xfs_trans_ijoin(tp, ip, 0);
 
        xfs_defer_init(&dfops, &firstfsb);
+       tp->t_dfops = &dfops;
        error = xfs_bunmapi(tp, ip, startoffset_fsb, len_fsb, 0, 2, &firstfsb,
-                       &dfops, done);
+                       tp->t_dfops, done);
        if (error)
                goto out_bmap_cancel;
 
-       xfs_defer_ijoin(&dfops, ip);
-       error = xfs_defer_finish(&tp, &dfops);
+       xfs_defer_ijoin(tp->t_dfops, ip);
+       error = xfs_defer_finish(&tp, tp->t_dfops);
        if (error)
                goto out_bmap_cancel;
 
        return error;
 
 out_bmap_cancel:
-       xfs_defer_cancel(&dfops);
+       xfs_defer_cancel(tp->t_dfops);
 out_trans_cancel:
        xfs_trans_cancel(tp);
        goto out_unlock;
 
 {
        struct xfs_mount        *mp = ip->i_mount;
        struct xfs_trans        *tp = *tpp;
+       struct xfs_defer_ops    *odfops = tp->t_dfops;
        struct xfs_defer_ops    dfops;
        xfs_fsblock_t           first_block;
        xfs_fileoff_t           first_unmap_block;
        unmap_len = last_block - first_unmap_block + 1;
        while (!done) {
                xfs_defer_init(&dfops, &first_block);
+               tp->t_dfops = &dfops;
                error = xfs_bunmapi(tp, ip, first_unmap_block, unmap_len, flags,
                                    XFS_ITRUNC_MAX_EXTENTS, &first_block,
-                                   &dfops, &done);
+                                   tp->t_dfops, &done);
                if (error)
                        goto out_bmap_cancel;
 
                 * Duplicate the transaction that has the permanent
                 * reservation and commit the old transaction.
                 */
-               xfs_defer_ijoin(&dfops, ip);
-               error = xfs_defer_finish(&tp, &dfops);
+               xfs_defer_ijoin(tp->t_dfops, ip);
+               error = xfs_defer_finish(&tp, tp->t_dfops);
                if (error)
                        goto out_bmap_cancel;
 
        trace_xfs_itruncate_extents_end(ip, new_size);
 
 out:
+       /* ->t_dfops points to local stack, don't leak it! */
+       tp->t_dfops = odfops;
        *tpp = tp;
        return error;
 out_bmap_cancel:
         * the transaction can be properly aborted.  We just need to make sure
         * we're not holding any resources that we were not when we came in.
         */
-       xfs_defer_cancel(&dfops);
+       xfs_defer_cancel(tp->t_dfops);
        goto out;
 }
 
 
 
                /* Unmap the old blocks in the data fork. */
                xfs_defer_init(&dfops, &firstfsb);
+               tp->t_dfops = &dfops;
                rlen = del.br_blockcount;
                error = __xfs_bunmapi(tp, ip, del.br_startoff, &rlen, 0, 1,
-                               &firstfsb, &dfops);
+                               &firstfsb, tp->t_dfops);
                if (error)
                        goto out_defer;
 
                trace_xfs_reflink_cow_remap(ip, &del);
 
                /* Free the CoW orphan record. */
-               error = xfs_refcount_free_cow_extent(tp->t_mountp, &dfops,
+               error = xfs_refcount_free_cow_extent(tp->t_mountp, tp->t_dfops,
                                del.br_startblock, del.br_blockcount);
                if (error)
                        goto out_defer;
 
                /* Map the new blocks into the data fork. */
-               error = xfs_bmap_map_extent(tp->t_mountp, &dfops, ip, &del);
+               error = xfs_bmap_map_extent(tp->t_mountp, tp->t_dfops, ip,
+                                           &del);
                if (error)
                        goto out_defer;
 
                /* Remove the mapping from the CoW fork. */
                xfs_bmap_del_extent_cow(ip, &icur, &got, &del);
 
-               xfs_defer_ijoin(&dfops, ip);
-               error = xfs_defer_finish(&tp, &dfops);
+               xfs_defer_ijoin(tp->t_dfops, ip);
+               error = xfs_defer_finish(&tp, tp->t_dfops);
                if (error)
                        goto out_defer;
                if (!xfs_iext_get_extent(ifp, &icur, &got))
        return 0;
 
 out_defer:
-       xfs_defer_cancel(&dfops);
+       xfs_defer_cancel(tp->t_dfops);
 out_cancel:
        xfs_trans_cancel(tp);
        xfs_iunlock(ip, XFS_ILOCK_EXCL);
        rlen = unmap_len;
        while (rlen) {
                xfs_defer_init(&dfops, &firstfsb);
+               tp->t_dfops = &dfops;
                error = __xfs_bunmapi(tp, ip, destoff, &rlen, 0, 1,
-                               &firstfsb, &dfops);
+                               &firstfsb, tp->t_dfops);
                if (error)
                        goto out_defer;
 
                                uirec.br_blockcount, uirec.br_startblock);
 
                /* Update the refcount tree */
-               error = xfs_refcount_increase_extent(mp, &dfops, &uirec);
+               error = xfs_refcount_increase_extent(mp, tp->t_dfops, &uirec);
                if (error)
                        goto out_defer;
 
                /* Map the new blocks into the data fork. */
-               error = xfs_bmap_map_extent(mp, &dfops, ip, &uirec);
+               error = xfs_bmap_map_extent(mp, tp->t_dfops, ip, &uirec);
                if (error)
                        goto out_defer;
 
 
 next_extent:
                /* Process all the deferred stuff. */
-               xfs_defer_ijoin(&dfops, ip);
-               error = xfs_defer_finish(&tp, &dfops);
+               xfs_defer_ijoin(tp->t_dfops, ip);
+               error = xfs_defer_finish(&tp, tp->t_dfops);
                if (error)
                        goto out_defer;
        }
        return 0;
 
 out_defer:
-       xfs_defer_cancel(&dfops);
+       xfs_defer_cancel(tp->t_dfops);
 out_cancel:
        xfs_trans_cancel(tp);
        xfs_iunlock(ip, XFS_ILOCK_EXCL);
 
         */
        done = 0;
        xfs_defer_init(&dfops, &first_block);
+       tp->t_dfops = &dfops;
        nmaps = ARRAY_SIZE(mval);
        error = xfs_bmapi_read(ip, 0, xfs_symlink_blocks(mp, size),
                                mval, &nmaps, 0);
         * Unmap the dead block(s) to the dfops.
         */
        error = xfs_bunmapi(tp, ip, 0, size, 0, nmaps,
-                           &first_block, &dfops, &done);
+                           &first_block, tp->t_dfops, &done);
        if (error)
                goto error_bmap_cancel;
        ASSERT(done);
        /*
         * Commit the first transaction.  This logs the EFI and the inode.
         */
-       xfs_defer_ijoin(&dfops, ip);
-       error = xfs_defer_finish(&tp, &dfops);
+       xfs_defer_ijoin(tp->t_dfops, ip);
+       error = xfs_defer_finish(&tp, tp->t_dfops);
        if (error)
                goto error_bmap_cancel;
 
        return 0;
 
 error_bmap_cancel:
-       xfs_defer_cancel(&dfops);
+       xfs_defer_cancel(tp->t_dfops);
 error_trans_cancel:
        xfs_trans_cancel(tp);
 error_unlock: