID retain the existing destruction behavior.
The unfixed sequence was reproduced in two clean boots.
And reproducer.
With this change the
creator-side -EEXIST branch was exercised twice, each caller-owned ID was
released exactly once on retry, no ida_free warning occurred, and ordinary
subvolume creation, writes, qgroup display, and clean unmount passed.
Fixes: 2dfb1e43f57d ("btrfs: preallocate anon block device at first phase of snapshot creation")
Reported-by: sungbyeongchan <tjdqudcks0424@xxxxxxxxx>
Tested-by: sungbyeongchan <tjdqudcks0424@xxxxxxxxx>
Assisted-by: LLM
Signed-off-by: sungbyeongchan <tjdqudcks0424@xxxxxxxxx>
Cc: stable@xxxxxxxxxxxxxxx
---
fs/btrfs/disk-io.c | 2 ++
1 file changed, 2 insertions(+)
diff --git a/fs/btrfs/disk-io.c b/fs/btrfs/disk-io.c
index dc7ad92876c0..4a5e43dfde6f 100644
--- a/fs/btrfs/disk-io.c
+++ b/fs/btrfs/disk-io.c
@@ -1355,6 +1355,8 @@ again:
ret = btrfs_insert_fs_root(fs_info, root);
if (ret) {
if (ret == -EEXIST) {
+ if (anon_dev && *anon_dev)
+ root->anon_dev = 0;
btrfs_put_root(root);
goto again;
}