From: Jiale Yao <yaojiale02@163.com>
To: Namjae Jeon <linkinjeon@kernel.org>,
Sungjong Seo <sj1557.seo@samsung.com>,
Yuezhang Mo <yuezhang.mo@sony.com>,
"Darrick J. Wong" <djwong@kernel.org>,
exfat@lists.linux.dev, linux-kernel@vger.kernel.org
Cc: Jiale Yao <yaojiale02@163.com>
Subject: [PATCH v4 3/3] exfat: drain in-flight DIO before buffered writes
Date: Sat, 3 Oct 2026 17:30:35 +0800 [thread overview]
Message-ID: <20261003093035.532916-4-yaojiale02@163.com> (raw)
In-Reply-To: <20261003093035.532916-1-yaojiale02@163.com>
An asynchronous direct write can remain in flight after the inode lock is
released. If a buffered operation dirties page cache while the direct
write is still pending, the direct write's post-I/O invalidation can find
the dirty pages, report a page cache invalidation failure, and record -EIO
in the mapping error sequence. A later fsync() therefore returns -EIO.
Commit 15cdefd0c0522f9d5e12d947fa04f4c11649b699 ("ext4: drain
in-flight DIO before buffered write fallback") fixed the same race in
ext4. ExFAT does not drain in-flight DIO before a regular buffered write,
the buffered fallback after iomap_dio_rw() returns -ENOTBLK or a short
write, or the page-cache operations used to extend valid_size.
Wait for in-flight DIO before these paths can dirty page cache.
A reproducer using concurrent AIO direct writes and buffered fallback
triggered the following warning and made a subsequent fsync() return
-EIO:
Page cache invalidation failure on direct I/O. Possible data corruption
due to collision with buffered I/O!
Fixes: 867b9c96dc83 ("exfat: add iomap direct I/O support")
Link: https://lore.kernel.org/r/20260629113827.4074335-3-libaokun@linux.alibaba.com
Signed-off-by: Jiale Yao <yaojiale02@163.com>
---
fs/exfat/file.c | 14 ++++++++++++--
1 file changed, 12 insertions(+), 2 deletions(-)
diff --git a/fs/exfat/file.c b/fs/exfat/file.c
index a2a9ee1a2004..3f08b571dec1 100644
--- a/fs/exfat/file.c
+++ b/fs/exfat/file.c
@@ -758,6 +758,8 @@ static int exfat_extend_valid_size(struct inode *inode, loff_t new_valid_size)
int ret = 0;
if (old_valid_size < new_valid_size) {
+ inode_dio_wait(inode);
+
/* Do not re-zero blocks already covered by zeroed_size. */
loff_t gap_start = max(old_valid_size, ei->zeroed_size);
@@ -807,6 +809,8 @@ static ssize_t exfat_fallback_buffered_write(struct kiocb *iocb,
iocb->ki_flags &= ~IOCB_DIRECT;
+ inode_dio_wait(file_inode(iocb->ki_filp));
+
written = iomap_file_buffered_write(iocb, from, &exfat_write_iomap_ops,
NULL, NULL);
if (written < 0)
@@ -889,11 +893,17 @@ static ssize_t exfat_file_write_iter(struct kiocb *iocb, struct iov_iter *iter)
goto unlock;
}
- if (iocb->ki_flags & IOCB_DIRECT)
+ if (iocb->ki_flags & IOCB_DIRECT) {
ret = exfat_dio_write_iter(iocb, iter);
- else
+ } else {
+ /*
+ * Prevent concurrent direct I/O and buffered I/O to the same file
+ * range. Wait for in-flight DIO to finish before dirtying pages.
+ */
+ inode_dio_wait(inode);
ret = iomap_file_buffered_write(iocb, iter,
&exfat_write_iomap_ops, NULL, NULL);
+ }
if (ret < 0)
goto unlock;
--
2.34.1
next prev parent reply other threads:[~2026-10-03 9:31 UTC|newest]
Thread overview: 7+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-10-03 9:30 [PATCH v4 0/3] fs: drain in-flight DIO before buffered write fallback Jiale Yao
2026-10-03 9:30 ` [PATCH v4 1/3] ext2: " Jiale Yao
2026-10-03 9:30 ` [PATCH v4 2/3] ntfs: " Jiale Yao
2026-10-06 7:45 ` Hyunchul Lee
2026-10-06 13:30 ` Namjae Jeon
2026-10-03 9:30 ` Jiale Yao [this message]
2026-10-06 13:00 ` [PATCH v4 3/3] exfat: drain in-flight DIO before buffered writes Namjae Jeon
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20261003093035.532916-4-yaojiale02@163.com \
--to=yaojiale02@163.com \
--cc=djwong@kernel.org \
--cc=exfat@lists.linux.dev \
--cc=linkinjeon@kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=sj1557.seo@samsung.com \
--cc=yuezhang.mo@sony.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®