[PATCH] dax: fix wrong size passed to dax_iomap_direct_access() in dax_range_compare_iter()

From: jianyungao89

Date: Sat Oct 10 2026 - 03:15:21 EST


From: Jianyun Gao <jianyungao89@xxxxxxxxx>

dax_range_compare_iter() passes ALIGN(pos + len, PAGE_SIZE) as the size
argument to dax_iomap_direct_access(), but this is an absolute file
offset rather than a length. This causes the underlying
dax_direct_access() to request a massively inflated nr_pages via
PHYS_PFN(size), leading to unnecessarily large access ranges and
potential spurious -EHWPOISON from driver badblock scans.

Fix by computing the correct aligned size:
ALIGN(len + (pos & ~PAGE_MASK), PAGE_SIZE)

which accounts for the page-in-page offset of pos, matching the pattern
used in dax_iomap_copy_around().

Fixes: 6f7db3894ae2 ("fsdax: dedup file range to use a compare function")
Cc: <stable@xxxxxxxxxxxxxxx>
Signed-off-by: Jianyun Gao <jianyungao89@xxxxxxxxx>
---
fs/dax.c | 9 +++++----
1 file changed, 5 insertions(+), 4 deletions(-)

diff --git a/fs/dax.c b/fs/dax.c
index 6ba50142eeb2..213b1c9e197c 100644
--- a/fs/dax.c
+++ b/fs/dax.c
@@ -2197,6 +2197,7 @@ static int dax_range_compare_iter(struct iomap_iter *it_src,
const struct iomap *dmap = &it_dest->iomap;
loff_t pos1 = it_src->pos, pos2 = it_dest->pos;
void *saddr, *daddr;
+ size_t size1, size2;
int id, ret;

len = min(len, min(smap->length, dmap->length));
@@ -2212,13 +2213,13 @@ static int dax_range_compare_iter(struct iomap_iter *it_src,
}

id = dax_read_lock();
- ret = dax_iomap_direct_access(smap, pos1, ALIGN(pos1 + len, PAGE_SIZE),
- &saddr, NULL);
+ size1 = ALIGN(len + (pos1 & ~PAGE_MASK), PAGE_SIZE);
+ ret = dax_iomap_direct_access(smap, pos1, size1, &saddr, NULL);
if (ret < 0)
goto out_unlock;

- ret = dax_iomap_direct_access(dmap, pos2, ALIGN(pos2 + len, PAGE_SIZE),
- &daddr, NULL);
+ size2 = ALIGN(len + (pos2 & ~PAGE_MASK), PAGE_SIZE);
+ ret = dax_iomap_direct_access(dmap, pos2, size2, &daddr, NULL);
if (ret < 0)
goto out_unlock;

--
2.34.1