[PATCH v3 3/3] exfat: drain in-flight DIO before buffered writes

From: Jiale Yao

Date: Mon Sep 28 2026 - 04:55:15 EST


An asynchronous direct write can remain in flight after the inode lock is
released. If a buffered write dirties page cache while the direct write
is still pending, the direct write's post-I/O invalidation can find the
dirty pages, report a page cache invalidation failure, and record -EIO in
the mapping error sequence. A later fsync() therefore returns -EIO.

Commit 15cdefd0c0522f9d5e12d947fa04f4c11649b699 ("ext4: drain
in-flight DIO before buffered write fallback") fixed the same race in
ext4. ExFAT does not drain in-flight DIO before either a regular buffered
write or the buffered fallback after iomap_dio_rw() returns -ENOTBLK or a
short write.

Wait for in-flight DIO before calling iomap_file_buffered_write() in both
paths.

A reproducer using concurrent AIO direct writes and buffered fallback
triggered the following warning and made a subsequent fsync() return
-EIO:

Page cache invalidation failure on direct I/O. Possible data corruption
due to collision with buffered I/O!

Fixes: 867b9c96dc83 ("exfat: add iomap direct I/O support")
Link: https://lore.kernel.org/r/20260629113827.4074335-3-libaokun@xxxxxxxxxxxxxxxxx
Signed-off-by: Jiale Yao <yaojiale02@xxxxxxx>
---
fs/exfat/file.c | 12 ++++++++++--
1 file changed, 10 insertions(+), 2 deletions(-)

diff --git a/fs/exfat/file.c b/fs/exfat/file.c
index a2a9ee1a2004..28811210663f 100644
--- a/fs/exfat/file.c
+++ b/fs/exfat/file.c
@@ -807,6 +807,8 @@ static ssize_t exfat_fallback_buffered_write(struct kiocb *iocb,

iocb->ki_flags &= ~IOCB_DIRECT;

+ inode_dio_wait(file_inode(iocb->ki_filp));
+
written = iomap_file_buffered_write(iocb, from, &exfat_write_iomap_ops,
NULL, NULL);
if (written < 0)
@@ -889,11 +891,17 @@ static ssize_t exfat_file_write_iter(struct kiocb *iocb, struct iov_iter *iter)
goto unlock;
}

- if (iocb->ki_flags & IOCB_DIRECT)
+ if (iocb->ki_flags & IOCB_DIRECT) {
ret = exfat_dio_write_iter(iocb, iter);
- else
+ } else {
+ /*
+ * Prevent concurrent direct I/O and buffered I/O to the same file
+ * range. Wait for in-flight DIO to finish before dirtying pages.
+ */
+ inode_dio_wait(inode);
ret = iomap_file_buffered_write(iocb, iter,
&exfat_write_iomap_ops, NULL, NULL);
+ }
if (ret < 0)
goto unlock;

--
2.34.1