Re: [PATCH] smb: client: avoid leaking refcount when cifs_sb_tlink() fails

From: Namjae Jeon

Date: Fri Sep 04 2026 - 13:04:30 EST


On Fri, Sep 4, 2026 at 7:42 PM Bjoern Doebel <doebel@xxxxxxxxx> wrote:
>
> cifs_oplock_break() takes over the reference that
> cifs_queue_oplock_break() acquired when it queued the work, and drops it
> with _cifsFileInfo_put() once the break has been processed.
>
> Only in setups with "-o multiuser", cifs_sb_tlink() may fail, at which
> point cifs_oplock_break() returns without putting the file reference,
> mirroring the reference leak we already fixed in the companion patch to
> cifs_queue_oplock_break().
>
> This would trigger a crash due to busy inodes on the next unmount:
>
> BUG: Dentry ... still in use (1) [unmount of cifs cifs]
> VFS: Busy inodes after unmount of cifs (cifs)
>
> Drop the reference on that path as well. Doing so before the out label
> mirrors the normal path, which also puts the reference before
> cifs_done_oplock_break().
>
> Found by Sashiko code review. The failure path was not exercised at
> runtime.
>
> Fixes: e8f5f849ffce2 ("cifs: fix potential oops in cifs_oplock_break")
> Cc: stable@xxxxxxxxxxxxxxx
> Assisted-by: Kiro:claude-opus-5
> Signed-off-by: Bjoern Doebel <doebel@xxxxxxxxx>
Reviewed-by: Namjae Jeon <linkinjeon@xxxxxxxxxx>
Thanks!