All of lore.kernel.org
 help / color / mirror / Atom feed
From: Chao Yu via Linux-f2fs-devel <linux-f2fs-devel@lists.sourceforge.net>
To: Hao-Qun Huang <alvinhuang0603@gmail.com>,
	Jaegeuk Kim <jaegeuk@kernel.org>
Cc: linux-kernel@vger.kernel.org, stable@vger.kernel.org,
	linux-f2fs-devel@lists.sourceforge.net
Subject: Re: [f2fs-dev] [PATCH] f2fs: reject overlapping move range after len expansion
Date: Mon, 3 Aug 2026 15:07:59 +0800	[thread overview]
Message-ID: <4febf145-36cf-4d4a-b9d3-1c33ac273607@kernel.org> (raw)
In-Reply-To: <20260708065439.1139937-1-alvinhuang0603@gmail.com>

On 7/8/26 14:54, Hao-Qun Huang wrote:
> F2FS_IOC_MOVE_RANGE treats a zero length as a request to move data
> from pos_in to EOF. However, the same-file overlap check runs before
> that expansion, so a request with len == 0 bypasses the overlap
> rejection added for same-file moves.
> 
> For example, with a four-block file, moving from block 0 to block 1
> with len == 0 is accepted by the old check because pos_in + len is
> still pos_in at that point. The code then expands len to cover the
> rest of the file and calls __exchange_data_block() on overlapping
> source and destination ranges in the same inode, which is the
> data-corruption case the overlap check was meant to reject.
> 
> Move the overlap check after the source range has been validated and
> len == 0 has been expanded, so it sees the effective length. This is a
> no-op for non-zero len (the value is unchanged there) and keeps the
> existing early return for identical positions.
> 
> Fixes: d95fd91c1ac1 ("f2fs: exclude special cases for f2fs_move_file_range")
> Cc: stable@vger.kernel.org
> Assisted-by: Claude:claude-fable-5
> Signed-off-by: Hao-Qun Huang <alvinhuang0603@gmail.com>
> ---
> diff --git a/fs/f2fs/file.c b/fs/f2fs/file.c
> index 4b52c56d71f0..fdfef01dc799 100644
> --- a/fs/f2fs/file.c
> +++ b/fs/f2fs/file.c
> @@ -3144,8 +3144,6 @@ static int f2fs_move_file_range(struct file *file_in, loff_t pos_in,
>   	if (src == dst) {
>   		if (pos_in == pos_out)
>   			return 0;
> -		if (pos_out > pos_in && pos_out < pos_in + len)
> -			return -EINVAL;
>   	}
>   
>   	inode_lock(src);
> @@ -3171,6 +3169,8 @@ static int f2fs_move_file_range(struct file *file_in, loff_t pos_in,
>   		goto out_unlock;
>   	if (len == 0)
>   		olen = len = src->i_size - pos_in;
> +	if (src == dst && pos_out > pos_in && pos_out < pos_in + len)
> +		goto out_unlock;

Reviewed-by: Chao Yu <chao@kernel.org>

Thanks,

>   	if (pos_in + len == src->i_size)
>   		len = ALIGN(src->i_size, F2FS_BLKSIZE) - pos_in;
>   	if (len == 0) {



_______________________________________________
Linux-f2fs-devel mailing list
Linux-f2fs-devel@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/linux-f2fs-devel

WARNING: multiple messages have this Message-ID (diff)
From: Chao Yu <chao@kernel.org>
To: Hao-Qun Huang <alvinhuang0603@gmail.com>,
	Jaegeuk Kim <jaegeuk@kernel.org>
Cc: chao@kernel.org, linux-f2fs-devel@lists.sourceforge.net,
	linux-kernel@vger.kernel.org, stable@vger.kernel.org
Subject: Re: [PATCH] f2fs: reject overlapping move range after len expansion
Date: Mon, 3 Aug 2026 15:07:59 +0800	[thread overview]
Message-ID: <4febf145-36cf-4d4a-b9d3-1c33ac273607@kernel.org> (raw)
In-Reply-To: <20260708065439.1139937-1-alvinhuang0603@gmail.com>

On 7/8/26 14:54, Hao-Qun Huang wrote:
> F2FS_IOC_MOVE_RANGE treats a zero length as a request to move data
> from pos_in to EOF. However, the same-file overlap check runs before
> that expansion, so a request with len == 0 bypasses the overlap
> rejection added for same-file moves.
> 
> For example, with a four-block file, moving from block 0 to block 1
> with len == 0 is accepted by the old check because pos_in + len is
> still pos_in at that point. The code then expands len to cover the
> rest of the file and calls __exchange_data_block() on overlapping
> source and destination ranges in the same inode, which is the
> data-corruption case the overlap check was meant to reject.
> 
> Move the overlap check after the source range has been validated and
> len == 0 has been expanded, so it sees the effective length. This is a
> no-op for non-zero len (the value is unchanged there) and keeps the
> existing early return for identical positions.
> 
> Fixes: d95fd91c1ac1 ("f2fs: exclude special cases for f2fs_move_file_range")
> Cc: stable@vger.kernel.org
> Assisted-by: Claude:claude-fable-5
> Signed-off-by: Hao-Qun Huang <alvinhuang0603@gmail.com>
> ---
> diff --git a/fs/f2fs/file.c b/fs/f2fs/file.c
> index 4b52c56d71f0..fdfef01dc799 100644
> --- a/fs/f2fs/file.c
> +++ b/fs/f2fs/file.c
> @@ -3144,8 +3144,6 @@ static int f2fs_move_file_range(struct file *file_in, loff_t pos_in,
>   	if (src == dst) {
>   		if (pos_in == pos_out)
>   			return 0;
> -		if (pos_out > pos_in && pos_out < pos_in + len)
> -			return -EINVAL;
>   	}
>   
>   	inode_lock(src);
> @@ -3171,6 +3169,8 @@ static int f2fs_move_file_range(struct file *file_in, loff_t pos_in,
>   		goto out_unlock;
>   	if (len == 0)
>   		olen = len = src->i_size - pos_in;
> +	if (src == dst && pos_out > pos_in && pos_out < pos_in + len)
> +		goto out_unlock;

Reviewed-by: Chao Yu <chao@kernel.org>

Thanks,

>   	if (pos_in + len == src->i_size)
>   		len = ALIGN(src->i_size, F2FS_BLKSIZE) - pos_in;
>   	if (len == 0) {


  reply	other threads:[~2026-08-03  7:08 UTC|newest]

Thread overview: 6+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-07-08  6:54 [PATCH] f2fs: reject overlapping move range after len expansion Hao-Qun Huang
2026-07-08  6:54 ` [f2fs-dev] " Hao-Qun Huang
2026-08-03  7:07 ` Chao Yu via Linux-f2fs-devel [this message]
2026-08-03  7:07   ` Chao Yu
2026-08-05 21:20 ` [f2fs-dev] " patchwork-bot+f2fs--- via Linux-f2fs-devel
2026-08-05 21:20   ` patchwork-bot+f2fs

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=4febf145-36cf-4d4a-b9d3-1c33ac273607@kernel.org \
    --to=linux-f2fs-devel@lists.sourceforge.net \
    --cc=alvinhuang0603@gmail.com \
    --cc=chao@kernel.org \
    --cc=jaegeuk@kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=stable@vger.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.