From: Chi Zhiling <chizhiling@163.com>
To: exfat@lists.linux.dev, linux-kernel@vger.kernel.org
Cc: Namjae Jeon <linkinjeon@kernel.org>,
Sungjong Seo <sj1557.seo@samsung.com>,
Yuezhang Mo <yuezhang.mo@sony.com>,
Chi Zhiling <chizhiling@kylinos.cn>
Subject: [PATCH 2/2] exfat: take bitmap_lock at the start of exfat_alloc_cluster()
Date: Sat, 5 Sep 2026 13:49:51 +0800 [thread overview]
Message-ID: <20260905054951.674766-3-chizhiling@163.com> (raw)
In-Reply-To: <20260905054951.674766-1-chizhiling@163.com>
From: Chi Zhiling <chizhiling@kylinos.cn>
exfat_alloc_cluster() checks sbi->used_clusters against the total
number of data clusters before acquiring sbi->bitmap_lock. A concurrent
allocation can update sbi->used_clusters after the check but before
the lock is acquired, making the check stale. This can allow the
allocation to proceed even though there are not enough free clusters,
causing it to fail partway through.
Acquire sbi->bitmap_lock before checking sbi->used_clusters so that
the free-space check and subsequent cluster allocation are serialized
with concurrent allocations.
Signed-off-by: Chi Zhiling <chizhiling@kylinos.cn>
---
fs/exfat/fatent.c | 17 ++++++++++-------
1 file changed, 10 insertions(+), 7 deletions(-)
diff --git a/fs/exfat/fatent.c b/fs/exfat/fatent.c
index a6728c361289..3c8bdc131f6f 100644
--- a/fs/exfat/fatent.c
+++ b/fs/exfat/fatent.c
@@ -427,19 +427,22 @@ int exfat_alloc_cluster(struct inode *inode, unsigned int num_alloc,
struct super_block *sb = inode->i_sb;
struct exfat_sb_info *sbi = EXFAT_SB(sb);
+ mutex_lock(&sbi->bitmap_lock);
+
total_cnt = EXFAT_DATA_CLUSTER_COUNT(sbi);
if (unlikely(total_cnt < sbi->used_clusters)) {
exfat_fs_error_ratelimit(sb,
"%s: invalid used clusters(t:%u,u:%u)\n",
__func__, total_cnt, sbi->used_clusters);
- return -EIO;
+ ret = -EIO;
+ goto unlock;
}
- if (num_alloc > total_cnt - sbi->used_clusters)
- return -ENOSPC;
-
- mutex_lock(&sbi->bitmap_lock);
+ if (num_alloc > total_cnt - sbi->used_clusters) {
+ ret = -ENOSPC;
+ goto unlock;
+ }
hint_clu = p_chain->dir;
/* find new cluster */
@@ -516,8 +519,8 @@ int exfat_alloc_cluster(struct inode *inode, unsigned int num_alloc,
if (p_chain->size == num_alloc) {
done:
sbi->clu_srch_ptr = hint_clu;
- mutex_unlock(&sbi->bitmap_lock);
- return 0;
+ ret = 0;
+ goto unlock;
}
hint_clu = new_clu + 1;
--
2.53.0
next prev parent reply other threads:[~2026-09-05 5:51 UTC|newest]
Thread overview: 7+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-05 5:49 [PATCH 0/2] exfat: fix cluster allocation accounting and locking Chi Zhiling
2026-09-05 5:49 ` [PATCH 1/2] exfat: fix used_clusters accounting during cluster allocation Chi Zhiling
2026-09-05 5:49 ` Chi Zhiling [this message]
2026-09-07 3:21 ` [PATCH 2/2] exfat: take bitmap_lock at the start of exfat_alloc_cluster() David Timber
2026-09-07 8:04 ` Chi Zhiling
2026-09-08 0:53 ` David Timber
2026-09-05 9:33 ` [PATCH 0/2] exfat: fix cluster allocation accounting and locking Namjae Jeon
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260905054951.674766-3-chizhiling@163.com \
--to=chizhiling@163.com \
--cc=chizhiling@kylinos.cn \
--cc=exfat@lists.linux.dev \
--cc=linkinjeon@kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=sj1557.seo@samsung.com \
--cc=yuezhang.mo@sony.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®