From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-pf1-f171.google.com (mail-pf1-f171.google.com [209.85.210.171]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 9C75F2989BC for ; Sun, 7 Jun 2026 05:17:36 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.210.171 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1780809459; cv=none; b=Wm/80w0UcU9Bj3IByTC57dVVxQjQOpq07vqbSzeUUziwpi+5e7u/oaabutlYNKI3vNhed+v8N2x9RDlHmCDNQkYpSepuqic6eNdyrmi7I5fT7d4kDHciLr5ZvVglyiV7zxi9Q8wLoqVxf++tdVjbzAFoVjMlQ+S1hKFRAcvor0M= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1780809459; c=relaxed/simple; bh=7aEKoCbAZP8jKDextGuPOy3ovK/navVFADXy48US3yM=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=VlFXaONH+rk/oUTZvKRMD/RMUxqTljduGQjd3Nr6pTcJKavTtpC3fIxfHtouXxYr5BzrJf4l+mlOqDnTuDa/LPCc3KkIEb0Ur1ZZ69IPEKIuv+OaVU8yiBL6gofGukulb5M3eud4JU39in5pW0Vt8ggzF93A6N/9bAJivyHeZt8= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=WbWk0/83; arc=none smtp.client-ip=209.85.210.171 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="WbWk0/83" Received: by mail-pf1-f171.google.com with SMTP id d2e1a72fcca58-8423f241792so83790b3a.1 for ; Sat, 06 Jun 2026 22:17:36 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1780809456; x=1781414256; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to; bh=OUmwuBjLvF0gJnDu5WwguMvo2blC3awnfJ4Cf5R95CQ=; b=WbWk0/83P5HUgg2SorlR0ankmqpPp54656ILwHLFKZugHOvmFxr/flfZRMWBpA1OVv +XUzzN8lAsr/PDJO0W+xekDeVMjaU881wRXjdOW3Ff2vejl7xjcD/Gnz3yOUnLBGdE/L mv1imPVPtADhwDDupST4RULXABc0pLS4wiK5aq1D2DXFoXrSZPr60sV6+MJ0cR4YSrH8 s1zGepgM/6EtiPTmSOeS33OPl+HjTL0dXkGQWAlCQQvIQ+vYow2GyUHeu0y4MxuKCYGo EbFgJuhCzcqoSTbDxjhTnPSgQDt47Y32BOD2K0lQ94zJ6yfarRXfZw7w2LUnMkLCh/EV se0w== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1780809456; x=1781414256; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to; bh=OUmwuBjLvF0gJnDu5WwguMvo2blC3awnfJ4Cf5R95CQ=; b=RpBysQSCsrXtjcR9f3iVXOAS4dd+QFYLp3SNFYrpRx/128r5QTC/929Tsg59FKhI1O L/91fia9WzFwoR5Khk6WFOHtHI1IrU9EiwZIOEHzw020fmFFzwsjAMxp6UKCAT2UA41Z 3yRJeXR100PKNv0zgIzE0O/Y8b9/HUXP5xDxnWy31j2BxkWILTla2PFu6EHOnRDHUeDX 0LJQ4ooMbtoOde/8Ep52nLBUEz28BXkBCGhv5aJJpditF0EbbgkTzh5dbu7kKVqaOGLy DHhrAxdwFw6fRiO74foUcDsiudi/9+y9JMnQQF0SqT4kEL6L6KuT1KFg7eK6Bt/Ye7vy Ua5A== X-Forwarded-Encrypted: i=1; AFNElJ+qVo+rcbSYz4vhCN4dx5zsUMtZkchVaPTKCOCSjR84rxonkuLGp0GxMPzHk2+C0bjh9iiTSwtgMSrorG4=@vger.kernel.org X-Gm-Message-State: AOJu0YxLKUmhTY7jiW2VPIIatfo39teqR2IfYmPHE2y6r5gA26RppGa7 0l+yGXJPRw9PMwkD2nFkwz4ot/UHSY3/Ya9ADxKECLoa4PExD8iD7AVM X-Gm-Gg: Acq92OGaywuB6B/m1i7VLUhXLDr/Ds0x89fdQyeQruLpSKNr3uaSGGE8tUImwdq4/Vc BKrgM3enPQKVXhOz5RGjkoYGt/0bi2VO7h4SDyGhy/VukovSfhwa691NhruOlUkxQFPlSugsHEg YrZVYygtR2KeFhUqDRA6FRblg+ibXQguy8aqOqiRBIZSskKl8YIIArKcUUY1tRunNplpAZAWHOX uCbSC69pz+m3DnzV/AUDOGV1HJPwkqGgtgr/HFVeTBbbTvplaCPslCoF7Di0v8PoYc/RV9t/hAU onn6fw83o8EnxZ8NHnmUNvOHSKSebUOYOqM90i3oxijBMCsGCrlwzJkv1MuQbBIBYh8gUn9b/wc X8QYJbEVXnJ2xOsLugbPHEISL2YLMD6GjwFY8Z7tefpVkZlab7YjuIrj006rupvqHWt8KVLXcy2 3S0Z9LB/rekoXDi56LWEbUTVNRM2zE+ZX4qSf4Eg== X-Received: by 2002:a05:6a00:a203:b0:834:dfb5:6e7f with SMTP id d2e1a72fcca58-842b0d4c5c2mr4955360b3a.2.1780809455818; Sat, 06 Jun 2026 22:17:35 -0700 (PDT) Received: from ser8.. ([221.156.231.192]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-842828e5638sm14494648b3a.50.2026.06.06.22.17.34 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sat, 06 Jun 2026 22:17:35 -0700 (PDT) From: DaeMyung Kang To: Namjae Jeon , Hyunchul Lee Cc: linux-fsdevel@vger.kernel.org, linux-kernel@vger.kernel.org, DaeMyung Kang Subject: [PATCH v5 3/4] ntfs: update index root allocated size before shrink Date: Sun, 7 Jun 2026 14:17:22 +0900 Message-ID: <20260607051723.1499833-4-charsyam@gmail.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260607051723.1499833-1-charsyam@gmail.com> References: <20260607051723.1499833-1-charsyam@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit ntfs_ir_truncate() currently shrinks the resident $INDEX_ROOT value first and only updates index.allocated_size after re-looking up the attribute. During that relookup, the resident value_length can already be smaller while index.allocated_size still contains the old larger size. That leaves a transiently inconsistent $INDEX_ROOT layout and prevents lookup-time $INDEX_ROOT validation from being enabled: validation can correctly reject allocated_size extending past the newly shrunk resident value. When shrinking, lower index.allocated_size before shrinking value_length. If the truncate fails, restore the old allocated_size. Keep the existing grow ordering because the old allocated_size remains within the enlarged resident value until it is updated after the relookup. The shrink path is safe because the new value_length still covers struct index_root, so the index.allocated_size field remains present while it is updated first. Signed-off-by: DaeMyung Kang --- fs/ntfs/index.c | 18 +++++++++++++++--- 1 file changed, 15 insertions(+), 3 deletions(-) diff --git a/fs/ntfs/index.c b/fs/ntfs/index.c index ab9a4bc36f0b..a411ca7fe629 100644 --- a/fs/ntfs/index.c +++ b/fs/ntfs/index.c @@ -1298,9 +1298,16 @@ static int ntfs_ir_reparent(struct ntfs_index_context *icx) static int ntfs_ir_truncate(struct ntfs_index_context *icx, int data_size) { int ret; + u32 old_allocated_size; + bool shrink; ntfs_debug("Entering\n"); + old_allocated_size = le32_to_cpu(icx->ir->index.allocated_size); + shrink = data_size < old_allocated_size; + if (shrink) + icx->ir->index.allocated_size = cpu_to_le32(data_size); + /* * INDEX_ROOT must be resident and its entries can be moved to * struct index_block, so ENOSPC isn't a real error. @@ -1312,9 +1319,14 @@ static int ntfs_ir_truncate(struct ntfs_index_context *icx, int data_size) if (!icx->ir) return -ENOENT; - icx->ir->index.allocated_size = cpu_to_le32(data_size); - } else if (ret != -ENOSPC) - ntfs_error(icx->idx_ni->vol->sb, "Failed to truncate INDEX_ROOT"); + if (!shrink) + icx->ir->index.allocated_size = cpu_to_le32(data_size); + } else { + if (shrink) + icx->ir->index.allocated_size = cpu_to_le32(old_allocated_size); + if (ret != -ENOSPC) + ntfs_error(icx->idx_ni->vol->sb, "Failed to truncate INDEX_ROOT"); + } return ret; } -- 2.43.0