From: sashiko-bot@kernel.org
To: "Zhang Yi" <yi.zhang@huaweicloud.com>
Cc: linux-ext4@vger.kernel.org, tytso@mit.edu
Subject: Re: [PATCH -next v5 19/32] ext4: tolerate unexpected holes in ext4_convert_unwritten_extents()
Date: Fri, 14 Aug 2026 10:09:17 +0000 [thread overview]
Message-ID: <20260814100917.CB2301F000E9@smtp.kernel.org> (raw)
In-Reply-To: <20260814093331.1703882-20-yi.zhang@huaweicloud.com>
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [Critical] The patch masks a severe physical block Use-After-Free that causes silent data corruption by suppressing the warning when IO completion observes a hole.
--
--- Patch [19]: [PATCH -next v5 19/32] ext4: tolerate unexpected holes in ext4_convert_unwritten_extents() ---
commit 024b041d5cfa7f6f30a260ff0a2a3cd17336e881
Author: Zhang Yi <yi.zhang@huawei.com>
Subject: ext4: tolerate unexpected holes in ext4_convert_unwritten_extents()
This patch suppresses the warning in ext4_convert_unwritten_extents() when
ext4_map_blocks() returns 0 (indicating a hole). It aims to handle the case
where a punch hole operation races with writeback when folio sizes are larger
than the block size.
Link: https://lore.kernel.org/linux-ext4/a638a8fb-c184-4069-ae33-379ec12cd514@huaweicloud.com/
> diff --git a/fs/ext4/extents.c b/fs/ext4/extents.c
> --- a/fs/ext4/extents.c
> +++ b/fs/ext4/extents.c
[ ... ]
> @@ -5166,19 +5166,21 @@ int ext4_convert_unwritten_extents(handle_t *handle, struct inode *inode,
> ret = ext4_map_blocks(handle, inode, &map,
> EXT4_GET_BLOCKS_IO_CONVERT_EXT |
> EXT4_EX_NOCACHE);
> - if (ret <= 0) {
> - /*
> - * If the ret is zero, an unexpected hole may cause
> - * conversion to fail. To avoid data loss during I/O
> - * end conversion, skip the hole and continue
> - * converting subsequent blocks.
> - */
> + /*
> + * A return value of zero means an unexpected hole was found.
> + * This can happen when writeback races with a concurrent
> + * punch hole in the iomap path. Because iomap may not create
> + * ifs for folios larger than block size, the dirty bit can
> + * be set again after punching. If writeback happens between
> + * partial folio invalidation and extent removal, a hole is
> + * observed at I/O completion.
> + */
> + if (ret < 0)
> ext4_warning(inode->i_sb,
> "inode #%llu: block %u: len %u: ext4_map_blocks returned %d",
> inode->i_ino, map.m_lblk, map.m_len, ret);
> - } else {
> + else if (ret > 0)
> conv_blocks += map.m_len;
[Severity: Critical]
Does masking the ret == 0 case here hide a physical block use-after-free?
If background writeback via ext4_iomap_writepages() submits a write bio for
the dirty folio, and a concurrent ext4_punch_hole() removes the extent, the
physical blocks are freed.
Since JBD2 does not wait for this in-flight bio during transaction commit
(due to data=ordered mode being disabled for iomap inodes), those blocks
return to the free pool and can be reallocated to another file.
When the in-flight write bio finally completes, will it silently overwrite
the newly reallocated blocks and cause data corruption?
Instead of silencing the warning during IO completion in
ext4_convert_unwritten_extents(), could the underlying race be prevented by
ensuring sub-folio dirty state is properly tracked so that punched blocks
are not submitted for writeback in the first place?
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260814093331.1703882-1-yi.zhang@huaweicloud.com?part=19
next prev parent reply other threads:[~2026-08-14 10:09 UTC|newest]
Thread overview: 65+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-14 9:32 [PATCH -next v5 00/32] ext4: use iomap for regular file's buffered I/O path Zhang Yi
2026-08-14 9:33 ` [PATCH -next v5 01/32] ext4: simplify size updating in ext4_setattr() Zhang Yi
2026-08-14 10:02 ` sashiko-bot
2026-08-14 9:33 ` [PATCH -next v5 02/32] ext4: factor out ext4_truncate_[up|down]() Zhang Yi
2026-08-14 10:04 ` sashiko-bot
2026-08-14 9:33 ` [PATCH -next v5 03/32] ext4: simplify error handling in ext4_setattr() Zhang Yi
2026-08-14 10:12 ` sashiko-bot
2026-08-14 9:33 ` [PATCH -next v5 04/32] ext4: skip ordered I/O wait when zeroing beyond i_disksize block Zhang Yi
2026-08-14 10:14 ` sashiko-bot
2026-08-14 9:33 ` [PATCH -next v5 05/32] ext4: set EXT4_MAP_NEW flag for delayed allocated blocks Zhang Yi
2026-08-14 10:08 ` sashiko-bot
2026-08-14 9:33 ` [PATCH -next v5 06/32] ext4: recheck extent status tree before block allocation Zhang Yi
2026-08-14 10:15 ` sashiko-bot
2026-08-14 9:33 ` [PATCH -next v5 07/32] ext4: fix orig_mlen initialization in ext4_map_blocks() Zhang Yi
2026-08-14 10:08 ` sashiko-bot
2026-08-14 9:33 ` [PATCH -next v5 08/32] ext4: allow ext4_map_blocks() to start its own transaction handle Zhang Yi
2026-08-14 10:00 ` sashiko-bot
2026-08-14 9:33 ` [PATCH -next v5 09/32] ext4: avoid unnecessary transaction in ext4_map_blocks() for unwritten extents Zhang Yi
2026-08-14 10:15 ` sashiko-bot
2026-08-14 9:33 ` [PATCH -next v5 10/32] ext4: skip block allocation for holes in the data submission path Zhang Yi
2026-08-14 10:15 ` sashiko-bot
2026-08-14 9:33 ` [PATCH -next v5 11/32] ext4: add iomap address space operations for buffered I/O Zhang Yi
2026-08-14 10:04 ` sashiko-bot
2026-08-14 9:33 ` [PATCH -next v5 12/32] ext4: implement buffered read path using iomap Zhang Yi
2026-08-14 10:15 ` sashiko-bot
2026-08-14 9:33 ` [PATCH -next v5 13/32] ext4: pass out extent seq counter when mapping da blocks Zhang Yi
2026-08-14 10:12 ` sashiko-bot
2026-08-14 9:33 ` [PATCH -next v5 14/32] ext4: do not use data=ordered mode for inodes using buffered iomap path Zhang Yi
2026-08-14 10:12 ` sashiko-bot
2026-08-14 9:33 ` [PATCH -next v5 15/32] ext4: implement buffered write path using iomap Zhang Yi
2026-08-14 10:40 ` sashiko-bot
2026-08-14 9:33 ` [PATCH -next v5 16/32] ext4: implement writeback " Zhang Yi
2026-08-14 10:19 ` sashiko-bot
2026-08-14 9:33 ` [PATCH -next v5 17/32] ext4: implement mmap " Zhang Yi
2026-08-14 10:35 ` sashiko-bot
2026-08-14 9:33 ` [PATCH -next v5 18/32] ext4: implement partial block zero range " Zhang Yi
2026-08-14 10:25 ` sashiko-bot
2026-08-14 9:33 ` [PATCH -next v5 19/32] ext4: tolerate unexpected holes in ext4_convert_unwritten_extents() Zhang Yi
2026-08-14 10:09 ` sashiko-bot [this message]
2026-08-14 9:33 ` [PATCH -next v5 20/32] ext4: add block mapping tracepoints for iomap buffered I/O path Zhang Yi
2026-08-14 10:08 ` sashiko-bot
2026-08-14 9:33 ` [PATCH -next v5 21/32] ext4: disable online defrag when inode using " Zhang Yi
2026-08-14 10:08 ` sashiko-bot
2026-08-14 9:33 ` [PATCH -next v5 22/32] ext4: add EXT4_STATE_DISKSIZE_GROW_PENDING state bit and helpers Zhang Yi
2026-08-14 10:09 ` sashiko-bot
2026-08-14 9:33 ` [PATCH -next v5 23/32] ext4: submit and wait for pending disksize-grow I/O on writeback Zhang Yi
2026-08-14 10:25 ` sashiko-bot
2026-08-14 9:33 ` [PATCH -next v5 24/32] ext4: advance i_disksize to i_size upon disksize-grow I/O completion Zhang Yi
2026-08-14 10:25 ` sashiko-bot
2026-08-14 9:33 ` [PATCH -next v5 25/32] ext4: defer i_disksize update while DISKSIZE_GROW_PENDING is set Zhang Yi
2026-08-14 10:31 ` sashiko-bot
2026-08-14 9:33 ` [PATCH -next v5 26/32] ext4: submit and wait for disksize-grow I/O in fallocate paths Zhang Yi
2026-08-14 10:28 ` sashiko-bot
2026-08-14 9:33 ` [PATCH -next v5 27/32] ext4: clear DISKSIZE_GROW_PENDING on truncate or error Zhang Yi
2026-08-14 10:31 ` sashiko-bot
2026-08-14 9:33 ` [PATCH -next v5 28/32] ext4: set DISKSIZE_GROW_PENDING after zeroing unaligned EOF block Zhang Yi
2026-08-14 10:18 ` sashiko-bot
2026-08-14 9:33 ` [PATCH -next v5 29/32] ext4: add tracepoints for DISKSIZE_GROW_PENDING set, clear, and wait Zhang Yi
2026-08-14 10:18 ` sashiko-bot
2026-08-14 9:33 ` [PATCH -next v5 30/32] ext4: add tracepoints for EOF block zeroing and disksize-grow I/O Zhang Yi
2026-08-14 10:19 ` sashiko-bot
2026-08-14 9:46 ` [PATCH -next v5 31/32] ext4: partially enable iomap for the buffered I/O path of regular files Zhang Yi
2026-08-14 10:39 ` sashiko-bot
2026-08-14 9:46 ` [PATCH -next v5 32/32] ext4: introduce a mount option for iomap buffered I/O path Zhang Yi
2026-08-14 10:25 ` sashiko-bot
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260814100917.CB2301F000E9@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=linux-ext4@vger.kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
--cc=tytso@mit.edu \
--cc=yi.zhang@huaweicloud.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox