[PATCH v2 5/7] exfat: publish valid_size under the folio lock for buffered writes

From: Chi Zhiling

Date: Fri Oct 02 2026 - 23:33:36 EST


From: Chi Zhiling <chizhiling@xxxxxxxxxx>

Buffered writes currently advance valid_size from
exfat_write_iomap_end(), which runs after the folio has been unlocked.
A folio that is beyond valid_size can therefore become uptodate and
dirty, and be observed by writeback or reclaim, while valid_size still
points below it.

If reclaim picks such a folio, the page can be dropped while the range is
still marked as a hole. A later read of that range is then treated as a
hole as well and is zero-filled without touching the disk. Once that
zero-filled page is written back, the zeros overwrite the data that was
just written, even though valid_size is advanced afterwards, so the write
is silently lost on disk.

Publish valid_size from the buffered write path while the folio is still
locked, via an iomap put_folio callback, so it is never smaller than any
folio writeback can see. Mark the inode dirty once the write advances
valid_size; the direct I/O path continues to advance it from ->iomap_end.

Signed-off-by: Chi Zhiling <chizhiling@xxxxxxxxxx>
---
fs/exfat/file.c | 8 ++++++--
fs/exfat/iomap.c | 16 ++++++++++++++++
fs/exfat/iomap.h | 1 +
3 files changed, 23 insertions(+), 2 deletions(-)

diff --git a/fs/exfat/file.c b/fs/exfat/file.c
index b2940732812a..6bd2b6d28a82 100644
--- a/fs/exfat/file.c
+++ b/fs/exfat/file.c
@@ -751,7 +751,7 @@ static ssize_t exfat_fallback_buffered_write(struct kiocb *iocb,
iocb->ki_flags &= ~IOCB_DIRECT;

written = iomap_file_buffered_write(iocb, from, &exfat_write_iomap_ops,
- NULL, NULL);
+ &exfat_iomap_write_ops, NULL);
if (written < 0)
return written;

@@ -837,10 +837,14 @@ static ssize_t exfat_file_write_iter(struct kiocb *iocb, struct iov_iter *iter)
ret = exfat_dio_write_iter(iocb, iter);
else
ret = iomap_file_buffered_write(iocb, iter,
- &exfat_write_iomap_ops, NULL, NULL);
+ &exfat_write_iomap_ops, &exfat_iomap_write_ops,
+ NULL);
if (ret < 0)
goto unlock;

+ if (exfat_get_valid_size(ei) > valid_size)
+ mark_inode_dirty(inode);
+
inode_unlock(inode);

if (iocb->ki_pos > pos) {
diff --git a/fs/exfat/iomap.c b/fs/exfat/iomap.c
index 291367e10c1e..4ed64c67070e 100644
--- a/fs/exfat/iomap.c
+++ b/fs/exfat/iomap.c
@@ -221,6 +221,22 @@ const struct iomap_ops exfat_write_iomap_ops = {
.iomap_next = exfat_write_iomap_next,
};

+static void exfat_iomap_put_folio(struct inode *inode, loff_t pos,
+ unsigned int copied, struct folio *folio)
+{
+ struct exfat_inode_info *ei = EXFAT_I(inode);
+
+ if (copied)
+ exfat_advance_valid_size(ei, pos + copied);
+
+ folio_unlock(folio);
+ folio_put(folio);
+}
+
+const struct iomap_write_ops exfat_iomap_write_ops = {
+ .put_folio = exfat_iomap_put_folio,
+};
+
/*
* exfat_writeback_range - Map folio during writeback
*
diff --git a/fs/exfat/iomap.h b/fs/exfat/iomap.h
index fd8a913f7794..39c93f8cd790 100644
--- a/fs/exfat/iomap.h
+++ b/fs/exfat/iomap.h
@@ -9,6 +9,7 @@
extern const struct iomap_dio_ops exfat_write_dio_ops;
extern const struct iomap_ops exfat_iomap_ops;
extern const struct iomap_ops exfat_write_iomap_ops;
+extern const struct iomap_write_ops exfat_iomap_write_ops;
extern const struct iomap_writeback_ops exfat_writeback_ops;
extern const struct iomap_read_ops exfat_iomap_bio_read_ops;

--
2.53.0