Re: [f2fs-dev] [PATCH] f2fs: cache: count the temporary pins apart from the regular references

From: Chao Yu

Date: Fri Oct 09 2026 - 03:27:36 EST


On 10/6/26 03:21, Daeho Jeong wrote:
> From: Daeho Jeong <daehojeong@xxxxxxxxxx>
>
> f2fs_unlock_cache() and f2fs_end_cache_writeback() take a temporary
> reference on the entry around clear_and_wake_up_bit(), so that the entry
> is not freed before wake_up_bit() returns. f2fs_destroy_cache() waits
> for the LOCKED and WRITEBACK bits and then expects the refcount to be 1,
> but the bit waits can return as soon as the bit is cleared, before the
> I/O completion drops the temporary reference. When the completion runs
> in process context and is preempted there (e.g. dm-flakey in
> generic/311), umount hits:
>
> kernel BUG at fs/f2fs/cache.c:567!
> f2fs_destroy_cache+0x260/0x268
> f2fs_put_super+0x1fc/0x428
>
> Count the temporary references in units of F2FS_CACHE_PIN_BIAS, like
> GUP_PIN_COUNTING_BIAS for folios, and check only the regular references
> in f2fs_destroy_cache(). A leaked regular reference is still caught
> there, without waiting for the completion.
>
> The pinned entry is freed by whichever of f2fs_cache_put() and
> f2fs_cache_unpin() drops the refcount to zero, as before. The shrinker
> still skips an entry while it is pinned, since the refcount is then
> neither 1 nor below 3.
>
> Fixes: 6e392158cf54 ("f2fs: cache: pin cached block in f2fs_end_cache_writeback()")
> Fixes: 61ba87b33e87 ("f2fs: cache: pin cached block in f2fs_unlock_cache()")
> Signed-off-by: Daeho Jeong <daehojeong@xxxxxxxxxx>
Reviewed-by: Chao Yu <chao@xxxxxxxxxx>

Thanks,