[PATCH] ext4: fix buffer_head leak in ext4_ind_map_blocks() error path
From: guolingxing
Date: Fri Oct 09 2026 - 02:35:10 EST
When ext4_ind_map_blocks() is called with EXT4_GET_BLOCKS_CREATE on
a non-extent mapped inode of a filesystem with the bigalloc feature
enabled, it fails with -EFSCORRUPTED via 'goto out'. However, at
this point ext4_get_branch() has already acquired buffer_head
references for the chain of indirect blocks, which are stored in
the stack variable 'chain'. Since 'goto out' skips the cleanup
loop that releases these references, they are leaked permanently
(each failed allocation can leak up to 3 buffer_heads, and repeated
allocation attempts keep pinning the corresponding pages in memory).
Jump to 'cleanup' instead, so that the chain of buffer_heads is
properly released before the error is returned.
Signed-off-by: guolingxing <guolingxing@xxxxxxxxxx>
---
fs/ext4/indirect.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/fs/ext4/indirect.c b/fs/ext4/indirect.c
index 5aec759eed70..9f1f4e6c37a4 100644
--- a/fs/ext4/indirect.c
+++ b/fs/ext4/indirect.c
@@ -603,7 +603,7 @@ int ext4_ind_map_blocks(handle_t *handle, struct inode *inode,
EXT4_ERROR_INODE(inode, "Can't allocate blocks for "
"non-extent mapped inodes with bigalloc");
err = -EFSCORRUPTED;
- goto out;
+ goto cleanup;
}
/* Set up for the direct block allocation */
--
2.34.1