[PATCH v4 3/3] exfat: drain in-flight DIO before buffered writes

From: Jiale Yao

Date: Sat Oct 03 2026 - 05:31:20 EST


An asynchronous direct write can remain in flight after the inode lock is
released. If a buffered operation dirties page cache while the direct
write is still pending, the direct write's post-I/O invalidation can find
the dirty pages, report a page cache invalidation failure, and record -EIO
in the mapping error sequence. A later fsync() therefore returns -EIO.

Commit 15cdefd0c0522f9d5e12d947fa04f4c11649b699 ("ext4: drain
in-flight DIO before buffered write fallback") fixed the same race in
ext4. ExFAT does not drain in-flight DIO before a regular buffered write,
the buffered fallback after iomap_dio_rw() returns -ENOTBLK or a short
write, or the page-cache operations used to extend valid_size.

Wait for in-flight DIO before these paths can dirty page cache.

A reproducer using concurrent AIO direct writes and buffered fallback
triggered the following warning and made a subsequent fsync() return
-EIO:

Page cache invalidation failure on direct I/O. Possible data corruption
due to collision with buffered I/O!

Fixes: 867b9c96dc83 ("exfat: add iomap direct I/O support")
Link: https://lore.kernel.org/r/20260629113827.4074335-3-libaokun@xxxxxxxxxxxxxxxxx
Signed-off-by: Jiale Yao <yaojiale02@xxxxxxx>
---
fs/exfat/file.c | 14 ++++++++++++--
1 file changed, 12 insertions(+), 2 deletions(-)

diff --git a/fs/exfat/file.c b/fs/exfat/file.c
index a2a9ee1a2004..3f08b571dec1 100644
--- a/fs/exfat/file.c
+++ b/fs/exfat/file.c
@@ -758,6 +758,8 @@ static int exfat_extend_valid_size(struct inode *inode, loff_t new_valid_size)
int ret = 0;

if (old_valid_size < new_valid_size) {
+ inode_dio_wait(inode);
+
/* Do not re-zero blocks already covered by zeroed_size. */
loff_t gap_start = max(old_valid_size, ei->zeroed_size);

@@ -807,6 +809,8 @@ static ssize_t exfat_fallback_buffered_write(struct kiocb *iocb,

iocb->ki_flags &= ~IOCB_DIRECT;

+ inode_dio_wait(file_inode(iocb->ki_filp));
+
written = iomap_file_buffered_write(iocb, from, &exfat_write_iomap_ops,
NULL, NULL);
if (written < 0)
@@ -889,11 +893,17 @@ static ssize_t exfat_file_write_iter(struct kiocb *iocb, struct iov_iter *iter)
goto unlock;
}

- if (iocb->ki_flags & IOCB_DIRECT)
+ if (iocb->ki_flags & IOCB_DIRECT) {
ret = exfat_dio_write_iter(iocb, iter);
- else
+ } else {
+ /*
+ * Prevent concurrent direct I/O and buffered I/O to the same file
+ * range. Wait for in-flight DIO to finish before dirtying pages.
+ */
+ inode_dio_wait(inode);
ret = iomap_file_buffered_write(iocb, iter,
&exfat_write_iomap_ops, NULL, NULL);
+ }
if (ret < 0)
goto unlock;

--
2.34.1