* [PATCH v3 1/5] netfs: clear post-EOF pagecache when extending a file via write
@ 2026-09-25 14:37 Paulo Alcantara
2026-09-25 14:37 ` [PATCH v3 2/5] smb: client: clear post-EOF pagecache when extending a file via truncate Paulo Alcantara
` (3 more replies)
0 siblings, 4 replies; 5+ messages in thread
From: Paulo Alcantara @ 2026-09-25 14:37 UTC (permalink / raw)
To: linux-cifs, netfs
Cc: Christian Brauner, Matthew Wilcox, Namjae Jeon, Ronnie Sahlberg,
Shyam Prasad N, Tom Talpey, Bharath SM, stable
Fix netfs to erase the contents of a hole created after the EOF by an
ordinary write if dirty data has been previously left there by writes
through an mmapped region. Neither the buffered nor the unbuffered/DIO
write path clears that stale pagecache.
Zero the tail of the folio straddling the EOF before an extending
write. That is the only folio that can hold data written past the EOF
through an mmap, as pages wholly beyond the EOF can't be faulted in.
The folio is zeroed rather than dropped so a concurrent extending write
can't lose data.
Both write paths downgrade the i_rwsem to shared, so extending writes
can run concurrently and the i_size read by the caller may be stale by
the time the folio is locked. Re-read i_size under the folio lock and
clamp the zeroed range up to it, so a racing write that already put
data into the folio isn't clobbered.
Wait for any writeback on the folio to finish before zeroing it so that
the pagecache isn't modified while it may still be read by the transport
during transmission. Honour IOCB_NOWAIT by returning -EAGAIN rather
than blocking on the folio lock, on writeback, or in folio_mkclean()'s
rmap walk when the folio is mapped.
truncate_pagecache() can't be used here: it must be called with the
i_rwsem held exclusively, but these write paths only hold it shared,
and it would block unconditionally, breaking IOCB_NOWAIT.
Export the helper so filesystems can clear the same stale data from
their own truncate paths.
This helper is required by the CIFS client to fix generic/363.
Closes: https://sashiko.dev/#/patchset/20260921230755.1133425-1-pc%40manguebit.org
Fixes: 938e13a73b24 ("netfs: Implement buffered write API")
Fixes: 153a9961b551 ("netfs: Implement unbuffered/DIO write support")
Signed-off-by: Paulo Alcantara <pc@manguebit.org>
Cc: Christian Brauner <brauner@kernel.org>
Cc: Matthew Wilcox <willy@infradead.org>
Cc: Namjae Jeon <linkinjeon@kernel.org>
Cc: Ronnie Sahlberg <ronniesahlberg@gmail.com>
Cc: Shyam Prasad N <sprasad@microsoft.com>
Cc: Tom Talpey <tom@talpey.com>
Cc: Bharath SM <bharathsm@microsoft.com>
Cc: stable@vger.kernel.org
---
v1 -> v2:
- Add netfs_clear_stale_post_eof() to zero (rather than drop via
truncate_pagecache()) the folio straddling the EOF; add Documentation.
v2 -> v3:
- Wait for writeback and honour IOCB_NOWAIT (-EAGAIN when the folio is
mapped or under writeback); re-read i_size under the folio lock and
clamp the zeroed range to it.
- Use uoff_t for the offset params; expand doc/kerneldoc on why
pagecache_isize_extended() can't be reused. Dropped Dave's R-b as the
code changed.
Documentation/filesystems/netfs_library.rst | 25 ++++++++
fs/netfs/buffered_write.c | 9 +++
fs/netfs/direct_write.c | 9 +++
fs/netfs/misc.c | 71 +++++++++++++++++++++
include/linux/netfs.h | 2 +
5 files changed, 116 insertions(+)
diff --git a/Documentation/filesystems/netfs_library.rst b/Documentation/filesystems/netfs_library.rst
index ddd799df6ce3..f2f22076168c 100644
--- a/Documentation/filesystems/netfs_library.rst
+++ b/Documentation/filesystems/netfs_library.rst
@@ -451,6 +451,31 @@ one.
The inode should be marked ``NETFS_ICTX_SINGLE_NO_UPLOAD`` if this API is to be
used. The writeback function requires the buffer to be of ITER_FOLIOQ type.
+Clearing Stale Post-EOF Pagecache
+---------------------------------
+
+When a file is extended, data left in the pagecache past the old EOF by a write
+through an mmap must not be exposed as file content. Netfslib clears this on
+its own write paths, and exports a helper so a filesystem can do the same from,
+for instance, its truncate or fallocate paths::
+
+ int netfs_clear_stale_post_eof(struct inode *inode, uoff_t from,
+ uoff_t to, bool nowait);
+
+This zeroes any such data within the ``[from, to)`` hole to be made, where @from
+is the current EOF. Only the folio straddling @from can hold data written past
+the EOF through an mmap, as pages wholly beyond the EOF can't be faulted in, so
+the zeroing is limited to that folio and clamped to the top of the hole. The
+folio is zeroed rather than dropped so that a concurrent extending write can't
+lose data. If @nowait is set, it returns ``-EAGAIN`` rather than blocking.
+
+This overlaps with ``pagecache_isize_extended()`` but can't reuse it: that
+helper is keyed on a sub-page block size and is a no-op when the block size is
+``>= PAGE_SIZE`` (as on network filesystems), it runs after ``i_size`` has been
+updated, it can't honour a non-blocking caller, and it doesn't wait for
+writeback. As both address the same problem, a change to one should probably be
+reflected in the other to keep them in sync.
+
High-Level VM API
==================
diff --git a/fs/netfs/buffered_write.c b/fs/netfs/buffered_write.c
index 2cdb68e6b16f..cc0561f77bd0 100644
--- a/fs/netfs/buffered_write.c
+++ b/fs/netfs/buffered_write.c
@@ -469,6 +469,7 @@ ssize_t netfs_buffered_write_iter_locked(struct kiocb *iocb, struct iov_iter *fr
struct netfs_group *netfs_group)
{
struct file *file = iocb->ki_filp;
+ struct inode *inode = file_inode(file);
ssize_t ret;
trace_netfs_write_iter(iocb, from);
@@ -481,6 +482,14 @@ ssize_t netfs_buffered_write_iter_locked(struct kiocb *iocb, struct iov_iter *fr
if (ret)
return ret;
+ if (iocb->ki_pos > i_size_read(inode)) {
+ ret = netfs_clear_stale_post_eof(inode, i_size_read(inode),
+ iocb->ki_pos,
+ iocb->ki_flags & IOCB_NOWAIT);
+ if (ret)
+ return ret;
+ }
+
return netfs_perform_write(iocb, from, netfs_group);
}
EXPORT_SYMBOL(netfs_buffered_write_iter_locked);
diff --git a/fs/netfs/direct_write.c b/fs/netfs/direct_write.c
index 2361277416c7..36c36bc6c9d2 100644
--- a/fs/netfs/direct_write.c
+++ b/fs/netfs/direct_write.c
@@ -359,6 +359,15 @@ ssize_t netfs_unbuffered_write_iter(struct kiocb *iocb, struct iov_iter *from)
ret = file_update_time(file);
if (ret < 0)
goto out;
+
+ if (iocb->ki_pos > i_size_read(inode)) {
+ ret = netfs_clear_stale_post_eof(inode, i_size_read(inode),
+ iocb->ki_pos,
+ iocb->ki_flags & IOCB_NOWAIT);
+ if (ret < 0)
+ goto out;
+ }
+
if (iocb->ki_flags & IOCB_NOWAIT) {
/* We could block if there are any pages in the range. */
ret = -EAGAIN;
diff --git a/fs/netfs/misc.c b/fs/netfs/misc.c
index f5c1c463f4ff..d93d8571c090 100644
--- a/fs/netfs/misc.c
+++ b/fs/netfs/misc.c
@@ -6,6 +6,7 @@
*/
#include <linux/swap.h>
+#include <linux/rmap.h>
#include "internal.h"
/**
@@ -582,3 +583,73 @@ void netfs_wait_for_put_ra_refs(struct netfs_io_request *rreq)
trace_netfs_rreq(rreq, netfs_rreq_trace_waited_put_ra_refs);
finish_wait(&rreq->waitq, &myself);
}
+
+/**
+ * netfs_clear_stale_post_eof - Clear stale pagecache in a to-be-created hole
+ * @inode: The inode to act upon.
+ * @from: The base of the hole to be made (the current EOF).
+ * @to: The top of the hole to be made.
+ * @nowait: True to return -EAGAIN rather than block.
+ *
+ * Before extending a file, zero any data left in the pagecache within the
+ * [@from, @to) hole by a write through an mmap so that it isn't exposed as file
+ * content once the file is extended. Only the uptodate folio straddling @from
+ * can hold such data as pages wholly beyond the EOF can't be faulted in, so the
+ * zeroing is limited to that folio. The folio is zeroed rather than dropped so
+ * that a concurrent extending write can't lose data, and the zeroed range is
+ * clamped to the current EOF so it can't clobber data written by such a write.
+ *
+ * pagecache_isize_extended() can't be reused here: it is keyed on a sub-page
+ * block size (a no-op when the block size is >= PAGE_SIZE, as on network
+ * filesystems), runs after i_size is updated, can't honour @nowait, and
+ * doesn't wait for writeback. Keep the two in sync if either is changed.
+ *
+ * Return: 0 on success, or -EAGAIN if @nowait is set and the folio is mapped
+ * or under writeback and so can't be cleaned without blocking.
+ */
+int netfs_clear_stale_post_eof(struct inode *inode, uoff_t from,
+ uoff_t to, bool nowait)
+{
+ struct address_space *mapping = inode->i_mapping;
+ fgf_t fgp = FGP_LOCK;
+ struct folio *folio;
+ int ret;
+
+ if (from >= to)
+ return 0;
+
+ if (nowait)
+ fgp |= FGP_NOWAIT;
+
+ folio = __filemap_get_folio(mapping, from >> PAGE_SHIFT, fgp, 0);
+ if (IS_ERR(folio))
+ return PTR_ERR(folio) == -EAGAIN ? -EAGAIN : 0;
+
+ ret = 0;
+ if (nowait && (folio_mapped(folio) || folio_test_writeback(folio))) {
+ ret = -EAGAIN;
+ goto out;
+ }
+
+ folio_wait_writeback(folio);
+
+ if (folio_mkclean(folio))
+ folio_mark_dirty(folio);
+
+ if (folio_test_uptodate(folio)) {
+ uoff_t fpos = folio_pos(folio);
+
+ from = umax(from, i_size_read(inode));
+ if (from < to && from < fpos + folio_size(folio)) {
+ size_t end = umin(to - fpos, folio_size(folio));
+ size_t offset = from - fpos;
+
+ folio_zero_segment(folio, offset, end);
+ }
+ }
+out:
+ folio_unlock(folio);
+ folio_put(folio);
+ return ret;
+}
+EXPORT_SYMBOL(netfs_clear_stale_post_eof);
diff --git a/include/linux/netfs.h b/include/linux/netfs.h
index b4dd32863dd4..c7b2ac404853 100644
--- a/include/linux/netfs.h
+++ b/include/linux/netfs.h
@@ -397,6 +397,8 @@ ssize_t netfs_unbuffered_write_iter(struct kiocb *iocb, struct iov_iter *from);
ssize_t netfs_unbuffered_write_iter_locked(struct kiocb *iocb, struct iov_iter *iter,
struct netfs_group *netfs_group);
ssize_t netfs_file_write_iter(struct kiocb *iocb, struct iov_iter *from);
+int netfs_clear_stale_post_eof(struct inode *inode, uoff_t from,
+ uoff_t to, bool nowait);
/* Single, monolithic object read/write API. */
void netfs_single_mark_inode_dirty(struct inode *inode);
base-commit: e66cf1625ec4a3fe68346119f371def713fd0a4d
--
2.55.0
^ permalink raw reply related [flat|nested] 5+ messages in thread* [PATCH v3 2/5] smb: client: clear post-EOF pagecache when extending a file via truncate
2026-09-25 14:37 [PATCH v3 1/5] netfs: clear post-EOF pagecache when extending a file via write Paulo Alcantara
@ 2026-09-25 14:37 ` Paulo Alcantara
2026-09-25 14:37 ` [PATCH v3 3/5] smb: client: discard post-EOF pagecache when extending a file via zero range Paulo Alcantara
` (2 subsequent siblings)
3 siblings, 0 replies; 5+ messages in thread
From: Paulo Alcantara @ 2026-09-25 14:37 UTC (permalink / raw)
To: linux-cifs, netfs
Cc: Christian Brauner, Matthew Wilcox, Namjae Jeon, Ronnie Sahlberg,
Shyam Prasad N, Tom Talpey, Bharath SM, stable
cifs_setsize() relied on pagecache_isize_extended() to zero the tail of
the folio straddling the old EOF, but that helper is a no-op on CIFS
(i_blkbits is 14), so data dirtied past EOF through an mmap survived and
became visible once the file was extended.
When extending, zero the tail of the folio straddling the old EOF with
netfs_clear_stale_post_eof() instead, mirroring what
pagecache_isize_extended() does for filesystems with a sub-page block
size. Do this before updating i_size so that the helper, which clamps
its zeroing to the current EOF, zeroes the whole [old_size, offset)
hole. truncate_pagecache() is then called as in truncate_setsize(): it
is essentially a no-op on extend and drops the pagecache beyond the new
EOF on shrink.
Closes: https://sashiko.dev/#/patchset/20260921230755.1133425-1-pc%40manguebit.org
Fixes: c510edb9734a ("cifs: call pagecache_isize_extended() in cifs_setsize() when extending")
Signed-off-by: Paulo Alcantara <pc@manguebit.org>
Cc: Christian Brauner <brauner@kernel.org>
Cc: Matthew Wilcox <willy@infradead.org>
Cc: Namjae Jeon <linkinjeon@kernel.org>
Cc: Ronnie Sahlberg <ronniesahlberg@gmail.com>
Cc: Shyam Prasad N <sprasad@microsoft.com>
Cc: Tom Talpey <tom@talpey.com>
Cc: Bharath SM <bharathsm@microsoft.com>
Cc: stable@vger.kernel.org
---
v1 -> v2:
- Zero the folio straddling the old EOF via netfs_clear_stale_post_eof()
instead of lowering the truncate_pagecache() boundary.
v2 -> v3:
- Call the helper before updating i_size (required by its clamp-to-EOF)
and simplify the comment. Dropped Dave's R-b as the code changed.
fs/smb/client/inode.c | 16 +++++++++++++---
1 file changed, 13 insertions(+), 3 deletions(-)
diff --git a/fs/smb/client/inode.c b/fs/smb/client/inode.c
index 1fe0ef0a95db..7988ddfd2bfd 100644
--- a/fs/smb/client/inode.c
+++ b/fs/smb/client/inode.c
@@ -3060,8 +3060,19 @@ void cifs_setsize(struct inode *inode, loff_t offset)
spin_lock(&inode->i_lock);
old_size = i_size_read(inode);
+ spin_unlock(&inode->i_lock);
+
+ /*
+ * When extending, zero the tail of the folio straddling the old EOF
+ * (before updating i_size) so data dirtied past EOF through an mmap
+ * isn't exposed. truncate_pagecache() then drops any pagecache beyond
+ * the new EOF, as in truncate_setsize().
+ */
+ if (offset > old_size)
+ netfs_clear_stale_post_eof(inode, old_size, offset, false);
+
+ spin_lock(&inode->i_lock);
i_size_write(inode, offset);
-
/*
* Extending EOF does not allocate the intervening range. Only clamp
* i_blocks on shrink; allocation growth comes from writes or from the
@@ -3071,8 +3082,7 @@ void cifs_setsize(struct inode *inode, loff_t offset)
inode->i_blocks = blocks;
spin_unlock(&inode->i_lock);
inode_set_mtime_to_ts(inode, inode_set_ctime_current(inode));
- if (offset > old_size)
- pagecache_isize_extended(inode, old_size, offset);
+
truncate_pagecache(inode, offset);
netfs_wait_for_outstanding_io(inode);
}
--
2.55.0
^ permalink raw reply related [flat|nested] 5+ messages in thread* [PATCH v3 3/5] smb: client: discard post-EOF pagecache when extending a file via zero range
2026-09-25 14:37 [PATCH v3 1/5] netfs: clear post-EOF pagecache when extending a file via write Paulo Alcantara
2026-09-25 14:37 ` [PATCH v3 2/5] smb: client: clear post-EOF pagecache when extending a file via truncate Paulo Alcantara
@ 2026-09-25 14:37 ` Paulo Alcantara
2026-09-25 14:37 ` [PATCH v3 4/5] smb: client: discard post-EOF pagecache when extending a file via copy range Paulo Alcantara
2026-09-25 14:37 ` [PATCH v3 5/5] smb: client: discard post-EOF pagecache when extending a file via clone range Paulo Alcantara
3 siblings, 0 replies; 5+ messages in thread
From: Paulo Alcantara @ 2026-09-25 14:37 UTC (permalink / raw)
To: linux-cifs, netfs
Cc: David Howells, Christian Brauner, Matthew Wilcox, Namjae Jeon,
Ronnie Sahlberg, Shyam Prasad N, Tom Talpey, Bharath SM, stable
smb3_zero_range() removed the pagecache only for the range being zeroed,
so when it extends the file the folio straddling the old EOF - which may
hold data dirtied past EOF through an mmap - was never dropped and became
visible as file content once the file was extended.
Lower the discard boundary to the smaller of the zero-range offset and the
old EOF.
Fixes: 72c419d9b073 ("cifs: fix smb3_zero_range so it can expand the file-size when required")
Reviewed-by: David Howells <dhowells@redhat.com>
Signed-off-by: Paulo Alcantara <pc@manguebit.org>
Cc: Christian Brauner <brauner@kernel.org>
Cc: Matthew Wilcox <willy@infradead.org>
Cc: Namjae Jeon <linkinjeon@kernel.org>
Cc: Ronnie Sahlberg <ronniesahlberg@gmail.com>
Cc: Shyam Prasad N <sprasad@microsoft.com>
Cc: Tom Talpey <tom@talpey.com>
Cc: Bharath SM <bharathsm@microsoft.com>
Cc: stable@vger.kernel.org
---
v1 -> v2: no changes
v2 -> v3: no changes
fs/smb/client/smb2ops.c | 5 ++++-
1 file changed, 4 insertions(+), 1 deletion(-)
diff --git a/fs/smb/client/smb2ops.c b/fs/smb/client/smb2ops.c
index aa142420dae2..e55e081e47b9 100644
--- a/fs/smb/client/smb2ops.c
+++ b/fs/smb/client/smb2ops.c
@@ -3558,8 +3558,11 @@ static long smb3_zero_range(struct file *file, struct cifs_tcon *tcon,
/*
* We zero the range through ioctl, so we need remove the page caches
* first, otherwise the data may be inconsistent with the server.
+ *
+ * Start at the old EOF when extending so the folio straddling it, which
+ * may hold data written past EOF through an mmap, is dropped too.
*/
- truncate_pagecache_range(inode, offset, offset + len - 1);
+ truncate_pagecache_range(inode, min(offset, i_size), offset + len - 1);
netfs_wait_for_outstanding_io(inode);
/* if file not oplocked can't be sure whether asking to extend size */
--
2.55.0
^ permalink raw reply related [flat|nested] 5+ messages in thread* [PATCH v3 4/5] smb: client: discard post-EOF pagecache when extending a file via copy range
2026-09-25 14:37 [PATCH v3 1/5] netfs: clear post-EOF pagecache when extending a file via write Paulo Alcantara
2026-09-25 14:37 ` [PATCH v3 2/5] smb: client: clear post-EOF pagecache when extending a file via truncate Paulo Alcantara
2026-09-25 14:37 ` [PATCH v3 3/5] smb: client: discard post-EOF pagecache when extending a file via zero range Paulo Alcantara
@ 2026-09-25 14:37 ` Paulo Alcantara
2026-09-25 14:37 ` [PATCH v3 5/5] smb: client: discard post-EOF pagecache when extending a file via clone range Paulo Alcantara
3 siblings, 0 replies; 5+ messages in thread
From: Paulo Alcantara @ 2026-09-25 14:37 UTC (permalink / raw)
To: linux-cifs, netfs
Cc: David Howells, Christian Brauner, Matthew Wilcox, Namjae Jeon,
Ronnie Sahlberg, Shyam Prasad N, Tom Talpey, Bharath SM, stable
cifs_file_copychunk_range() invalidated the pagecache only for the
destination region, so when a copy extends the file the folio straddling
the old EOF - which may hold data dirtied past EOF through an mmap - was
never dropped and became visible as file content once the file was
extended.
Start the invalidation at the smaller of the destination offset and the
old EOF. filemap_invalidate_inode() writes back before invalidating
while i_size is still old, so nothing past the old EOF is flushed to the
server.
Fixes: 8101d6e112e2 ("cifs: Fix copy offload to flush destination region")
Reviewed-by: David Howells <dhowells@redhat.com>
Signed-off-by: Paulo Alcantara <pc@manguebit.org>
Cc: Christian Brauner <brauner@kernel.org>
Cc: Matthew Wilcox <willy@infradead.org>
Cc: Namjae Jeon <linkinjeon@kernel.org>
Cc: Ronnie Sahlberg <ronniesahlberg@gmail.com>
Cc: Shyam Prasad N <sprasad@microsoft.com>
Cc: Tom Talpey <tom@talpey.com>
Cc: Bharath SM <bharathsm@microsoft.com>
Cc: stable@vger.kernel.org
---
v1 -> v2: no changes
v2 -> v3: no changes
fs/smb/client/cifsfs.c | 7 ++++++-
1 file changed, 6 insertions(+), 1 deletion(-)
diff --git a/fs/smb/client/cifsfs.c b/fs/smb/client/cifsfs.c
index 7ecd70efdfea..f1fb4b7b7b7c 100644
--- a/fs/smb/client/cifsfs.c
+++ b/fs/smb/client/cifsfs.c
@@ -1581,8 +1581,13 @@ ssize_t cifs_file_copychunk_range(unsigned int xid,
/* Flush and invalidate all the folios in the destination region. If
* the copy was successful, then some of the flush is extra overhead,
* but we need to allow for the copy failing in some way (eg. ENOSPC).
+ *
+ * Start at the old EOF when extending so the folio straddling it, which
+ * may hold data written past EOF through an mmap, is dropped too.
*/
- rc = filemap_invalidate_inode(target_inode, true, destoff, destoff + len - 1);
+ rc = filemap_invalidate_inode(target_inode, true,
+ min(destoff, i_size_read(target_inode)),
+ destoff + len - 1);
if (rc)
goto unlock;
--
2.55.0
^ permalink raw reply related [flat|nested] 5+ messages in thread* [PATCH v3 5/5] smb: client: discard post-EOF pagecache when extending a file via clone range
2026-09-25 14:37 [PATCH v3 1/5] netfs: clear post-EOF pagecache when extending a file via write Paulo Alcantara
` (2 preceding siblings ...)
2026-09-25 14:37 ` [PATCH v3 4/5] smb: client: discard post-EOF pagecache when extending a file via copy range Paulo Alcantara
@ 2026-09-25 14:37 ` Paulo Alcantara
3 siblings, 0 replies; 5+ messages in thread
From: Paulo Alcantara @ 2026-09-25 14:37 UTC (permalink / raw)
To: linux-cifs, netfs
Cc: David Howells, Christian Brauner, Matthew Wilcox, Namjae Jeon,
Ronnie Sahlberg, Shyam Prasad N, Tom Talpey, Bharath SM, stable
cifs_remap_file_range() discarded the pagecache only for the folios
overlapping the destination region, so when a clone extends the file the
folio straddling the old EOF - which may hold data dirtied past EOF
through an mmap - was never dropped and became visible as file content
once the file was extended.
Start the discard at the smaller of fstart and the old EOF. i_size is
still old here, so nothing past the old EOF is flushed to the server.
Fixes: c54fc3a4f375 ("cifs: Fix flushing, invalidation and file size with FICLONE")
Reviewed-by: David Howells <dhowells@redhat.com>
Signed-off-by: Paulo Alcantara <pc@manguebit.org>
Cc: Christian Brauner <brauner@kernel.org>
Cc: Matthew Wilcox <willy@infradead.org>
Cc: Namjae Jeon <linkinjeon@kernel.org>
Cc: Ronnie Sahlberg <ronniesahlberg@gmail.com>
Cc: Shyam Prasad N <sprasad@microsoft.com>
Cc: Tom Talpey <tom@talpey.com>
Cc: Bharath SM <bharathsm@microsoft.com>
Cc: stable@vger.kernel.org
---
v1 -> v2: no changes
v2 -> v3: no changes
fs/smb/client/cifsfs.c | 9 +++++++--
1 file changed, 7 insertions(+), 2 deletions(-)
diff --git a/fs/smb/client/cifsfs.c b/fs/smb/client/cifsfs.c
index f1fb4b7b7b7c..6410249f529a 100644
--- a/fs/smb/client/cifsfs.c
+++ b/fs/smb/client/cifsfs.c
@@ -1467,9 +1467,14 @@ static loff_t cifs_remap_file_range(struct file *src_file, loff_t off,
i_size = target_inode->i_size;
spin_unlock(&target_inode->i_lock);
- /* Discard all the folios that overlap the destination region. */
+ /*
+ * Discard all the folios that overlap the destination region. Start at
+ * the old EOF when extending so the folio straddling it, which may hold
+ * data written past EOF through an mmap, is dropped too.
+ */
cifs_dbg(FYI, "about to discard pages %llx-%llx\n", fstart, fend);
- truncate_inode_pages_range(&target_inode->i_data, fstart, fend);
+ truncate_inode_pages_range(&target_inode->i_data,
+ min(fstart, i_size), fend);
fscache_invalidate(cifs_inode_cookie(target_inode), NULL, i_size, 0);
--
2.55.0
^ permalink raw reply related [flat|nested] 5+ messages in thread
end of thread, other threads:[~2026-09-25 14:37 UTC | newest]
Thread overview: 5+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-25 14:37 [PATCH v3 1/5] netfs: clear post-EOF pagecache when extending a file via write Paulo Alcantara
2026-09-25 14:37 ` [PATCH v3 2/5] smb: client: clear post-EOF pagecache when extending a file via truncate Paulo Alcantara
2026-09-25 14:37 ` [PATCH v3 3/5] smb: client: discard post-EOF pagecache when extending a file via zero range Paulo Alcantara
2026-09-25 14:37 ` [PATCH v3 4/5] smb: client: discard post-EOF pagecache when extending a file via copy range Paulo Alcantara
2026-09-25 14:37 ` [PATCH v3 5/5] smb: client: discard post-EOF pagecache when extending a file via clone range Paulo Alcantara
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox