Re: [PATCH] smb: client: free partially allocated transform folio queue
From: Steve French
Date: Mon Jul 27 2026 - 18:36:45 EST
Merged into cifs-2.6.git for-next
On Mon, Jul 27, 2026 at 8:41 AM ChenXiaoSong
<chenxiaosong@xxxxxxxxxxxxxxxx> wrote:
>
> Reviewed-by: ChenXiaoSong <chenxiaosong@xxxxxxxxxx>
>
> 在 2026/7/4 13:27, Yichong Chen 写道:
> > netfs_alloc_folioq_buffer() may leave a partially allocated folio
> > queue attached to the caller's buffer pointer when it returns an error.
> >
> > smb3_init_transform_rq() stores the buffer in the request only after
> > allocation succeeds, so the common error path cannot free a partial
> > allocation. Store the buffer pointer before checking the return value so
> > err_free releases it.
> >
> > Signed-off-by: Yichong Chen <chenyichong@xxxxxxxxxxxxx>
> > ---
> > fs/smb/client/smb2ops.c | 2 +-
> > 1 file changed, 1 insertion(+), 1 deletion(-)
> >
> > diff --git a/fs/smb/client/smb2ops.c b/fs/smb/client/smb2ops.c
> > index 199f6aeb7b33..3fe9f0534e42 100644
> > --- a/fs/smb/client/smb2ops.c
> > +++ b/fs/smb/client/smb2ops.c
> > @@ -4882,10 +4882,10 @@ smb3_init_transform_rq(struct TCP_Server_Info *server, int num_rqst,
> > size_t cur_size = 0;
> > rc = netfs_alloc_folioq_buffer(NULL, &buffer, &cur_size,
> > size, GFP_NOFS);
> > + new->rq_buffer = buffer;
> > if (rc < 0)
> > goto err_free;
> >
> > - new->rq_buffer = buffer;
> > iov_iter_folio_queue(&new->rq_iter, ITER_SOURCE,
> > buffer, 0, 0, size);
> >
>
> --
> ChenXiaoSong <chenxiaosong@xxxxxxxxxxxxxxxx>
> Chinese Homepage: https://chenxiaosong.com
> English Homepage: https://chenxiaosong.com/en
>
>
--
Thanks,
Steve