From nobody Thu Sep 24 12:05:50 2026 Received: from mail-wr2-f12.google.com (mail-wr2-f12.google.com [74.125.225.76]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 60D7E4477F1 for ; Thu, 24 Sep 2026 09:12:57 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=74.125.225.76 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790241179; cv=none; b=EJIOkTqcL8Obyp9RQwfcyUuRH4+rtCtynN2rv6seqovqy/+lHbSxjOk8KNpZyrpckV+Ot2LmbzaYzJoPAQFC4142wep6yjfaKKU9n7Yc1R1Lce+tjN4tT1xnhu5yzL6nN/RYubuOAdURqdWj5WB0iSp4FmCNlpJ/y7pqUKmjbD4= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790241179; c=relaxed/simple; bh=gbD38OZ+K8pV/KQl4DgCWHt3UcaEpwGclj1C9Ynx0P8=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=lL6dGPALJD6f4y1FGVwcELjzl+3evfj3xbMlfYEkQy9TiO+eeSo09dd2nqVMlOBaxsR2ttQ7A2DKQr34IALgTYfbv4U5fXVb5GAT3oTdlTftBtAnBNgRDpJ/D2Uu1agpejN0bTULVulzGL1CLdkiAElSTpRlV5MSNOzASWPv+es= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=FgWIybPP; arc=none smtp.client-ip=74.125.225.76 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="FgWIybPP" Received: by mail-wr2-f12.google.com with SMTP id ffacd0b85a97d-482f6356f6bso1496426f8f.2 for ; Thu, 24 Sep 2026 02:12:57 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1790241175; x=1790845975; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=0T6gy4Aw3WfHFoNTCiQ4B3uP/bh3QfbEnAm8LgQjvIs=; b=FgWIybPPwptnGoIMYOj7kdxjQrBorZKG+GaAjJrLTGeUftBhTV3d+SI23asRa+NFwg I3jExrtk+cXsFIDIuHWylnuAaVx78XEHGz5AAa/WuIkT+MBlb91KRUWOVddZCUv38i98 G+uDfnn2hMgcK82bdMJCaDmOtlUfVzC8oFZy2dD2AxW5953XUe0XdyS+qwH+DmSCkwJ3 dRG1GtI7UfF2x8BHqCinLwDhj8z/bPOuPEKXQ426y9I96ucVMvmz8ikXDu4nDt5ri/MA XY1DZcBhfJh3lw3UF2Nlo1OuFrNLJEzor1KBncDMWjEGpToTNgCZx0A8vauo8UJ3y1cL HY6Q== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790241175; x=1790845975; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=0T6gy4Aw3WfHFoNTCiQ4B3uP/bh3QfbEnAm8LgQjvIs=; b=FHohpgYmImIniWN0N+IVKMq3g6Y9uQEVm+4cqbPesIrYzzgr1gAn/gaTIWcg0B2hk9 Ds1+gE5lWgfdSLGWCpXFHZ+5PpkJl+e3VJv1RdepZ9j+sAeo6jKcvpqYu4S+KoAvkW+k mMH215VAbVjyUb7jMjCx0xvoxTYWjV4Wuza5TU4WPiAGN7YbSHLeJVzENcsx7ORBAXGs 9o19TUUfsJURu1bY6XQUcL/LhRsYbg5o5P8sPZ3l6P1VQKs8duvnm8o8/xERPi3rZMli o25rtfICVmAYi7zMvLf2dQDd6FwhxTG0+AcoXVH5pbgZ8abOmT8hmSCEblemCOPROKtH GYvQ== X-Forwarded-Encrypted: i=1; AKwUvBwQoA00krxkJ1VY3+XWi/kfWn6RW2JxQlKYkBU/iVTVCh1Pyq2duzsv9CjkhWy3BPPLD1XFdpoGJxNVy18=@vger.kernel.org X-Gm-Message-State: AFuF++lVZeAhMCa17Qn7dhx4PxNxpDpBCIpIfG9qYckArJhV3Co/GamL N0FYarweD/ujXzvh+ilo9RhXrpKeOKOHGAci3a0YS7tmmNIrYrIr/tSe X-Gm-Gg: AYBFou2q0dIQYvEJ1YZj6XBlCTcZYO3FwkomPcK4hmoZv0dHq5xevMm5LR3j+zVlNXp pz46iTOcfEVxV60OepQ4tB1vIxvZjYkkzx5N7OxTRngz6jJkhrLbyWOSTfxU6A14N0xec/uu2jS dcDM3X3OemfY2C/gvLn1C63mtqcQe5glJRSH/VC3qQkAphjwBHoQXuTqdfTZwHXpxQ2WzO1otq4 wlkEiJe4FZ89Q6evcyiUAV+by8i/GzrFwkUKxB31tbsbc122w6+jwquOSg+fMlEd0kbc2Mw5bQS tAa63rn+VuLXHk/jDxknbwI0jRiSCToRq+oG3Fs5ChKPJgcEb2iax+EJm7q6j1XS/h2Oq3klwM/ gDoi6oNPpZMY6a05ePyONDU9Msx5qMBSDtJdh55EN5rK7AMCAUsi5y5kCWolDMh/TF6ZLcdjJ48 5ulo7FJqKPWuMCTOrc4XsB4xfiXDjEUUqwFuXRi+HkqLh+imeYaWJ/6MUHM2bLtrhSFougwTY/b sOaIC/PqHNplhfBlmT+BD5HgX2znnqKYgDMW6mt5xgxH4mWHWC7B8cJnNoDmca7wdx2dxNwcmGB lS6B X-Received: by 2002:a05:6000:604:b0:487:d60:aa69 with SMTP id ffacd0b85a97d-488716b74a7mr3595554f8f.7.1790241175505; Thu, 24 Sep 2026 02:12:55 -0700 (PDT) Received: from andreayoga.localdomain (93-42-14-189.ip84.fastwebnet.it. [93.42.14.189]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-4886848636asm12756677f8f.6.2026.09.24.02.12.53 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 24 Sep 2026 02:12:55 -0700 (PDT) From: Andrea Parri To: Christian Brauner , Carlos Maiolino , "Darrick J . Wong" , Joanne Koong , Brian Foster , Christoph Hellwig , Damien Le Moal , Hannes Reinecke , Daniel Gomez , Pankaj Raghav , Dave Chinner Cc: Andrea Parri , linux-xfs@vger.kernel.org, linux-fsdevel@vger.kernel.org, linux-kernel@vger.kernel.org, stable@vger.kernel.org Subject: [PATCH v2 1/4] iomap: don't resubmit an ioend after ->writeback_submit() failed Date: Thu, 24 Sep 2026 11:11:51 +0200 Message-ID: <20260924091203.198225-2-parri.andrea@gmail.com> X-Mailer: git-send-email 2.53.0 In-Reply-To: <20260924091203.198225-1-parri.andrea@gmail.com> References: <20260924091203.198225-1-parri.andrea@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" iomap_add_to_ioend() submits the pending ioend through ->writeback_submit() before allocating a new one for the current range. When the submission fails the helper completes the ioend with an error, but iomap_add_to_ioend() returns the error without clearing wpc->wb_ctx. iomap_writepages() then submits whatever wpc->wb_ctx points to, so the already completed ioend is submitted a second time. For XFS the second bio_endio() lands in xfs_end_bio(), which list_add_tail()s the already linked ioend into ip->i_ioend_list. This corrupts the list and leaves a use-after-free/double-free window against the ioend completion worker. Reproduced with a fault-injected ->writeback_submit() failure on a reflinked XFS file with several CoW writeback ranges in flight: the unfixed kernel hits repeated "list_add double add" warnings from __list_add_valid_or_report(), the fixed kernel fails writeback cleanly. Clear wpc->wb_ctx when ->writeback_submit() fails. The old iomap_submit_ioend() cleared the context unconditionally; that clear was lost when submission moved to iomap_ioend_writeback_submit(). The final ->writeback_submit() call in iomap_writepages() needs no equivalent fix: it is the last thing the function does before returning, and every caller allocates its iomap_writepage_ctx on the stack for a single call, so wpc->wb_ctx is never read again afterwards. Fixes: f4fa7981fa26 ("iomap: hide ioends from the generic writeback code") Cc: # v6.17 Reviewed-by: Brian Foster Assisted-by: LLM Signed-off-by: Andrea Parri --- fs/iomap/ioend.c | 10 +++++++++- 1 file changed, 9 insertions(+), 1 deletion(-) diff --git a/fs/iomap/ioend.c b/fs/iomap/ioend.c index 7bbbb417f9152..32ae292a84cbe 100644 --- a/fs/iomap/ioend.c +++ b/fs/iomap/ioend.c @@ -246,8 +246,16 @@ ssize_t iomap_add_to_ioend(struct iomap_writepage_ctx = *wpc, struct folio *folio, new_ioend: if (ioend) { error =3D wpc->ops->writeback_submit(wpc, 0); - if (error) + if (error) { + /* + * ->writeback_submit() completed the ioend + * with an error, so drop the stale context; + * iomap_writepages() would otherwise submit + * it a second time. + */ + wpc->wb_ctx =3D NULL; return error; + } } wpc->wb_ctx =3D ioend =3D iomap_alloc_ioend(wpc, pos, ioend_flags); } --=20 2.53.0 From nobody Thu Sep 24 12:05:50 2026 Received: from mail-wr2-f38.google.com (mail-wr2-f38.google.com [74.125.225.102]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 03CC14432FF for ; Thu, 24 Sep 2026 09:12:59 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=74.125.225.102 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790241183; cv=none; b=WHU85qm6orpEKN+4JgVhkGvlxuOIa5rEdriCqXQWjEozpvbBNP/KvDlR0hpOoxljqIp3moFZf+Hr3ALCCTIqVamVFlv6SJpB6Btc6tcqrvTUYwMHRMAlfvGVhzdug4JVJ3UaSJT9KRCVmF0brc7y3BqsXV3u5WYg+4ok5EdGiPk= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790241183; c=relaxed/simple; bh=+hOZACThI9fTymMJZFcS53sfhvVmabkJCCIZDLXeVX8=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=eo3Kuy0ydR7LLHuxU1AMAe5qMQc39n1zhXiEP+VPfE2X1Top6L0T3cPn3pbR6DFeqn2bTjeOMsOc6e51Dh0sZ6hcpEjBfogfDR+YDNqDbGioiZlJl9Ux3oed+Hy3yPmCtuYXDUufqZvSr/vXPdKVPXTs6QT/ikIaX5x/v9ENQsA= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=MRTt7MeS; arc=none smtp.client-ip=74.125.225.102 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="MRTt7MeS" Received: by mail-wr2-f38.google.com with SMTP id ffacd0b85a97d-482f6350f89so1275855f8f.3 for ; Thu, 24 Sep 2026 02:12:59 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1790241178; x=1790845978; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=ULqy3851A4B8rk2HooNfYhmLdLyD4QbbwevT0D7ixEg=; b=MRTt7MeSaAaW6U7mujoM4gBZPX69ndIkCJOjsuWSbBg7SgTg5l2pQX4NLTvN18UNGV YGoc2YBLkUcf5uvxwxcsBGtNj6N2RRDX0wfX39pjf8UfeA+2j4KGNagUHCgQ0+EvPKbE xI+AkjHC4IyQl+HylGQJqK1Z/boQPiYM/9h/cqSnLNcAtSJ2198fVQE8ekSjucUvw0pb RiFUTO7cXLH/yTwlrOzVP8TYwIvHjQUbhntQz1Snd+bJUy01DRRh/qPxXOVaGuzDFR/a ELKoFmdAYHUGrEARMOIiUfViIrPUiy5IcsTPixoIv9WbqGOb/3e/o+vRhAaHHxDH0I1X hlhw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790241178; x=1790845978; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=ULqy3851A4B8rk2HooNfYhmLdLyD4QbbwevT0D7ixEg=; b=tuoVvtlpzzYL0Obc49qFRZnot04LAYJkhq/3SRzlILJBEAblEFK8gjwnBMABAYzAcn hF7G5f/EZVqe0iddRgUxW7A8c1u4RLygIY9OliSdCR/sVEGCtafPS+0cee+Ie3J53kTL V+5Q0DSOuha972tKK78XKMss//V6MxJPbDsa957GFZjHvNlGiXUS85gRRVe/VfpZrVrD Utnc4stmYu/gsY2H9T4dEXJ8MV5/gxCyZw+CIJDigRKwVnxOrHuavAVYe0JWJ564vSVg nkIyPzFuvy0aabTHry4cWpivZlQvRxLY5wlJl78u15B3/5hFjzrXuZNdb8efsVKw3g3W EwrQ== X-Forwarded-Encrypted: i=1; AKwUvBzosEz9y3Lrqi+Cp6B0eaBE1VMQwS7yu/SNPWKRofpRSPTdfpgZXjet1mggcrPYIkYXUNeZwuXgfHPq5Rs=@vger.kernel.org X-Gm-Message-State: AFuF++l7wGoB9wCr0f9U/WIWdigBXmA3vOjPRKc2Ptfnrjn78NNrC3Oz zTSo1D63B1mHHoLwIQPAkLcuziDrhtNVpzbmOTdRMqKXEsMmVp/uDHUx X-Gm-Gg: AYBFou1NvsfF2O6yh/U/z+4mXaI9A4JJ2HGXYpU/4ae6HaYnk+9DuLKzrg+oRpueX4x 3a/4BmHGNKDiqfSevTMvqyR6eVHrUcuVDN3/G1r8Dcezn/4fhzWKiXevzLlb811MSCCwI4/SDrx tNOjhuSiXfGwOsjOjaBaltKfJmZ5Ua5O7NLutDc9hJeGLR4eu4RSAhKBRu7n1g2FchzzxU1PV/w 6egh4rbBb70By1eSPp9JOBKhZbS/Ur+x3Ct+uHNhZqBSVFM415KBB4H7sPZdb72mibCa/WkvgUI FyCHPl4FmLVS+d0P/uQ8j7y1qUbvWOyKUbCj47FKcvU8GrPqcWeAAoZElQV3ehmAtKoEsCekhno +yUGbo4aY3SHeqMkUezvSbyAAWPZQuEYOuTUAkZUjoG8u57QhC7ubA5QgVYcxcHazOEEExsPSjr /O0G/NGUKvEmO72NXvUpyMyamEUpkZIAmeBbku8A6dXFhAXLgspgxV6SXJdjuyPyJ0XIzkpsMTp TC6q2RvZVHQh8g6OWz4u9y03s7TSCpCeircOoeV4ESUps4jll9q8mcXtb3dkgwf7sIucqihjb72 19kX X-Received: by 2002:a05:6000:4012:b0:487:40d:af33 with SMTP id ffacd0b85a97d-4887171633bmr3055061f8f.13.1790241178110; Thu, 24 Sep 2026 02:12:58 -0700 (PDT) Received: from andreayoga.localdomain (93-42-14-189.ip84.fastwebnet.it. [93.42.14.189]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-4886848636asm12756677f8f.6.2026.09.24.02.12.56 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 24 Sep 2026 02:12:57 -0700 (PDT) From: Andrea Parri To: Christian Brauner , Carlos Maiolino , "Darrick J . Wong" , Joanne Koong , Brian Foster , Christoph Hellwig , Damien Le Moal , Hannes Reinecke , Daniel Gomez , Pankaj Raghav , Dave Chinner Cc: Andrea Parri , linux-xfs@vger.kernel.org, linux-fsdevel@vger.kernel.org, linux-kernel@vger.kernel.org Subject: [PATCH v2 2/4] xfs: add an error tag to inject a ->writeback_submit() failure Date: Thu, 24 Sep 2026 11:11:52 +0200 Message-ID: <20260924091203.198225-3-parri.andrea@gmail.com> X-Mailer: git-send-email 2.53.0 In-Reply-To: <20260924091203.198225-1-parri.andrea@gmail.com> References: <20260924091203.198225-1-parri.andrea@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" The only in-tree way for xfs_writeback_submit() to fail is a failing xfs_reflink_convert_cow(), which requires a shared (reflinked) CoW extent. There was previously no way to exercise that failure path from userspace, which made it hard to write an xfstest for it, e.g. for "iomap: don't resubmit an ioend after ->writeback_submit() failed". Add XFS_ERRTAG_WB_COW_CONVERT_ERROR to force xfs_reflink_convert_cow() to fail with -EIO, so that ->writeback_submit() failure and its callers' error handling can be exercised with error injection alone, without needing a corrupted or racy COW fork. Suggested-by: Christoph Hellwig Assisted-by: LLM Signed-off-by: Andrea Parri --- fs/xfs/libxfs/xfs_errortag.h | 6 ++++-- fs/xfs/xfs_reflink.c | 5 +++++ 2 files changed, 9 insertions(+), 2 deletions(-) diff --git a/fs/xfs/libxfs/xfs_errortag.h b/fs/xfs/libxfs/xfs_errortag.h index 6de207fed2d89..e6b0864051b0a 100644 --- a/fs/xfs/libxfs/xfs_errortag.h +++ b/fs/xfs/libxfs/xfs_errortag.h @@ -75,7 +75,8 @@ #define XFS_ERRTAG_METAFILE_RESV_CRITICAL 45 #define XFS_ERRTAG_FORCE_ZERO_RANGE 46 #define XFS_ERRTAG_ZONE_RESET 47 -#define XFS_ERRTAG_MAX 48 +#define XFS_ERRTAG_WB_COW_CONVERT_ERROR 48 +#define XFS_ERRTAG_MAX 49 =20 /* * Random factors for above tags, 1 means always, 2 means 1/2 time, etc. @@ -137,7 +138,8 @@ XFS_ERRTAG(WRITE_DELAY_MS, write_delay_ms, 3000) \ XFS_ERRTAG(EXCHMAPS_FINISH_ONE, exchmaps_finish_one, 1) \ XFS_ERRTAG(METAFILE_RESV_CRITICAL, metafile_resv_crit, 4) \ XFS_ERRTAG(FORCE_ZERO_RANGE, force_zero_range, 4) \ -XFS_ERRTAG(ZONE_RESET, zone_reset, 1) +XFS_ERRTAG(ZONE_RESET, zone_reset, 1) \ +XFS_ERRTAG(WB_COW_CONVERT_ERROR, wb_cow_convert_error, 1) #endif /* XFS_ERRTAG */ =20 #endif /* __XFS_ERRORTAG_H_ */ diff --git a/fs/xfs/xfs_reflink.c b/fs/xfs/xfs_reflink.c index 4801361366359..104542b10d9e0 100644 --- a/fs/xfs/xfs_reflink.c +++ b/fs/xfs/xfs_reflink.c @@ -34,6 +34,8 @@ #include "xfs_rtalloc.h" #include "xfs_rtgroup.h" #include "xfs_metafile.h" +#include "xfs_errortag.h" +#include "xfs_error.h" =20 /* * Copy on Write of Shared Blocks @@ -346,6 +348,9 @@ xfs_reflink_convert_cow( =20 ASSERT(count !=3D 0); =20 + if (XFS_TEST_ERROR(mp, XFS_ERRTAG_WB_COW_CONVERT_ERROR)) + return -EIO; + xfs_ilock(ip, XFS_ILOCK_EXCL); error =3D xfs_reflink_convert_cow_locked(ip, offset_fsb, count_fsb); xfs_iunlock(ip, XFS_ILOCK_EXCL); --=20 2.53.0 From nobody Thu Sep 24 12:05:51 2026 Received: from mail-wr2-f12.google.com (mail-wr2-f12.google.com [74.125.225.76]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id D2AF544998D for ; Thu, 24 Sep 2026 09:13:02 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=74.125.225.76 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790241184; cv=none; b=BGt3VQXJlUmFWtz094GgMQA/gL80uwaomG9Xg+IRmTsF0CgQbW46KSDMI4O+uofNxBPoc0OmaIi6CjZngJzAQFP/1DfCpOO4wufIDqG3byNeOKQKAwaJfd1md/IqJYwJY+LjLdlYiNJJ+h9XFizjlES6U3n7V8MM23VqY5aRL1g= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790241184; c=relaxed/simple; bh=RYRoyEZy3AZX96/W22uGNOvKvksOSwlIn7uO1WdQA74=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=CON2SBnxTbbA9fg/G1w4EjhmXtui/YyVQj76iVoq/Tb+7d251GxbZP/CxpKH1pWRl71d6zwj0aYqtyP+IEdRP1mbT0BmVEi55FfGHS7u3Svzn4ZgL++m7/YlFrFfop3MLakm0aDmoIAqpQCCc7Pi5liHDC+rVpMpgrUyKd/BxMg= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=mWJgp0cD; arc=none smtp.client-ip=74.125.225.76 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="mWJgp0cD" Received: by mail-wr2-f12.google.com with SMTP id ffacd0b85a97d-48449f62b93so734088f8f.0 for ; Thu, 24 Sep 2026 02:13:02 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1790241181; x=1790845981; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=3/GiZQj0CaseyrQZxOd/ioPb55nZ1v2BOlX+DpEu3BI=; b=mWJgp0cD0DM87D2738zgSOVYuR5hlg//Uu1mCt4DFc1sNCWyFPabhj8TSsKKcg+9f1 Cn6RagoOVukVH8bJwQHzu3Zb7vpj4zNXSxWlcP5xUh+B7F+bQdvVi4c3CJ7LAlTIRcch vhpAEH9DvQETawOVRa0mhXxkAPUjQqR8s57Ix3z+Y/zp29yX6rm+4yod+sHu5k9l1AKE etGCuatNuKciF/FjDiLvPczKZ+Q9MI0M6+AhUdAYn9AVMTWqi1rjEYZs4KhO5JY1weKi AI1AapihHnre2QpaWYSd6n5ihPyGGlrt1sRR42XZSEbjFWZmOGyFRuUVqMpAXInq+9Td +wXg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790241181; x=1790845981; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=3/GiZQj0CaseyrQZxOd/ioPb55nZ1v2BOlX+DpEu3BI=; b=NVwrSUI60MuskhCo6SoToee2C8vX0MCOjk9y+D3IOXOYrDCECtpVVydm3kWFGYBCU3 /VNHpSY4AwLQropZ8vbe+ngob/O8eaK06BL2b70y4teU6PhmMAqT/+6VWNei7F4M3R9E SU8dIC/wX8uDZGfAjMml8vVenEvUG/lO8NKepFTev787xDCtbNMhEgpoNtm1VkF5OaBB jGFJgYV8tUEBDIoMplZMIOWPrEt1Cu62NICjQfPJkMxBiY6+mKE5rj3xNQy07nC+eTay 4uSv0gYralpAZkqLJT2dL8LUdxD8LglDcvJJ0tU/VqT+Cd80UrD0QVIHYp61gE67E4M/ 9g2g== X-Forwarded-Encrypted: i=1; AKwUvBzNDa7jiCk7pciALvqQAf1c2eMQ3QA3S+BNT0Trn+iTVWRrN/AA3Bi66Czx7lwghR00RzuiX8UNgfGcIeI=@vger.kernel.org X-Gm-Message-State: AFuF++k8XT8nIvYBy18sgx4iKyVOP0RiIkuFVzmPxPtOh7Djmnb8WJnO 1wIuiYZzKHXF0sWF/sCLWw0ESelNDt+qPuWSZQoa5Pi40vIvXpuP/K1zCverf5W30Pk= X-Gm-Gg: AYBFou1sgyE84Ws/UYTMt0c1r8pPNJkNP8rBNCTLMk16QBQDS97CnCFpIOp84kXwHgT SOpnkgVMRGNjR1fNE+AqTHOrTXX2dJkc6W4fCeWeS3pYJe5G8UCbuf/dwCg9WoK5C9drtG6pNFL +Vv5QinHFUxLLEyVOkCVj3M/GJuWdkK3LNg2l29OG381a1uUBWON29gqqMVDP3Sb4SBtPHsEhyN IgLDqZjzC05o4cXU/6WSYJ9oHyiMIl/oOSyV67gn1eiQ9+ePDV9ml/HoDzFeOkLSL95rj2yu5pD ed1VcQ2qVuZvAhPBPWHRjrw9yxQJLIXL+xQQp5YsuVFB9M2UG/09o3+VBIOGwRY5j+hkHuAJyVy oPw9vXDDcixLvCTxQg639LDPFUUi1ddYHQXIt73r3MAbP2LTuSN4JjL6kJwV0ShvyJMalwKeyqM 0DM0o3ui2zM67OslIov3QGIhwIkKZ04ZAYM5/vt/J5fVFZLZMVDK8yJuk26oyTXRFfeEIeMHNie n+ub4wfr5vzY+MbAG4knfDpoxQrFq4PXJY9N/FvWZ/oFKk8UahvIAqEvavGmAlObsg3gna9A/wD wmHT X-Received: by 2002:a05:6000:41f5:b0:47f:9158:5924 with SMTP id ffacd0b85a97d-4887169cfd7mr3162682f8f.9.1790241180882; Thu, 24 Sep 2026 02:13:00 -0700 (PDT) Received: from andreayoga.localdomain (93-42-14-189.ip84.fastwebnet.it. [93.42.14.189]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-4886848636asm12756677f8f.6.2026.09.24.02.12.59 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 24 Sep 2026 02:13:00 -0700 (PDT) From: Andrea Parri To: Christian Brauner , Carlos Maiolino , "Darrick J . Wong" , Joanne Koong , Brian Foster , Christoph Hellwig , Damien Le Moal , Hannes Reinecke , Daniel Gomez , Pankaj Raghav , Dave Chinner Cc: Andrea Parri , linux-xfs@vger.kernel.org, linux-fsdevel@vger.kernel.org, linux-kernel@vger.kernel.org, stable@vger.kernel.org, Christoph Hellwig Subject: [PATCH v2 3/4] iomap: don't lose a fiemap iteration error when emitting the last extent Date: Thu, 24 Sep 2026 11:11:53 +0200 Message-ID: <20260924091203.198225-4-parri.andrea@gmail.com> X-Mailer: git-send-email 2.53.0 In-Reply-To: <20260924091203.198225-1-parri.andrea@gmail.com> References: <20260924091203.198225-1-parri.andrea@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" iomap_fiemap() emits extents one behind: iomap_fiemap_iter() flushes the previous extent and remembers the current one, and the remembered extent is written with FIEMAP_EXTENT_LAST after the iteration loop. That final flush overwrites ret, so when ->iomap_begin() fails partway through the iteration the error is replaced by the result of iomap_to_fiemap() (zero on success) and iomap_fiemap() returns success with a truncated extent list whose last entry is wrongly marked as the last extent in the file. The pre-iomap_iter code returned the error from inside the loop, before flushing the pending extent. Check for the iteration error before flushing the pending extent, so that real errors are propagated and only a successful iteration emits the final FIEMAP_EXTENT_LAST extent. -ENOENT (no mapping) is still not an error, and the pending extent is still emitted in that case. Fixes: 7892386d3571 ("iomap: switch iomap_fiemap to use iomap_iter") Cc: # v5.15 Reviewed-by: Brian Foster Reviewed-by: Darrick J. Wong Reviewed-by: Christoph Hellwig Assisted-by: LLM Signed-off-by: Andrea Parri --- fs/iomap/fiemap.c | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/fs/iomap/fiemap.c b/fs/iomap/fiemap.c index d11dadff82865..54b824b7edb5c 100644 --- a/fs/iomap/fiemap.c +++ b/fs/iomap/fiemap.c @@ -76,15 +76,15 @@ int iomap_fiemap(struct inode *inode, struct fiemap_ext= ent_info *fi, while ((ret =3D iomap_iter(&iter, ops)) > 0) iter.status =3D iomap_fiemap_iter(&iter, fi, &prev); =20 + /* inode with no (attribute) mapping will give ENOENT */ + if (ret < 0 && ret !=3D -ENOENT) + return ret; + if (prev.type !=3D IOMAP_HOLE) { ret =3D iomap_to_fiemap(fi, &prev, FIEMAP_EXTENT_LAST); if (ret < 0) return ret; } - - /* inode with no (attribute) mapping will give ENOENT */ - if (ret < 0 && ret !=3D -ENOENT) - return ret; return 0; } EXPORT_SYMBOL_GPL(iomap_fiemap); --=20 2.53.0 From nobody Thu Sep 24 12:05:51 2026 Received: from mail-wm2-f13.google.com (mail-wm2-f13.google.com [74.125.225.141]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 401F9449B3B for ; Thu, 24 Sep 2026 09:13:05 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=74.125.225.141 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790241188; cv=none; b=DtJn+wMglpB5/Covw8Wbe7HzTpCADk8z62kC720IqnOcCqeiggz/GbgRsxxwOQaPgCrrClDtml9aYsOLJeysVoPwzvSouKKxoHR2v2o4uAHSIQ/HxmXblhzKnJDUGQR5hXqAREq+F/cwRoFvgByTLcsUw5dOfFdnrJoeE29pqPE= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790241188; c=relaxed/simple; bh=R2v6XIS8rFzH1++61DHzZpR8Odr/UFZzSld3CIqALtM=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=khWDpDK7fewezxicY5XMZAeMeAHsYJpB7zxwQYjaRnijW0Bq0IWoxd8pfNPe5FRxrYZ9K9jnOMz5qfuhAYYOXXGZc9Q/kqMTeAVSVfY+si6XmRSe70Otmkwlz107k4BabSanHz72vMlu//Y3vNxORfao0g9K3fL/zrFUXaik48c= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=UYuIOpz7; arc=none smtp.client-ip=74.125.225.141 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="UYuIOpz7" Received: by mail-wm2-f13.google.com with SMTP id 5b1f17b1804b1-49e620fa473so10890245e9.1 for ; Thu, 24 Sep 2026 02:13:05 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1790241183; x=1790845983; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=Q3UEIk5rnMiFTRGuZ99oPenAjQD9CsZRbMnKE/eY65Q=; b=UYuIOpz7j6vU2ibj8cfoBAxRZK2IAanJQ8c6r++AJPUZ3U7iw2r8DUjdaybDb1sDOb h5Z78rP4R8WHZpcj5Tk+YsSPgnAGdcaPxWrRR97l634lFp2CWvK5w1FP1Q/jmlsj6nYm RADQH+5FgGnJ7fe8L3BigTcEMBSm2tRPJh7gcJH36nvS6t6krVZnE8HPfMI0JCAQKUHT Wkr7fCpJpW9LLeb3xhAnvSDU25WTfACbZGWP4D9cl5yvhsvPxn2KFsVVYh9C35wgWY79 6EPC61Tb4AkETEhvL2No1XWittJnoE5YiSHDI8y9mBOHJrHqEwF41GmQBKWj6/zz/VPX d83Q== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790241183; x=1790845983; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=Q3UEIk5rnMiFTRGuZ99oPenAjQD9CsZRbMnKE/eY65Q=; b=lZmY+0X4el+ZRPEwalDX292UVU2y3kBZ8aYPijFa3OqNoiLboWPJpYiM0mHSapydfk yG31ACQrojtq6vwL59q8522xJ4VZaRig9WfjwKI0S3KX9MwD+64w93AHg5g9gg89Dof8 ZKL6fTbuUU4BqEceEqidZj3Kw6HWVDsYBXksMTn2eMpqnsvuNsGzJkUJitCEEpSQ7hfD 1zyHlVCI03lHEoB2cir3bszn2fPcOb2sAvV26SGjz8c3gW6E4uuXzOG0M1I4Ea5DzZrt PpLSePLFmd45mYihVCJkDkEfWk7lYvckr0eFe9Noimjx21uJYerSnko1m8gWmrWNknAi gjpg== X-Forwarded-Encrypted: i=1; AKwUvBwf2hnuDcyt+kny9QkcEpHyDE8QaaMriHDb3Jcp2tIO7MbeN1lvp1ht9ei1Lps9uJDZeOEd6CGCWEu7zbg=@vger.kernel.org X-Gm-Message-State: AFuF++kIHpbtIL2FQhebQm+KxgcuTau+JL4SZQmpbvmgcW+YrbvVZEhO sKstL8x3HexI6MS4+CAuFvLp29Fx7v3WFdaat4jPeCADcXUfaaAbF62w X-Gm-Gg: AYBFou3Qv47FAH5fRcDoMiH1VGdEDSNHOk0Ndsml0BBoOYF1o31U0A1T4MeCcGDTmDc 34s0wbhks3fzgdmNJMpieqq3Ourmj+rWqspL5yQxJ5lslMMSTyeimDtkL9nJfDi+BlaXNNEdNvK gCVuI/m8GtlwAuA/aXVdp1hJJ75SKMjrfG1uEztNrmAIy58rIAQebAW8tl5SUMi9Z45C9dp/EIm nIT9o5lzuTKc+ZvyWOHSTEzDbELdlvdEQhzfmdj0nUM3dSM95Mfc9pwL1eKjaPB1yMNHNgsQoBI 97mcgBBKO8nseXdUmDmfwH4XCbg4NVCxd7R/ZISO+LISCqEnUbUchR53+EJ/V5C8b2KXktK2zFV LtlG5FMwnoWWZQ/7juEfQpZS6GSEsqY33ku169j9pgjd56j9bTMBEcslkVYfyuWxD+S3jAhutVQ 1PfP9kw4E/aqZTRMNxfKzGvFtCKnH12DxfA27ZTa3tokRvAKufyBeOTRUtGKVOXlMmlp9lkSCTP e2goknIAVMP0G97/XktcGrwlSm2+S6PfLxGTtXDoOFxS8vE9ZXoEQHoTb6eVaoWR0IpRiZjPYZ0 hZ6+i2UfgXHXmAk= X-Received: by 2002:a05:600c:a015:b0:49f:c199:e1e2 with SMTP id 5b1f17b1804b1-49fe6700006mr27711555e9.28.1790241183440; Thu, 24 Sep 2026 02:13:03 -0700 (PDT) Received: from andreayoga.localdomain (93-42-14-189.ip84.fastwebnet.it. [93.42.14.189]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-4886848636asm12756677f8f.6.2026.09.24.02.13.01 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 24 Sep 2026 02:13:03 -0700 (PDT) From: Andrea Parri To: Christian Brauner , Carlos Maiolino , "Darrick J . Wong" , Joanne Koong , Brian Foster , Christoph Hellwig , Damien Le Moal , Hannes Reinecke , Daniel Gomez , Pankaj Raghav , Dave Chinner Cc: Andrea Parri , linux-xfs@vger.kernel.org, linux-fsdevel@vger.kernel.org, linux-kernel@vger.kernel.org, stable@vger.kernel.org Subject: [PATCH v2 4/4] iomap: don't lose a failed direct I/O bio's error when zeroing the tail Date: Thu, 24 Sep 2026 11:11:54 +0200 Message-ID: <20260924091203.198225-5-parri.andrea@gmail.com> X-Mailer: git-send-email 2.53.0 In-Reply-To: <20260924091203.198225-1-parri.andrea@gmail.com> References: <20260924091203.198225-1-parri.andrea@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" iomap_dio_bio_iter() falls through to the sub-block tail zeroing when the data bio submission fails, so that the rest of the block is still zeroed and stale data is not exposed. The zeroing result was assigned to ret, which overwrote the submission error with the successful zeroing result (zero) and the failed write was reported as success. iomap_dio_zero() can only return an error from a can't-happen WARN_ON_ONCE() (nr_vecs exceeding BIO_MAX_VECS, which the existing comment there says "shall never be reached" for any in-tree filesystem), so it isn't a real runtime failure worth reporting to userspace, let alone one worth losing the actual submission error for. Make iomap_dio_zero() return void and drop the error handling at both call sites instead of threading the result through a separate variable. Fixes: 10553a91652d ("iomap: fix iomap_dio_zero() for fs bs > system page s= ize") Cc: stable@vger.kernel.org Assisted-by: LLM Signed-off-by: Andrea Parri --- fs/iomap/direct-io.c | 19 +++++++------------ 1 file changed, 7 insertions(+), 12 deletions(-) diff --git a/fs/iomap/direct-io.c b/fs/iomap/direct-io.c index 8b4039d16ce89..e00995c296c79 100644 --- a/fs/iomap/direct-io.c +++ b/fs/iomap/direct-io.c @@ -296,8 +296,9 @@ u32 iomap_finish_ioend_direct(struct iomap_ioend *ioend) return vec_count; } =20 -static int iomap_dio_zero(const struct iomap_iter *iter, struct iomap_dio = *dio, - loff_t pos, unsigned len) +static void iomap_dio_zero(const struct iomap_iter *iter, + struct iomap_dio *dio, loff_t pos, + unsigned int len) { struct inode *inode =3D file_inode(dio->iocb->ki_filp); struct bio *bio; @@ -305,14 +306,14 @@ static int iomap_dio_zero(const struct iomap_iter *it= er, struct iomap_dio *dio, int nr_vecs =3D max(1, i_blocksize(inode) / folio_size(zero_folio)); =20 if (!len) - return 0; + return; =20 /* * This limit shall never be reached as most filesystems have a * maximum blocksize of 64k. */ if (WARN_ON_ONCE(nr_vecs > BIO_MAX_VECS)) - return -EINVAL; + return; =20 bio =3D iomap_dio_alloc_bio(iter, dio, nr_vecs, REQ_OP_WRITE | REQ_SYNC | REQ_IDLE); @@ -328,8 +329,6 @@ static int iomap_dio_zero(const struct iomap_iter *iter= , struct iomap_dio *dio, len -=3D io_len; } iomap_dio_submit_bio(iter, dio, bio, pos); - - return 0; } =20 static ssize_t iomap_dio_bio_iter_one(struct iomap_iter *iter, @@ -541,10 +540,7 @@ static int iomap_dio_bio_iter(struct iomap_iter *iter,= struct iomap_dio *dio) if (need_zeroout) { /* zero out from the start of the block to the write offset */ pad =3D pos & (fs_block_size - 1); - - ret =3D iomap_dio_zero(iter, dio, pos - pad, pad); - if (ret) - goto out; + iomap_dio_zero(iter, dio, pos - pad, pad); } =20 do { @@ -582,8 +578,7 @@ static int iomap_dio_bio_iter(struct iomap_iter *iter, = struct iomap_dio *dio) /* zero out from the end of the write to the end of the block */ pad =3D pos & (fs_block_size - 1); if (pad) - ret =3D iomap_dio_zero(iter, dio, pos, - fs_block_size - pad); + iomap_dio_zero(iter, dio, pos, fs_block_size - pad); } out: /* Undo iter limitation to current extent */ --=20 2.53.0