From: Slawomir Stepien <sst@poczta.fm>
To: syzbot <syzbot@kernel.org>
Cc: syzkaller-upstream-moderation@googlegroups.com, syzbot@lists.linux.dev
Subject: Re: [PATCH RFC] fs/ntfs3: handle partial allocation in attr_data_get_block_locked()
Date: Wed, 15 Jul 2026 14:24:55 +0200 [thread overview]
Message-ID: <ald8F82-k3GK79RB@nr200> (raw)
In-Reply-To: <69fc5364-da7a-4a91-bdff-078af00db6f6@mail.kernel.org>
#syz upstream
On lip 09, 2026 12:07, 'syzbot' via syzkaller-upstream-moderation wrote:
> When allocating clusters for a sparse or compressed attribute in
> attr_data_get_block_locked(), the requested virtual cluster number (vcn0)
> is aligned down to a frame boundary (vcn). The function then attempts to
> allocate a full frame of clusters.
>
> If the disk is nearly full and highly fragmented, attr_allocate_clusters()
> might only manage to allocate a small fragment and return success with a
> partial allocation length. If this partial allocation is so small that it
> does not even reach the originally requested vcn0 (i.e., end <= vcn0), vcn0
> remains unallocated (a sparse hole).
>
> When the code subsequently calls run_lookup_entry() for vcn0, it finds the
> original SPARSE_LCN entry, which triggers a WARN_ON(1).
>
> Fix this by adding a check to verify if the partial allocation reached
> vcn0. If it did not (vcn0 >= end), treat this as an -ENOSPC failure and
> jump to the undo1 label. This safely rolls back the partial allocation,
> restores the original size, and repacks the runs, leaving the inode in a
> consistent state before returning the error to the caller.
>
> WARNING: fs/ntfs3/attrib.c:1236 at attr_data_get_block_locked+0x1980/0x25d0
> fs/ntfs3/attrib.c:1236
> RIP: 0010:attr_data_get_block_locked+0x1980/0x25d0 fs/ntfs3/attrib.c:1236
> Call Trace:
> <TASK>
> attr_data_get_block+0x1f1/0x2a0 fs/ntfs3/attrib.c:979
> ntfs_fallocate+0xd3d/0xf70 fs/ntfs3/file.c:670
> vfs_fallocate+0x663/0x7f0 fs/open.c:338
> ksys_fallocate fs/open.c:362 [inline]
> __do_sys_fallocate fs/open.c:367 [inline]
> __se_sys_fallocate fs/open.c:365 [inline]
> __x64_sys_fallocate+0xbf/0x110 fs/open.c:365
> do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]
> do_syscall_64+0x174/0x580 arch/x86/entry/syscall_64.c:94
> entry_SYSCALL_64_after_hwframe+0x77/0x7f
> </TASK>
>
> Fixes: 099ef9ab9203 ("fs/ntfs3: implement iomap-based file operations")
> Assisted-by: Gemini:gemini-3.1-pro-preview Gemini:gemini-3-flash-preview syzbot
> Reported-by: syzbot+7be6ad5cb228286af3e3@syzkaller.appspotmail.com
> Closes: https://syzkaller.appspot.com/bug?extid=7be6ad5cb228286af3e3
> Link: https://syzkaller.appspot.com/ai_job?id=3c9dee6e-001d-4972-8bf6-f6c960708246
> To: "Konstantin Komarov" <almaz.alexandrovich@paragon-software.com>
> To: <ntfs3@lists.linux.dev>
> Cc: <linux-kernel@vger.kernel.org>
>
> ---
> diff --git a/fs/ntfs3/attrib.c b/fs/ntfs3/attrib.c
> index c621a4c58..786fd0ec0 100644
> --- a/fs/ntfs3/attrib.c
> +++ b/fs/ntfs3/attrib.c
> @@ -1227,6 +1227,10 @@ int attr_data_get_block_locked(struct ntfs_inode *ni, CLST vcn, CLST clen,
> total_size = total_size0 + ((u64)*len << cluster_bits);
>
> if (vcn != vcn0) {
> + if (vcn0 >= end) {
> + err = -ENOSPC;
> + goto undo1;
> + }
> if (!run_lookup_entry(run, vcn0, lcn, len, NULL)) {
> err = -EINVAL;
> goto out;
>
>
> base-commit: 8cdeaa50eae8dad34885515f62559ee83e7e8dda
--
Slawomir Stepien
prev parent reply other threads:[~2026-07-15 12:25 UTC|newest]
Thread overview: 2+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-07-09 12:07 [PATCH RFC] fs/ntfs3: handle partial allocation in attr_data_get_block_locked() syzbot
2026-07-15 12:24 ` Slawomir Stepien [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=ald8F82-k3GK79RB@nr200 \
--to=sst@poczta.fm \
--cc=syzbot@kernel.org \
--cc=syzbot@lists.linux.dev \
--cc=syzkaller-upstream-moderation@googlegroups.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox