From: "Darrick J. Wong" <djwong@kernel.org>
To: sashiko-reviews@lists.linux.dev
Cc: Andrey Albershteyn <aalbersh@kernel.org>,
linux-ext4@vger.kernel.org, tytso@mit.edu, dsterba@suse.cz
Subject: Re: [PATCH v16 13/21] xfs: add XFS_BMAPI_UNWRITTEN to unmap unwritten extents in __xfs_bunmapi()
Date: Mon, 21 Sep 2026 21:49:11 -0700 [thread overview]
Message-ID: <20260922044911.GA6239@frogsfrogsfrogs> (raw)
In-Reply-To: <20260918113212.B80601F00899@smtp.kernel.org>
On Fri, Sep 18, 2026 at 11:32:12AM +0000, sashiko-bot@kernel.org wrote:
> Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
> - [Critical] xfs: XFS_BMAPI_UNWRITTEN corrupts data on realtime files
> --
>
> commit 03f3992d52956762d29c7c4c4908adeac76b8662
> Author: Andrey Albershteyn <aalbersh@kernel.org>
> xfs: add XFS_BMAPI_UNWRITTEN to unmap unwritten extents in __xfs_bunmapi()
>
> The __xfs_bunmapi() function is used to remove all extents past EOF. This
> patch adds XFS_BMAPI_UNWRITTEN to remove only unwritten extents, leaving
> written ones in place. This will be used to clean up unwritten extents on
> fsverity inodes.
>
> > diff --git a/fs/xfs/libxfs/xfs_bmap.c b/fs/xfs/libxfs/xfs_bmap.c
> > index ba6a9611f6f9d..69364abbfd011 100644
> > --- a/fs/xfs/libxfs/xfs_bmap.c
> > +++ b/fs/xfs/libxfs/xfs_bmap.c
> > @@ -5279,6 +5279,10 @@ __xfs_bunmapi(
> > if (del.br_startoff + del.br_blockcount > end + 1)
> > del.br_blockcount = end + 1 - del.br_startoff;
> >
> > + if ((flags & XFS_BMAPI_UNWRITTEN) &&
> > + del.br_state != XFS_EXT_UNWRITTEN)
> > + goto skip;
> > +
> > if (!isrt || (flags & XFS_BMAPI_REMAP))
> > goto delete;
> >
>
> [Severity: Critical]
> Does introducing the XFS_BMAPI_UNWRITTEN flag cause data corruption on
> realtime files due to how __xfs_bunmapi() handles unwritten extents?
>
> If a user creates a realtime file, writes data so that EOF is not aligned
> to the realtime extent size, and preallocates space after EOF (creating an
> unwritten extent), subsequent calls to clean up with XFS_BMAPI_UNWRITTEN
> (such as enabling fs-verity) will process the front-misaligned unwritten
> extent.
>
> Because __xfs_bunmapi() falls through to the legacy realtime misalignment
> logic for unwritten extents:
>
> } else if (del.br_state == XFS_EXT_UNWRITTEN) {
> struct xfs_bmbt_irec prev;
> ...
> /*
> * This one is already unwritten.
> * It must have a written left neighbor.
> * Unwrite the killed part of that one and
> * try again.
> */
> ...
> prev.br_state = XFS_EXT_UNWRITTEN;
> error = xfs_bmap_add_extent_unwritten_real(tp,
> ip, whichfork, &icur, &cur,
> &prev, &logflags);
>
> Could this legacy truncation logic forcefully unwrite the written left
> neighbor (the valid user data before EOF) to form a full realtime extent,
> effectively destroying the mapping to valid user data?
Yes. Either we don't support fsverity with rt files when rtextsize > 1,
or I guess we have to figure out something else? Only removing full
rtextents? Or just leaving them in place?
--D
> [ ... ]
>
> --
> Sashiko AI review · https://sashiko.dev/#/patchset/20260918111539.1003439-1-aalbersh@kernel.org?part=13
>
next prev parent reply other threads:[~2026-09-22 4:49 UTC|newest]
Thread overview: 67+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-18 11:15 [PATCH v16 00/21] fs-verity support for XFS with post EOF merkle tree Andrey Albershteyn
2026-09-18 11:15 ` [PATCH v16 01/21] fsverity: report validation errors through fserror to fsnotify Andrey Albershteyn
2026-09-18 11:27 ` sashiko-bot
2026-09-18 11:15 ` [PATCH v16 02/21] fsverity: expose ensure_fsverity_info() Andrey Albershteyn
2026-09-18 11:32 ` sashiko-bot
2026-09-18 11:15 ` [PATCH v16 03/21] fsverity: pass digest size and hash of the all-zeroes block to ->write Andrey Albershteyn
2026-09-18 11:24 ` sashiko-bot
2026-09-18 11:15 ` [PATCH v16 04/21] fsverity: hoist pagecache_read from f2fs/ext4 to fsverity Andrey Albershteyn
2026-09-18 11:26 ` sashiko-bot
2026-09-18 11:15 ` [PATCH v16 05/21] fsverity: don't allow setting DAX file attribute on fsverity files Andrey Albershteyn
2026-09-18 11:28 ` sashiko-bot
2026-09-25 4:35 ` Eric Biggers
2026-09-18 11:15 ` [PATCH v16 06/21] fsverity: hoist statx reporting of fs-verity flag Andrey Albershteyn
2026-09-18 11:28 ` sashiko-bot
2026-09-18 11:15 ` [PATCH v16 07/21] xfs: introduce fsverity on-disk changes Andrey Albershteyn
2026-09-18 11:34 ` sashiko-bot
2026-09-18 11:15 ` [PATCH v16 08/21] xfs: don't allow to enable DAX on fs-verity sealed inode Andrey Albershteyn
2026-09-18 11:27 ` sashiko-bot
2026-09-18 11:15 ` [PATCH v16 09/21] xfs: disable direct read path for fs-verity files Andrey Albershteyn
2026-09-18 11:26 ` sashiko-bot
2026-09-18 11:15 ` [PATCH v16 10/21] xfs: don't report dio_mem_align and dio_offset_align for fsverity files Andrey Albershteyn
2026-09-18 11:26 ` sashiko-bot
2026-09-18 11:15 ` [PATCH v16 11/21] xfs: handle fsverity I/O in write/read path Andrey Albershteyn
2026-09-18 11:38 ` sashiko-bot
2026-09-22 7:15 ` Christoph Hellwig
2026-09-18 11:15 ` [PATCH v16 12/21] xfs: use read ioend for fsverity data verification Andrey Albershteyn
2026-09-18 11:36 ` sashiko-bot
2026-09-22 4:29 ` Darrick J. Wong
2026-09-22 7:18 ` Christoph Hellwig
2026-09-22 9:13 ` Andrey Albershteyn
2026-09-22 12:31 ` Christoph Hellwig
2026-09-22 13:17 ` Andrey Albershteyn
2026-09-18 11:15 ` [PATCH v16 13/21] xfs: add XFS_BMAPI_UNWRITTEN to unmap unwritten extents in __xfs_bunmapi() Andrey Albershteyn
2026-09-18 11:32 ` sashiko-bot
2026-09-22 4:49 ` Darrick J. Wong [this message]
2026-09-22 4:34 ` Darrick J. Wong
2026-09-22 7:20 ` Christoph Hellwig
2026-09-22 8:32 ` Andrey Albershteyn
2026-09-18 11:15 ` [PATCH v16 14/21] xfs: don't remove written extents past EOF on fsverity inodes Andrey Albershteyn
2026-09-18 11:41 ` sashiko-bot
2026-09-22 4:37 ` Darrick J. Wong
2026-09-22 8:33 ` Andrey Albershteyn
2026-09-22 11:29 ` Andrey Albershteyn
2026-09-18 11:15 ` [PATCH v16 15/21] xfs: add fs-verity support Andrey Albershteyn
2026-09-18 11:43 ` sashiko-bot
2026-09-22 4:50 ` Darrick J. Wong
2026-09-22 4:45 ` Darrick J. Wong
2026-09-22 9:27 ` Andrey Albershteyn
2026-09-22 7:22 ` Christoph Hellwig
2026-09-22 8:56 ` Andrey Albershteyn
2026-09-22 12:32 ` Christoph Hellwig
2026-09-22 13:27 ` Andrey Albershteyn
2026-09-23 4:44 ` Christoph Hellwig
2026-09-18 11:15 ` [PATCH v16 16/21] xfs: initialize fs-verity on file open Andrey Albershteyn
2026-09-18 11:33 ` sashiko-bot
2026-09-18 11:15 ` [PATCH v16 17/21] xfs: add fs-verity ioctls Andrey Albershteyn
2026-09-18 11:31 ` sashiko-bot
2026-09-18 11:15 ` [PATCH v16 18/21] xfs: advertise fs-verity being available on filesystem Andrey Albershteyn
2026-09-18 11:30 ` sashiko-bot
2026-09-18 11:15 ` [PATCH v16 19/21] xfs: check and repair the verity inode flag state Andrey Albershteyn
2026-09-18 11:40 ` sashiko-bot
2026-09-18 11:15 ` [PATCH v16 20/21] xfs: introduce health state for corrupted fsverity metadata Andrey Albershteyn
2026-09-18 11:34 ` sashiko-bot
2026-09-18 11:15 ` [PATCH v16 21/21] xfs: enable ro-compat fs-verity flag Andrey Albershteyn
2026-09-18 11:44 ` sashiko-bot
2026-09-22 4:51 ` [PATCH v16 00/21] fs-verity support for XFS with post EOF merkle tree Darrick J. Wong
2026-09-22 9:00 ` Andrey Albershteyn
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260922044911.GA6239@frogsfrogsfrogs \
--to=djwong@kernel.org \
--cc=aalbersh@kernel.org \
--cc=dsterba@suse.cz \
--cc=linux-ext4@vger.kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
--cc=tytso@mit.edu \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox