[PATCH v3 0/3] ntfs: fix the undo path of $MFT data extension
From: Matthias Goergens
Date: Fri Oct 02 2026 - 00:35:18 EST
These fix two bugs in the undo path of
ntfs_mft_data_extend_allocation_nolock(): patch 1 fixes a use-after-free
of a pointer into the runlist across the truncation, and patch 3 makes
its $MFT runlist locking consistent. Patch 2 adds the runlist merge
that patch 3 uses to keep the runlist of the new clusters for the undo.
The undo path only runs when something fails while $MFT grows, so I
tested it in QEMU by forcing each failure once with a debug patch, and
tested patch 2 in userspace against the merge code it changes. The
debug patch, the test scripts, the volume images and the userspace test
are at
https://github.com/matthiasgoergens/linux/tree/reproducer/2026-10-02-ntfs-mft-extend-undo-v3
Changes in v3:
- Patch 3 frees the clusters from the runlist that ntfs_cluster_alloc()
returned, using the merge from patch 2, which leaves that runlist
intact, instead of copying the new runs with ntfs_mft_copy_tail() in
undo_alloc (Hyunchul Lee). The undo path no longer allocates.
- Patch 1 (patch 2 in v2) is unchanged and keeps Baolin Liu's
Reviewed-by. It now comes first, as it can be applied on its own.
- Rebased onto current ntfs-next.
v2: https://lore.kernel.org/all/20260930033556.169300-1-matthias.goergens@xxxxxxxxx/
v1: https://lore.kernel.org/all/20260927105706.3111333-1-matthias.goergens@xxxxxxxxx/
Thanks,
Matthias
Matthias Goergens (3):
ntfs: do not use a stale runlist pointer when undoing $MFT extension
ntfs: add a runlist merge that leaves the source runlist to the caller
ntfs: balance the $MFT runlist lock in data extension error paths
fs/ntfs/mft.c | 59 +++++++++++++++++++---------
fs/ntfs/runlist.c | 98 ++++++++++++++++++++++++++++++++++++++---------
fs/ntfs/runlist.h | 3 ++
3 files changed, 123 insertions(+), 37 deletions(-)
base-commit: 708f9d56cacae21aeee98d16bcdd50a66edc04a0
--
2.56.0