[PATCH] md/raid5: drain released_stripes before destroying the cache
From: Li Youhong
Date: Tue Sep 29 2026 - 04:44:27 EST
From: Li Youhong <liyouhong@xxxxxxxxxx>
grow_one_stripe() calls raid5_release_stripe() for each new stripe.
When mddev->thread is already set, that queues the stripe on
conf->released_stripes and wakes the thread. Only raid5d moves that
list onto inactive_list.
Takeover calls setup_conf() while mddev->thread still belongs to the
previous personality, so those stripes stay on released_stripes. If
setup_conf() then fails, shrink_stripes() only frees inactive_list and
kmem_cache_destroy() warns that objects remain.
Move stripes still queued on released_stripes onto inactive_list
before shrink_stripes() frees them.
Fixes: 773ca82fa1ee ("raid5: make release_stripe lockless")
Reported-by: syzbot+6a132745caefcf42cb0d@xxxxxxxxxxxxxxxxxxxxxxxxx
Closes: https://lore.kernel.org/linux-raid/6ab6b743.7eec07f4.c25c.0006.GAE@xxxxxxxxxx/T/#t
Signed-off-by: Li Youhong <liyouhong@xxxxxxxxxx>
---
drivers/md/raid5.c | 31 +++++++++++++++++++++++++++++++
1 file changed, 31 insertions(+)
diff --git a/drivers/md/raid5.c b/drivers/md/raid5.c
index b91545ce090d..8f375a596312 100644
--- a/drivers/md/raid5.c
+++ b/drivers/md/raid5.c
@@ -2712,6 +2712,37 @@ static int drop_one_stripe(struct r5conf *conf)
static void shrink_stripes(struct r5conf *conf)
{
+ struct list_head temp[NR_STRIPE_HASH_LOCKS];
+ int i;
+
+ /*
+ * grow_one_stripe() parks new stripes on released_stripes when
+ * mddev->thread is already set. Takeover leaves the previous
+ * personality's thread there, so raid5d never moves them to
+ * inactive_list. Drain them before the cache is destroyed.
+ * slab_cache is assigned only after device_lock and the hash
+ * lists exist; earlier abort paths have nothing to drain.
+ */
+ if (conf->slab_cache) {
+ for (i = 0; i < NR_STRIPE_HASH_LOCKS; i++)
+ INIT_LIST_HEAD(&temp[i]);
+
+ spin_lock_irq(&conf->device_lock);
+ release_stripe_list(conf, temp);
+ spin_unlock_irq(&conf->device_lock);
+
+ for (i = 0; i < NR_STRIPE_HASH_LOCKS; i++) {
+ if (list_empty(&temp[i]))
+ continue;
+ spin_lock_irq(conf->hash_locks + i);
+ if (list_empty(conf->inactive_list + i))
+ atomic_dec(&conf->empty_inactive_list_nr);
+ list_splice_tail_init(&temp[i],
+ conf->inactive_list + i);
+ spin_unlock_irq(conf->hash_locks + i);
+ }
+ }
+
while (conf->max_nr_stripes &&
drop_one_stripe(conf))
;
--
2.43.0