Re: [PATCH 0/2] ntfs: fix the undo path of $MFT data extension

From: liubaolin

Date: Sun Sep 27 2026 - 09:07:24 EST




在 2026/9/27 18:57, Matthias Goergens 写道:
These fix two bugs in the undo path of
ntfs_mft_data_extend_allocation_nolock(). Patch 1 makes the $MFT
runlist locking there consistent: a map_mft_record() failure leaks the
lock, a lookup failure in restore_undo_alloc releases it without holding
it, and the clusters are freed and the runlist truncated without it.
Patch 2 fixes a use-after-free of a pointer into the runlist across the
truncation.

Both paths only run when something fails while $MFT grows, so I tested
them in QEMU by forcing each failure once with a debug patch. The
debug patch, the test scripts and the images are at
https://github.com/matthiasgoergens/linux/tree/reproducer/2026-09-27-ntfs-mft-extend-undo

Thanks,
Matthias

Matthias Goergens (2):
ntfs: balance the $MFT runlist lock in data extension error paths
ntfs: do not use a stale runlist pointer when undoing $MFT extension

fs/ntfs/mft.c | 63 +++++++++++++++++++++++++++++++++++++++++++--------
1 file changed, 53 insertions(+), 10 deletions(-)


base-commit: 259abb551e2944998cad4214c201954ab1ac5c8d

The series looks good to me.

Reviewed-by: Baolin Liu <liubaolin@xxxxxxxxxx>