git: adfcef9dfe2e - stable/15 - posixshm: Fix a double unlock in shm_partial_page_invalidate()

From: Mark Johnston <markj_at_FreeBSD.org>
Date: Thu, 01 Oct 2026 15:20:23 UTC
The branch stable/15 has been updated by markj:

URL: https://cgit.FreeBSD.org/src/commit/?id=adfcef9dfe2e68395512fba31741e989c2e4f6f3

commit adfcef9dfe2e68395512fba31741e989c2e4f6f3
Author:     Mark Johnston <markj@FreeBSD.org>
AuthorDate: 2026-09-23 16:53:53 +0000
Commit:     Mark Johnston <markj@FreeBSD.org>
CommitDate: 2026-10-01 13:42:28 +0000

    posixshm: Fix a double unlock in shm_partial_page_invalidate()
    
    For some reason, shm_partial_page_invalidate() unlocks the object upon
    an error, but its callers don't expect this.  Don't do any special error
    handling.  Keep the subroutine anyway since the name is a bit clearer
    than vm_page_grab_zero_partial().
    
    While here, normalize the object pointer used for locking in
    shm_deallocate().
    
    Reviewed by:    kib
    Fixes:          454bc887f250 ("uipc_shm: Implements fspacectl(2) support")
    MFC after:      1 week
    Sponsored by:   The FreeBSD Foundation
    Differential Revision:  https://reviews.freebsd.org/D59877
    
    (cherry picked from commit ba974faaf30b74472acc4f0dc5853a22d43951f2)
---
 sys/kern/uipc_shm.c | 9 ++-------
 1 file changed, 2 insertions(+), 7 deletions(-)

diff --git a/sys/kern/uipc_shm.c b/sys/kern/uipc_shm.c
index b77731f8188b..7df9d59716c7 100644
--- a/sys/kern/uipc_shm.c
+++ b/sys/kern/uipc_shm.c
@@ -723,12 +723,7 @@ static int
 shm_partial_page_invalidate(vm_object_t object, vm_pindex_t idx, int base,
     int end)
 {
-	int error;
-
-	error = vm_page_grab_zero_partial(object, idx, base, end);
-	if (error == EIO)
-		VM_OBJECT_WUNLOCK(object);
-	return (error);
+	return (vm_page_grab_zero_partial(object, idx, base, end));
 }
 
 static int
@@ -2093,7 +2088,7 @@ shm_deallocate(struct shmfd *shmfd, off_t *offset, off_t *length, int flags)
 	}
 
 out:
-	VM_OBJECT_WUNLOCK(shmfd->shm_object);
+	VM_OBJECT_WUNLOCK(object);
 	*offset = off;
 	*length = len;
 	return (error);