fs/ntfs/attrib.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-)
ntfs_dio_zero_range() returns either 0 or a negative errno from
blkdev_issue_zeroout(); it never returns a positive value. The
zeroing failure check in ntfs_attr_fallocate() therefore never fired,
so a failed zeroing operation was silently ignored: the loop kept
going, the newly allocated clusters were folded into initialized_size
and the write could succeed leaving stale on-disk data.
Treat any nonzero return as an error and abort the allocation.
Fixes: 495e90fa33482 ("ntfs: update attrib operations")
Assisted-by: atomcode:deepseek-v4-flash
Signed-off-by: Wentao Guan <guanwentao@uniontech.com>
---
fs/ntfs/attrib.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/fs/ntfs/attrib.c b/fs/ntfs/attrib.c
index 58f32aac5f614..b50413a5d982f 100644
--- a/fs/ntfs/attrib.c
+++ b/fs/ntfs/attrib.c
@@ -5666,7 +5666,7 @@ int ntfs_attr_fallocate(struct ntfs_inode *ni, loff_t start, loff_t byte_len, bo
lcn << vol->cluster_size_bits,
alloc_cnt <<
vol->cluster_size_bits);
- if (err > 0)
+ if (err)
goto out;
}
--
2.30.2
On Tue, Aug 25, 2026 at 2:47 PM Wentao Guan <guanwentao@uniontech.com> wrote:
>
> ntfs_dio_zero_range() returns either 0 or a negative errno from
> blkdev_issue_zeroout(); it never returns a positive value. The
> zeroing failure check in ntfs_attr_fallocate() therefore never fired,
> so a failed zeroing operation was silently ignored: the loop kept
> going, the newly allocated clusters were folded into initialized_size
> and the write could succeed leaving stale on-disk data.
>
> Treat any nonzero return as an error and abort the allocation.
>
> Fixes: 495e90fa33482 ("ntfs: update attrib operations")
> Assisted-by: atomcode:deepseek-v4-flash
> Signed-off-by: Wentao Guan <guanwentao@uniontech.com>
Applied it to #ntfs-next.
Thanks!
NOTE this here need also rollback the clusters that were installed in, and taken from the volume bitmap for the failed hole: leaving them mapped would let a later read reach unzeroed clusters and expose stale on-disk data even though fallocate() failed. Punch the allocation back out of the runlist and free the clusters before returning. But I don`t know how to easily imply them, anyone has idea please let me know. BRs Wentao Guan
© 2016 - 2026 Red Hat, Inc.