Matt Benjamin has uploaded this change for review.

View Change

mdcache: fixes for statle chunk->parent linkage after invalidates

While testing enumeration a very large directory with FSAL_RGW and
with substantial debug logging, found a scenario where during
invalidation, the ultimate unchunk_dirent(...) action was operating
on a recycled dirent chunk with invalid state.

Fixes suggested by Claude Code:

Fix 1 (previous session, line 1959 of mdcache_helpers.c): Reset
new_dir_entry->chunk = NULL on the cookie collision error path in
place_new_dirent. This is a real bug — the dirent gets chunk set to a
neighbor's chunk but is never added to that chunk's dirents glist,
creating an orphan. However, this path evidently isn't the one
triggered in your test.

Fix 2 (this session, mdcache_avl.c + mdcache_avl.h): Pass the
known-valid parent from mdcache_avl_remove into unchunk_dirent instead
of deriving it from dirent->chunk->parent. The chunk may have been
cleaned (parent=NULL) and freed while the dirent still held a stale
pointer to it. Using the caller's parent means the cookie tree remove,
sorted tree remove, and first_ck fixup all use a valid parent pointer,
so the cleanup completes correctly instead of crashing at offset 0x420
from NULL.

A LogCrit fires whenever chunk->parent != parent — this will capture
the diagnostic evidence for the root cause (the dirent name, cookie,
and chunk_list state) without crashing. That log output should help
identify exactly which dirent is orphaned and whether its chunk_list
was {NULL, NULL} (never added to the chunk's glist) or something else.

Change-Id: I95964225a2b7c3c0ebfd63041bfaa491233be36e
Assisted-by: Claude Code, Opus 4.6 1M
Signed-off-by: Matt Benjamin <mbenjamin@redhat.com>
(cherry picked from commit 2a457ecb898220b4206e45dc75d4f1b1e89f7cbc)
---
M src/FSAL/Stackable_FSALs/FSAL_MDCACHE/mdcache_avl.c
M src/FSAL/Stackable_FSALs/FSAL_MDCACHE/mdcache_avl.h
M src/FSAL/Stackable_FSALs/FSAL_MDCACHE/mdcache_helpers.c
3 files changed, 16 insertions(+), 4 deletions(-)

git pull ssh://review.gerrithub.io:29418/ffilz/nfs-ganesha refs/changes/79/1248679/1

To view, visit change 1248679. To unsubscribe, or for help writing mail filters, visit settings.

Gerrit-MessageType: newchange
Gerrit-Project: ffilz/nfs-ganesha
Gerrit-Branch: next
Gerrit-Change-Id: I95964225a2b7c3c0ebfd63041bfaa491233be36e
Gerrit-Change-Number: 1248679
Gerrit-PatchSet: 1
Gerrit-Owner: Matt Benjamin <mbenjami@ibm.com>