[PATCH v10 0/6] ntfs: fix volume flag races and persist the recorded error state

From: Hongling Zeng

Date: Sun Sep 13 2026 - 23:09:02 EST


The fs/ntfs runtime metadata-corruption paths only record the in-memory
NVolErrors() flag, and the caller-side dirty-bit marking races with
ntfs_sync_fs(): a volume can end up with a clean on-disk dirty flag
despite modification or recorded corruption, so chkdsk never runs on
the next mount. Based on ntfs/ntfs-next (9a05b5715cfa).

1/4 makes the volume flag read-modify-write atomic under the
$Volume mrec_lock;
2/4 marks the volume dirty unconditionally on metadata changes,
dropping the racy caller-side checks in file.c and namei.c;
3/4 derives the on-disk dirty bit from the recorded error state at
the persistence points (sync_fs, remount-ro, put_super) and never
writes a hibernated volume;
4/4 persists the dirty state after the final put_super() commits so
late errors cannot unmount clean.

Changes in v10:

- Add 5/6: Stop clearing VOLUME_IS_DIRTY during sync. The bit is now
cleared only on remount to read-only or clean unmount, preventing a
crash during metadata updates from bypassing chkdsk. Verified in QEMU.

- Add 6/6: Check commit and flush errors during remount and unmount.
Re-check NInoDirty() after __ntfs_write_inode(). A failed remount is
rejected so unmount can retry; unmount failures are reported as warnings.


Hongling Zeng (4):
ntfs: fix volume flag update races
ntfs: set the volume dirty bit unconditionally on metadata changes
ntfs: sync the volume dirty bit with the recorded error state
ntfs: persist the dirty state after the final put_super() commits

fs/ntfs/file.c | 20 ++---
fs/ntfs/namei.c | 24 ++----
fs/ntfs/ntfs.h | 1 -
fs/ntfs/super.c | 191 ++++++++++++++++++++++++++++++++++++-----------
fs/ntfs/volume.h | 4 +
5 files changed, 171 insertions(+), 69 deletions(-)

--
2.25.1