https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=281749
--- Comment #37 from Konstantin Belousov <[email protected]> --- Try this commit 5aa7a767a5d20baecb891892c971672bd7d97c98 Author: Konstantin Belousov <[email protected]> Date: Thu May 28 12:42:38 2026 +0300 vtryrecycle(): do not recycle used vnode It is possible for a vnode to be vref-ed or vuse-ed lockless after it is held by vhold_recycle_free(). Then, since vtryrecycle() does not recheck the hold count, we might end up freeing vused vnode. diff --git a/sys/kern/vfs_subr.c b/sys/kern/vfs_subr.c index e43a574a0881..aa07e3ef6ceb 100644 --- a/sys/kern/vfs_subr.c +++ b/sys/kern/vfs_subr.c @@ -1936,9 +1936,14 @@ vtryrecycle(struct vnode *vp, bool isvnlru) * anyone picked up this vnode from another list. If not, we will * mark it with DOOMED via vgonel() so that anyone who does find it * will skip over it. + * + * We cannot check only for v_usecount > 0 there, since + * v_usecount increment is lockless. Instead also check + * v_holdcnt, allowing the situation where a parallel vhold() + * unneccessary aborts freeing this vnode. */ VI_LOCK(vp); - if (vp->v_usecount) { + if (vp->v_usecount > 0 || vp->v_holdcnt > 1) { VOP_UNLOCK(vp); vdropl_recycle(vp); vn_finished_write(vnmp); -- You are receiving this mail because: You are the assignee for the bug.
