[PATCH 0/4] exfat: fix VDL tracking bugs

From: Chi Zhiling

Date: Sat Oct 03 2026 - 23:02:16 EST


From: Chi Zhiling <chizhiling@xxxxxxxxxx>

exFAT tracks a valid data length (VDL) as exfat_inode_info.valid_size:
below it is valid data, at or above it is a hole that the read paths
zero-fill. It is read without the inode lock (->iomap_begin and the
buffered-read bio completion) and updated from the write, mmap and
truncate paths, so it must only move forward, and only once the data has
actually been copied and the folio dirtied. This series fixes the bugs
around that invariant:

- An O_APPEND write uses the caller's offset instead of the position
recalculated by generic_write_checks(), so valid_size may not be
advanced to EOF.

- Truncate does not hold mapping->invalidate_lock, so it can race with
an mmap write faulting a page back in for the same range.

- exfat_zero_new_range() does not dirty non-uptodate pages, so some of
the zeroed blocks are never written back.

Patch 4 converts valid_size and zeroed_size to monotonic atomic counters
as a prerequisite for updating valid_size from contexts that do not hold
i_rwsem.

This series was split from:
https://lore.kernel.org/exfat/20261003033032.1775311-1-chizhiling@xxxxxxx/T/#t
The other patches still need some improvement.

Chi Zhiling (4):
exfat: advance valid_size to EOF for append writes
exfat: hold the invalidate lock while truncating
exfat: dirty all new pages when extending valid_size
exfat: make valid_size and zeroed_size atomic

fs/exfat/exfat_fs.h | 60 +++++++++++++++++-
fs/exfat/file.c | 144 ++++++++++++++------------------------------
fs/exfat/inode.c | 16 ++---
fs/exfat/iomap.c | 20 +++---
fs/exfat/namei.c | 4 +-
5 files changed, 123 insertions(+), 121 deletions(-)


base-commit: 216426aff8f69379f03337857551ca0ed3190361
--
2.53.0