Re: [PATCH 0/2] ntfs: fix the undo path of $MFT data extension
From: liubaolin
Date: Sun Sep 27 2026 - 09:07:24 EST
在 2026/9/27 18:57, Matthias Goergens 写道:
These fix two bugs in the undo path of
ntfs_mft_data_extend_allocation_nolock(). Patch 1 makes the $MFT
runlist locking there consistent: a map_mft_record() failure leaks the
lock, a lookup failure in restore_undo_alloc releases it without holding
it, and the clusters are freed and the runlist truncated without it.
Patch 2 fixes a use-after-free of a pointer into the runlist across the
truncation.
Both paths only run when something fails while $MFT grows, so I tested
them in QEMU by forcing each failure once with a debug patch. The
debug patch, the test scripts and the images are at
https://github.com/matthiasgoergens/linux/tree/reproducer/2026-09-27-ntfs-mft-extend-undo
Thanks,
Matthias
Matthias Goergens (2):
ntfs: balance the $MFT runlist lock in data extension error paths
ntfs: do not use a stale runlist pointer when undoing $MFT extension
fs/ntfs/mft.c | 63 +++++++++++++++++++++++++++++++++++++++++++--------
1 file changed, 53 insertions(+), 10 deletions(-)
base-commit: 259abb551e2944998cad4214c201954ab1ac5c8d
The series looks good to me.
Reviewed-by: Baolin Liu <liubaolin@xxxxxxxxxx>