[PATCH v1 1/4] ntfs: bound the adjacent cluster in MFT bitmap extension

From: Xuewen Wang

Date: Wed Sep 23 2026 - 21:43:57 EST


When the last MFT bitmap run reaches the volume boundary, the direct
allocation path tests the bit for nr_clusters, an invalid LCN. A clear
bit allows an out-of-volume allocation; a bitmap read failure aborts
extension even if valid clusters remain available.

Check the candidate LCN before accessing $Bitmap and fall back to
ntfs_cluster_alloc() with no locality hint when it is outside the volume.

Reviewed-by: Baolin Liu <liubaolin@xxxxxxxxxx>
Signed-off-by: Xuewen Wang <wangxuewen@xxxxxxxxxx>
---
fs/ntfs/mft.c | 6 ++++++
1 file changed, 6 insertions(+)

diff --git a/fs/ntfs/mft.c b/fs/ntfs/mft.c
index 8bb8b4085c8b..88bac85d22bc 100644
--- a/fs/ntfs/mft.c
+++ b/fs/ntfs/mft.c
@@ -1377,6 +1377,11 @@ static int ntfs_mft_bitmap_extend_allocation_nolock(struct ntfs_volume *vol)
lcn = rl->lcn + rl->length;
ntfs_debug("Last lcn of mft bitmap attribute is 0x%llx.",
(long long)lcn);
+ /* There is no adjacent cluster if the last run ends at the volume end. */
+ if (lcn >= vol->nr_clusters) {
+ lcn = -1;
+ goto alloc_cluster;
+ }
/*
* Attempt to get the cluster following the last allocated cluster by
* hand as it may be in the MFT zone so the allocator would not give it
@@ -1413,6 +1418,7 @@ static int ntfs_mft_bitmap_extend_allocation_nolock(struct ntfs_volume *vol)
kunmap_local(b);
folio_put(folio);
up_write(&vol->lcnbmp_lock);
+alloc_cluster:
/* Allocate a cluster from the DATA_ZONE. */
rl2 = ntfs_cluster_alloc(vol, rl[1].vcn, 1, lcn, DATA_ZONE,
true, false, false);
--
2.25.1