Skip to content

Commit 909d9dc

Browse files
masalkhiYu Kuai
authored andcommitted
raid1: fix nr_pending leak in REQ_ATOMIC bad-block error path
In raid1_write_request(), each per-mirror loop iteration begins by incrementing rdev->nr_pending. If a REQ_ATOMIC write encounters a badblock within the requested range, the code jumps to err_handle without dropping the reference taken for the current mirror. err_handle's cleanup loop will only decrements for k < i and r1_bio->bios[k] is non-NULL. The current slot is therefore skipped, leaving its nr_pending reference leaked permanently. The reference prevents the rdev from ever being removed, since raid1_remove_conf() refuses to remove an rdev with nr_pending > 0. Fix this by calling rdev_dec_pending() before jumping to err_handle. Fixes: f2a38ab ("md/raid1: Atomic write support") Signed-off-by: Abd-Alrhman Masalkhi <abd.masalkhi@gmail.com> Link: https://patch.msgid.link/20260530151411.4119-1-abd.masalkhi@gmail.com Signed-off-by: Yu Kuai <yukuai@fygo.io>
1 parent 6e3b0b9 commit 909d9dc

1 file changed

Lines changed: 3 additions & 1 deletion

File tree

drivers/md/raid1.c

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1603,8 +1603,10 @@ static void raid1_write_request(struct mddev *mddev, struct bio *bio,
16031603
* complexity of supporting that is not worth
16041604
* the benefit.
16051605
*/
1606-
if (bio->bi_opf & REQ_ATOMIC)
1606+
if (bio->bi_opf & REQ_ATOMIC) {
1607+
rdev_dec_pending(rdev, mddev);
16071608
goto err_handle;
1609+
}
16081610

16091611
good_sectors = first_bad - r1_bio->sector;
16101612
if (good_sectors < max_sectors)

0 commit comments

Comments
 (0)