Re: [PATCH v4 2/3] ntfs: drain in-flight DIO before buffered write fallback

From: Hyunchul Lee

Date: Tue Oct 06 2026 - 03:45:55 EST


On Sat, Oct 03, 2026 at 05:30:34PM +0800, Jiale Yao wrote:
> An asynchronous direct write can remain in flight after the inode lock is
> released. If another direct write falls back to buffered I/O while the
> first write is still pending, iomap_file_buffered_write() can dirty pages
> before the first write completes its post-I/O page cache invalidation.
> The invalidation then finds dirty pages, reports a page cache invalidation
> failure, and records -EIO in the mapping error sequence. A later fsync()
> therefore returns -EIO.
>
> Commit 15cdefd0c0522f9d5e12d947fa04f4c11649b699 ("ext4: drain
> in-flight DIO before buffered write fallback") fixed the same race in
> ext4. NTFS has an equivalent fallback after iomap_dio_rw() returns
> -ENOTBLK or a short write, but does not drain other in-flight DIO before
> dirtying the page cache.
>
> Wait for in-flight DIO before calling iomap_file_buffered_write() in the
> fallback path. Since NTFS supports IOCB_NOWAIT, do not enter the blocking
> fallback for such requests. Return -EAGAIN if no bytes were written, or
> preserve the positive short-write result if the direct write made partial
> progress.
>
> A reproducer using concurrent AIO direct writes and buffered fallback
> triggered the following warning and made a subsequent fsync() return
> -EIO:
>
> Page cache invalidation failure on direct I/O. Possible data corruption
> due to collision with buffered I/O!
>
> Fixes: 9c87959601e8 ("ntfs: update file operations")
> Link: https://lore.kernel.org/r/20260629113827.4074335-3-libaokun@xxxxxxxxxxxxxxxxx
> Reviewed-by: Baolin Liu <liubaolin@xxxxxxxxxx>
> Signed-off-by: Jiale Yao <yaojiale02@xxxxxxx>

Looks good to me.

Reviewed-by: Hyunchul Lee <hyc.lee@xxxxxxxxx>

> ---
> fs/ntfs/file.c | 13 +++++++++++++
> 1 file changed, 13 insertions(+)
>
> diff --git a/fs/ntfs/file.c b/fs/ntfs/file.c
> index 007d1614b9ac..8bbfa842889a 100644
> --- a/fs/ntfs/file.c
> +++ b/fs/ntfs/file.c
> @@ -525,8 +525,21 @@ static ssize_t ntfs_dio_write_iter(struct kiocb *iocb, struct iov_iter *from)
> ssize_t written;
> int ret2;
>
> + if (iocb->ki_flags & IOCB_NOWAIT) {
> + if (!ret)
> + ret = -EAGAIN;
> + goto out;
> + }
> +
> offset = iocb->ki_pos;
> iocb->ki_flags &= ~IOCB_DIRECT;
> +
> + /*
> + * Prevent concurrent direct I/O and buffered I/O to the same file
> + * range. Wait for in-flight DIO to finish before dirtying pages.
> + */
> + inode_dio_wait(file_inode(iocb->ki_filp));
> +
> written = iomap_file_buffered_write(iocb, from,
> &ntfs_write_iomap_ops, &ntfs_iomap_folio_ops,
> NULL);
> --
> 2.34.1
>
>

--
Thanks,
Hyunchul