From: Zhang Yi <yizhang089@gmail.com>
To: sashiko-reviews@lists.linux.dev
Cc: linux-ext4@vger.kernel.org, tytso@mit.edu,
Zhang Yi <yi.zhang@huaweicloud.com>
Subject: Re: [PATCH v6 09/31] ext4: skip block allocation for holes in the data submission path
Date: Wed, 9 Sep 2026 15:13:22 +0800 [thread overview]
Message-ID: <8356eaaf-ff5e-4777-9760-3c596204fc49@gmail.com> (raw)
In-Reply-To: <20260903134626.1771E1F00AC4@smtp.kernel.org>
On 9/3/2026 9:46 PM, sashiko-bot@kernel.org wrote:
> Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
> - [Critical] mpage_map_one_extent() fails to check for err == 0 from ext4_map_blocks(), leading to dirty buffers being mapped to block 0 and silently overwriting the filesystem superblock on inconsistencies.
> --
>
> commit 0c0032b57a5cee4a0ac28f30d5e6fc9a53e4e923
> Author: Zhang Yi <yi.zhang@huawei.com>
>
> ext4: skip block allocation for holes in the data submission path
>
> This commit modifies ext4_map_blocks() to return 0 without allocating blocks
> when encountering a hole during the data submission path. It aims to discard
> dirty bits for holes without submitting I/O.
>
>> diff --git a/fs/ext4/inode.c b/fs/ext4/inode.c
>> index 1473263dd82f1..81c4625de752a 100644
>> --- a/fs/ext4/inode.c
>> +++ b/fs/ext4/inode.c
>> @@ -825,6 +825,13 @@ int ext4_map_blocks(handle_t *handle, struct inode *inode,
>> map->m_flags |= EXT4_MAP_MAPPED;
>> goto out_handle;
>> }
>> + } else if (retval == 0) {
>> + /*
>> + * Do not allocate blocks for holes in the context of
>> + * data submission path.
>> + */
>> + if (!map->m_flags && (flags & EXT4_GET_BLOCKS_IO_SUBMIT))
>> + goto out_handle;
>
> [Severity: Critical]
> Does this new return path create an unhandled condition in
> mpage_map_one_extent() for the buffer_head writeback path?
>
> When ext4_map_blocks() is called by mpage_map_one_extent() and returns 0 due
> to this new logic, the caller only checks for err < 0:
>
> fs/ext4/inode.c:mpage_map_one_extent() {
> ...
> err = ext4_map_blocks(handle, inode, map, get_blocks_flags);
> if (err < 0)
> return err;
> ...
> }
>
> Because err == 0 is ignored, mpage_map_one_extent() proceeds as if blocks
> were successfully allocated. The zero m_pblk is then used by
> mpage_map_and_submit_buffers(), which sets bh->b_blocknr = 0 and clears the
> delay flag.
>
> Could this result in ext4_bio_write_folio() submitting I/O to the mapped
> physical block 0 and silently overwriting the filesystem superblock on
> inconsistencies?
>
This should not happen in practice. mpage_add_bh_to_extent() only
collects delayed or unwritten buffers into the extent to map. Hole
buffers are filtered out there and never reach ext4_map_blocks(), so
when mpage_map_one_extent() runs, ext4_map_blocks() can only return a
positive number on allocation or a negative error, never zero.
That said, I agree a defensive check is better than relying on that
invariant alone. I'll add the following to guard against an unexpected
hole.
/*
* A hole? This should never happen since mpage_add_bh_to_extent()
* has filtered it out.
*/
if (WARN_ON_ONCE(!err))
return -EINVAL;
Thanks,
Yi
>> }
>>
>> if (!handle) {
>
next prev parent reply other threads:[~2026-09-09 7:13 UTC|newest]
Thread overview: 68+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-03 12:35 [PATCH v6 00/31] ext4: use iomap for regular file's buffered I/O path Zhang Yi
2026-09-03 12:35 ` [PATCH v6 01/31] ext4: simplify size updating in ext4_setattr() Zhang Yi
2026-09-03 12:56 ` sashiko-bot
2026-09-03 12:35 ` [PATCH v6 02/31] ext4: factor out ext4_truncate_[up|down]() Zhang Yi
2026-09-03 13:09 ` sashiko-bot
2026-09-03 12:35 ` [PATCH v6 03/31] ext4: skip ordered I/O wait when zeroing beyond i_disksize block Zhang Yi
2026-09-03 13:14 ` sashiko-bot
2026-09-08 11:31 ` Zhang Yi
2026-09-03 12:35 ` [PATCH v6 04/31] ext4: set EXT4_MAP_NEW flag for delayed allocated blocks Zhang Yi
2026-09-03 12:54 ` sashiko-bot
2026-09-03 12:35 ` [PATCH v6 05/31] ext4: recheck extent status tree before block allocation Zhang Yi
2026-09-03 13:02 ` sashiko-bot
2026-09-09 9:27 ` Zhang Yi
2026-09-03 12:35 ` [PATCH v6 06/31] ext4: fix orig_mlen initialization in ext4_map_blocks() Zhang Yi
2026-09-03 12:55 ` sashiko-bot
2026-09-03 12:35 ` [PATCH v6 07/31] ext4: allow ext4_map_blocks() to start its own transaction handle Zhang Yi
2026-09-03 13:02 ` sashiko-bot
2026-09-03 12:35 ` [PATCH v6 08/31] ext4: avoid unnecessary transaction in ext4_map_blocks() for unwritten extents Zhang Yi
2026-09-03 13:06 ` sashiko-bot
2026-09-03 12:35 ` [PATCH v6 09/31] ext4: skip block allocation for holes in the data submission path Zhang Yi
2026-09-03 13:46 ` sashiko-bot
2026-09-09 7:13 ` Zhang Yi [this message]
2026-09-03 12:35 ` [PATCH v6 10/31] ext4: add iomap address space operations for buffered I/O Zhang Yi
2026-09-03 12:57 ` sashiko-bot
2026-09-03 12:35 ` [PATCH v6 11/31] ext4: implement buffered read path using iomap Zhang Yi
2026-09-03 13:12 ` sashiko-bot
2026-09-03 12:35 ` [PATCH v6 12/31] ext4: pass out extent seq counter when mapping da blocks Zhang Yi
2026-09-03 13:05 ` sashiko-bot
2026-09-03 12:35 ` [PATCH v6 13/31] ext4: do not use data=ordered mode for inodes using buffered iomap path Zhang Yi
2026-09-03 13:13 ` sashiko-bot
2026-09-03 12:35 ` [PATCH v6 14/31] ext4: implement buffered write path using iomap Zhang Yi
2026-09-03 13:23 ` sashiko-bot
2026-09-10 12:14 ` Zhang Yi
2026-09-03 12:35 ` [PATCH v6 15/31] ext4: implement writeback " Zhang Yi
2026-09-03 13:36 ` sashiko-bot
2026-09-12 8:28 ` Zhang Yi
2026-09-03 12:35 ` [PATCH v6 16/31] ext4: implement mmap " Zhang Yi
2026-09-03 13:29 ` sashiko-bot
2026-09-03 12:35 ` [PATCH v6 17/31] ext4: implement partial block zero range " Zhang Yi
2026-09-03 13:29 ` sashiko-bot
2026-09-03 12:35 ` [PATCH v6 18/31] ext4: drain writeback before removing extents on the iomap path Zhang Yi
2026-09-03 13:19 ` sashiko-bot
2026-09-03 12:35 ` [PATCH v6 19/31] ext4: add block mapping tracepoints for iomap buffered I/O path Zhang Yi
2026-09-03 13:19 ` sashiko-bot
2026-09-03 12:35 ` [PATCH v6 20/31] ext4: disable online defrag when inode using " Zhang Yi
2026-09-03 13:25 ` sashiko-bot
2026-09-03 12:35 ` [PATCH v6 21/31] ext4: add EXT4_STATE_DISKSIZE_GROW_PENDING state bit and helpers Zhang Yi
2026-09-03 13:19 ` sashiko-bot
2026-09-03 12:35 ` [PATCH v6 22/31] ext4: submit and wait for pending disksize-grow I/O on writeback Zhang Yi
2026-09-03 13:40 ` sashiko-bot
2026-09-03 12:35 ` [PATCH v6 23/31] ext4: advance i_disksize to i_size upon disksize-grow I/O completion Zhang Yi
2026-09-03 13:31 ` sashiko-bot
2026-09-03 12:35 ` [PATCH v6 24/31] ext4: defer i_disksize update while DISKSIZE_GROW_PENDING is set Zhang Yi
2026-09-03 13:38 ` sashiko-bot
2026-09-03 12:35 ` [PATCH v6 25/31] ext4: submit and wait for disksize-grow I/O in fallocate paths Zhang Yi
2026-09-03 13:42 ` sashiko-bot
2026-09-03 12:35 ` [PATCH v6 26/31] ext4: clear DISKSIZE_GROW_PENDING on truncate or error Zhang Yi
2026-09-03 13:46 ` sashiko-bot
2026-09-03 12:35 ` [PATCH v6 27/31] ext4: set DISKSIZE_GROW_PENDING after zeroing unaligned EOF block Zhang Yi
2026-09-03 13:36 ` sashiko-bot
2026-09-03 12:35 ` [PATCH v6 28/31] ext4: add tracepoints for DISKSIZE_GROW_PENDING set, clear, and wait Zhang Yi
2026-09-03 13:34 ` sashiko-bot
2026-09-03 12:40 ` [PATCH v6 29/31] ext4: add tracepoints for EOF block zeroing and disksize-grow I/O Zhang Yi
2026-09-03 13:32 ` sashiko-bot
2026-09-03 12:40 ` [PATCH v6 30/31] ext4: partially enable iomap for the buffered I/O path of regular files Zhang Yi
2026-09-03 14:04 ` sashiko-bot
2026-09-03 12:40 ` [PATCH v6 31/31] ext4: introduce a mount option for iomap buffered I/O path Zhang Yi
2026-09-03 13:46 ` sashiko-bot
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=8356eaaf-ff5e-4777-9760-3c596204fc49@gmail.com \
--to=yizhang089@gmail.com \
--cc=linux-ext4@vger.kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
--cc=tytso@mit.edu \
--cc=yi.zhang@huaweicloud.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.