Re: [PATCH v3 0/3] ntfs: fix the undo path of $MFT data extension
From: Namjae Jeon
Date: Fri Oct 02 2026 - 21:03:04 EST
On Fri, Oct 2, 2026 at 1:35 PM Matthias Goergens
<matthias.goergens@xxxxxxxxx> wrote:
>
> These fix two bugs in the undo path of
> ntfs_mft_data_extend_allocation_nolock(): patch 1 fixes a use-after-free
> of a pointer into the runlist across the truncation, and patch 3 makes
> its $MFT runlist locking consistent. Patch 2 adds the runlist merge
> that patch 3 uses to keep the runlist of the new clusters for the undo.
>
> The undo path only runs when something fails while $MFT grows, so I
> tested it in QEMU by forcing each failure once with a debug patch, and
> tested patch 2 in userspace against the merge code it changes. The
> debug patch, the test scripts, the volume images and the userspace test
> are at
> https://github.com/matthiasgoergens/linux/tree/reproducer/2026-10-02-ntfs-mft-extend-undo-v3
>
> Changes in v3:
> - Patch 3 frees the clusters from the runlist that ntfs_cluster_alloc()
> returned, using the merge from patch 2, which leaves that runlist
> intact, instead of copying the new runs with ntfs_mft_copy_tail() in
> undo_alloc (Hyunchul Lee). The undo path no longer allocates.
> - Patch 1 (patch 2 in v2) is unchanged and keeps Baolin Liu's
> Reviewed-by. It now comes first, as it can be applied on its own.
> - Rebased onto current ntfs-next.
>
> v2: https://lore.kernel.org/all/20260930033556.169300-1-matthias.goergens@xxxxxxxxx/
> v1: https://lore.kernel.org/all/20260927105706.3111333-1-matthias.goergens@xxxxxxxxx/
>
> Thanks,
> Matthias
>
> Matthias Goergens (3):
> ntfs: do not use a stale runlist pointer when undoing $MFT extension
> ntfs: add a runlist merge that leaves the source runlist to the caller
> ntfs: balance the $MFT runlist lock in data extension error paths
Applied them to #ntfs-next.
Thanks!