Linux network filesystem support library
 help / color / mirror / Atom feed
From: Paulo Alcantara <pc@manguebit.org>
To: linux-cifs@vger.kernel.org, netfs@lists.linux.dev
Cc: Christian Brauner <brauner@kernel.org>,
	David Howells <dhowells@redhat.com>,
	Matthew Wilcox <willy@infradead.org>,
	Namjae Jeon <linkinjeon@kernel.org>,
	Ronnie Sahlberg <ronniesahlberg@gmail.com>,
	Shyam Prasad N <sprasad@microsoft.com>,
	Tom Talpey <tom@talpey.com>, Bharath SM <bharathsm@microsoft.com>
Subject: [PATCH 00/15] netfs, cifs: data corruption fixes
Date: Mon, 28 Sep 2026 17:09:19 -0300	[thread overview]
Message-ID: <20260928200934.1040189-1-pc@manguebit.org> (raw)

This series fixes a number of data corruption and spurious I/O error
bugs found by running generic/363 (fsx) in a loop against Windows
Server 2022 and Samba 4.24 servers.

* Post-EOF pagecache poisoning on extend (1-5)

  Data dirtied past EOF through an mmapped region was never discarded,
  so it reappeared as file content once the file was extended by an
  ordinary write, a truncate, a zero range, a copy range or a clone
  range.  pagecache_isize_extended() doesn't help here: it's a no-op on
  cifs because i_blkbits is 14.  Only the one folio straddling the old
  EOF can hold such data, since pages wholly beyond EOF can't be
  faulted in, so each extending path now zeroes or discards that folio.

* Missing flush or drain before trusting server or pagecache state (6-9)

  FSCTL_QUERY_ALLOCATED_RANGES can report just-written data as a hole
  unless it has been committed to disk first, and the O_TRUNC open,
  interior zero range and server-side copy/clone paths did not flush
  dirty data or drain in-flight I/O before an operation that assumes
  the pagecache and the server agree on the file's contents.

* fallocate refused without a read lease (10, 12)

  smb3_zero_range() and smb3_simple_falloc() returned -EOPNOTSUPP for
  any size-extending request whenever the inode wasn't read caching,
  since the cached i_size couldn't be trusted.  Query the server's EOF
  in that case instead of refusing the request outright.

* Short reads leaving stale data behind (11, 13, 14)

  The read-gaps path and the DIO/unbuffered read collector left the
  untransferred tail of a short read untouched, and cifs could not
  tell a genuine EOF from a stale cached remote_i_size after a lease
  downgrade.  A read racing an extending write could come back short
  and, in the read-gaps case, have that stale folio content written
  back to the server.

* Unstable pages during a signed write (15)

  cifs signs the pagecache folios in place before handing them to the
  socket.  A buffered write could modify a folio while a write
  subrequest built from it was still in flight, so the signature no
  longer matched the data that followed it; the server answered
  STATUS_ACCESS_DENIED, which surfaced later as -EIO.

Paulo Alcantara (15):
  netfs: clear post-EOF pagecache when extending a file via write
  smb: client: clear post-EOF pagecache when extending a file via
    truncate
  smb: client: discard post-EOF pagecache when extending a file via zero
    range
  smb: client: discard post-EOF pagecache when extending a file via copy
    range
  smb: client: discard post-EOF pagecache when extending a file via
    clone range
  smb: client: flush and commit data before querying allocated ranges
  smb: client: drain outstanding I/O before truncating on O_TRUNC open
  smb: client: flush dirty data before zeroing a range
  smb: client: drain and invalidate before server-side copy/clone
  smb: client: only require read lease for size-extending zero range
  netfs: zero gaps in read-gaps folio to avoid writing back stale data
  smb: client: only require read lease for size-extending preallocate
  netfs: zero the tail of a short DIO/unbuffered read
  smb: client: distinguish real EOF from a stale remote_i_size on read
  smb: client: require stable pages for signed connections

 Documentation/filesystems/netfs_library.rst | 25 ++++++
 fs/netfs/buffered_read.c                    |  7 ++
 fs/netfs/buffered_write.c                   |  9 ++
 fs/netfs/direct_write.c                     |  9 ++
 fs/netfs/misc.c                             | 71 +++++++++++++++
 fs/netfs/read_collect.c                     | 24 +++++
 fs/smb/client/cifsfs.c                      | 25 +++++-
 fs/smb/client/file.c                        |  2 +
 fs/smb/client/inode.c                       | 19 ++--
 fs/smb/client/smb2ops.c                     | 97 ++++++++++++++++-----
 fs/smb/client/smb2pdu.c                     | 10 ++-
 include/linux/netfs.h                       |  2 +
 12 files changed, 267 insertions(+), 33 deletions(-)

-- 
2.55.0


             reply	other threads:[~2026-09-28 20:09 UTC|newest]

Thread overview: 17+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-28 20:09 Paulo Alcantara [this message]
2026-09-28 20:09 ` [PATCH 01/15] netfs: clear post-EOF pagecache when extending a file via write Paulo Alcantara
2026-09-28 20:09 ` [PATCH 02/15] smb: client: clear post-EOF pagecache when extending a file via truncate Paulo Alcantara
2026-09-28 20:09 ` [PATCH 03/15] smb: client: discard post-EOF pagecache when extending a file via zero range Paulo Alcantara
2026-09-28 20:09 ` [PATCH 04/15] smb: client: discard post-EOF pagecache when extending a file via copy range Paulo Alcantara
2026-09-28 20:09 ` [PATCH 05/15] smb: client: discard post-EOF pagecache when extending a file via clone range Paulo Alcantara
2026-09-28 20:09 ` [PATCH 06/15] smb: client: flush and commit data before querying allocated ranges Paulo Alcantara
2026-09-28 20:09 ` [PATCH 07/15] smb: client: drain outstanding I/O before truncating on O_TRUNC open Paulo Alcantara
2026-09-28 20:09 ` [PATCH 08/15] smb: client: flush dirty data before zeroing a range Paulo Alcantara
2026-09-28 20:09 ` [PATCH 09/15] smb: client: drain and invalidate before server-side copy/clone Paulo Alcantara
2026-09-28 20:09 ` [PATCH 10/15] smb: client: only require read lease for size-extending zero range Paulo Alcantara
2026-09-28 20:09 ` [PATCH 11/15] netfs: zero gaps in read-gaps folio to avoid writing back stale data Paulo Alcantara
2026-09-28 20:09 ` [PATCH 12/15] smb: client: only require read lease for size-extending preallocate Paulo Alcantara
2026-09-28 20:09 ` [PATCH 13/15] netfs: zero the tail of a short DIO/unbuffered read Paulo Alcantara
2026-09-28 20:09 ` [PATCH 14/15] smb: client: distinguish real EOF from a stale remote_i_size on read Paulo Alcantara
2026-09-28 20:09 ` [PATCH 15/15] smb: client: require stable pages for signed connections Paulo Alcantara
2026-09-29  1:44 ` [PATCH 00/15] netfs, cifs: data corruption fixes Namjae Jeon

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260928200934.1040189-1-pc@manguebit.org \
    --to=pc@manguebit.org \
    --cc=bharathsm@microsoft.com \
    --cc=brauner@kernel.org \
    --cc=dhowells@redhat.com \
    --cc=linkinjeon@kernel.org \
    --cc=linux-cifs@vger.kernel.org \
    --cc=netfs@lists.linux.dev \
    --cc=ronniesahlberg@gmail.com \
    --cc=sprasad@microsoft.com \
    --cc=tom@talpey.com \
    --cc=willy@infradead.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox