https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=281749

--- Comment #37 from Konstantin Belousov <[email protected]> ---
Try this

commit 5aa7a767a5d20baecb891892c971672bd7d97c98
Author: Konstantin Belousov <[email protected]>
Date:   Thu May 28 12:42:38 2026 +0300

    vtryrecycle(): do not recycle used vnode

    It is possible for a vnode to be vref-ed or vuse-ed lockless after it is
    held by vhold_recycle_free(). Then, since vtryrecycle() does not recheck
    the hold count, we might end up freeing vused vnode.

diff --git a/sys/kern/vfs_subr.c b/sys/kern/vfs_subr.c
index e43a574a0881..aa07e3ef6ceb 100644
--- a/sys/kern/vfs_subr.c
+++ b/sys/kern/vfs_subr.c
@@ -1936,9 +1936,14 @@ vtryrecycle(struct vnode *vp, bool isvnlru)
         * anyone picked up this vnode from another list.  If not, we will
         * mark it with DOOMED via vgonel() so that anyone who does find it
         * will skip over it.
+        *
+        * We cannot check only for v_usecount > 0 there, since
+        * v_usecount increment is lockless.  Instead also check
+        * v_holdcnt, allowing the situation where a parallel vhold()
+        * unneccessary aborts freeing this vnode.
         */
        VI_LOCK(vp);
-       if (vp->v_usecount) {
+       if (vp->v_usecount > 0 || vp->v_holdcnt > 1) {
                VOP_UNLOCK(vp);
                vdropl_recycle(vp);
                vn_finished_write(vnmp);

-- 
You are receiving this mail because:
You are the assignee for the bug.

Reply via email to