[PATCH v3] f2fs: wait for inode record work before clearing ino bitmaps
From: Wenjie Qi
Date: Wed Sep 02 2026 - 05:20:21 EST
APPEND/UPDATE inode state recording was moved to the inode eviction
workqueue. These entries were later converted to bitmap values stored in
XArrays, but the workqueue drain was left behind in the list cleanup loop
where it is now a no-op.
During unmount, inode eviction work can therefore remain queued when
f2fs_release_ino_entry() destroys the bitmap XArrays. A delayed worker can
repopulate them before the workqueue is finally destroyed, leaking newly
allocated XArray nodes when the F2FS superblock is freed.
Wait for APPEND/UPDATE inode record work before destroying each bitmap
XArray, restoring the required ordering.
Fixes: 9a9ee7408a1f ("f2fs: reduce memory footprint of ino management")
Signed-off-by: Wenjie Qi <qiwenjie@xxxxxxxxxx>
---
v3:
- Call flush_workqueue() directly, remove the obsolete helper, and retain
a comment explaining the APPEND/UPDATE state-record wait.
fs/f2fs/checkpoint.c | 14 +++-----------
1 file changed, 3 insertions(+), 11 deletions(-)
diff --git a/fs/f2fs/checkpoint.c b/fs/f2fs/checkpoint.c
index 4b59f30ef45d5..cf88b463fde51 100644
--- a/fs/f2fs/checkpoint.c
+++ b/fs/f2fs/checkpoint.c
@@ -825,15 +825,6 @@ static void __clear_ino_bitmap(struct f2fs_sb_info *sbi, nid_t ino, int type)
spin_unlock(&im->ino_lock);
}
-static void f2fs_wait_for_inode_record(struct f2fs_sb_info *sbi, int mode)
-{
- if (mode != APPEND_INO && mode != UPDATE_INO)
- return;
-
- /* Let's wait for some pending updates for APPEND_INO and UPDATE_INO. */
- flush_workqueue(sbi->evict_wq);
-}
-
static void __f2fs_add_ino_entry(struct f2fs_sb_info *sbi, nid_t ino,
unsigned int devidx, int type)
{
@@ -887,8 +878,6 @@ void f2fs_release_ino_entry(struct f2fs_sb_info *sbi, bool all)
for (i = all ? ORPHAN_INO : FLUSH_INO; i <= FLUSH_INO; i++) {
struct inode_management *im = &sbi->im[i];
- f2fs_wait_for_inode_record(sbi, i);
-
spin_lock(&im->ino_lock);
list_for_each_entry_safe(e, tmp, &im->ino_list, list) {
list_del(&e->list);
@@ -899,6 +888,9 @@ void f2fs_release_ino_entry(struct f2fs_sb_info *sbi, bool all)
spin_unlock(&im->ino_lock);
}
+ /* Wait for pending APPEND/UPDATE inode state updates. */
+ flush_workqueue(sbi->evict_wq);
+
for (i = APPEND_INO; i < MAX_INO_ENTRY; i++) {
struct inode_management *im = &sbi->im[i];
--
2.43.0