[PATCH 0/2] ntfs: fix the undo path of $MFT data extension
From: Matthias Goergens
Date: Sun Sep 27 2026 - 06:58:29 EST
These fix two bugs in the undo path of
ntfs_mft_data_extend_allocation_nolock(). Patch 1 makes the $MFT
runlist locking there consistent: a map_mft_record() failure leaks the
lock, a lookup failure in restore_undo_alloc releases it without holding
it, and the clusters are freed and the runlist truncated without it.
Patch 2 fixes a use-after-free of a pointer into the runlist across the
truncation.
Both paths only run when something fails while $MFT grows, so I tested
them in QEMU by forcing each failure once with a debug patch. The
debug patch, the test scripts and the images are at
https://github.com/matthiasgoergens/linux/tree/reproducer/2026-09-27-ntfs-mft-extend-undo
Thanks,
Matthias
Matthias Goergens (2):
ntfs: balance the $MFT runlist lock in data extension error paths
ntfs: do not use a stale runlist pointer when undoing $MFT extension
fs/ntfs/mft.c | 63 +++++++++++++++++++++++++++++++++++++++++++--------
1 file changed, 53 insertions(+), 10 deletions(-)
base-commit: 259abb551e2944998cad4214c201954ab1ac5c8d
--
2.55.0