summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorHongling Zeng <zenghongling@kylinos.cn>2026-08-31 16:30:14 +0800
committerNamjae Jeon <linkinjeon@kernel.org>2026-08-31 19:46:30 +0900
commit9cc5761b8f28f9cef72061094eb5e37e2cd44d97 (patch)
tree1e9c6556da1d56e054ea2e15fc3acce5ab39b683
parent4dc8f4ee2d46d5d1e749ddd1b94912c72e796162 (diff)
downloadlinux-9cc5761b8f28f9cef72061094eb5e37e2cd44d97.tar.gz
linux-9cc5761b8f28f9cef72061094eb5e37e2cd44d97.zip
ntfs: take invalidate_lock in ntfs_setattr_size()
ntfs_setattr_size() updates i_size and resizes the on-disk attribute without holding mapping->invalidate_lock. Page faults take the lock shared, so a fault racing the resize can resolve a VCN against the transient runlist state of ntfs_non_resident_attr_expand() and fail with a spurious SIGBUS, and can interleave with the size-change epilogue (truncate_pagecache(), i_size_write(), pagecache_isize_extended()). Take invalidate_lock exclusively around the whole resize after inode_dio_wait(), matching the fallocate path and other filesystems such as xfs, which wraps truncate in its mmaplock (= invalidate_lock). Fixes: 9c87959601e8 ("ntfs: update file operations") Cc: stable@vger.kernel.org Reviewed-by: Hyunchul Lee <hyc.lee@gmail.com> Reviewed-by: Baolin Liu <liubaolin@kylinos.cn> Signed-off-by: Hongling Zeng <zenghongling@kylinos.cn> Signed-off-by: Namjae Jeon <linkinjeon@kernel.org>
-rw-r--r--fs/ntfs/file.c15
1 files changed, 11 insertions, 4 deletions
diff --git a/fs/ntfs/file.c b/fs/ntfs/file.c
index 1969e4f444f7..585ab2145797 100644
--- a/fs/ntfs/file.c
+++ b/fs/ntfs/file.c
@@ -270,18 +270,25 @@ static int ntfs_setattr_size(struct inode *vi, struct iattr *attr)
return err;
inode_dio_wait(vi);
+
+ /*
+ * Serialize with page faults and pagecache instantiation so that
+ * readers cannot observe the size change until the attribute
+ * updates below have completed.
+ */
+ filemap_invalidate_lock(vi->i_mapping);
if (attr->ia_size > old_size) {
truncate_pagecache(vi, old_size);
i_size_write(vi, attr->ia_size);
pagecache_isize_extended(vi, old_size, attr->ia_size);
- } else
+ } else {
truncate_setsize(vi, attr->ia_size);
+ }
err = ntfs_truncate_vfs(vi, attr->ia_size, old_size);
- if (err) {
+ if (err)
i_size_write(vi, old_size);
- return err;
- }
+ filemap_invalidate_unlock(vi->i_mapping);
return err;
}