From: liubaolin <liubaolin12138@163.com>
To: dd <zhongling0719@126.com>, Hyunchul Lee <hyc.lee@gmail.com>
Cc: Hongling Zeng <zenghongling@kylinos.cn>,
linkinjeon@kernel.org, ntfs@lists.linux.dev,
linux-kernel@vger.kernel.org, stable@vger.kernel.org
Subject: Re: [PATCH v5] ntfs: mount hibernated volumes read-only regardless of errors=
Date: Tue, 22 Sep 2026 08:16:57 +0800 [thread overview]
Message-ID: <3b2dc68a-08fb-45c7-aaa9-bfa8de52affd@163.com> (raw)
In-Reply-To: <4e70c6d0.7644.1a0c34d327f.Coremail.zhongling0719@126.com>
在 2026/9/21 17:30, dd 写道:
> Hi baolin,
> Thanks for catching this. I agree that temporarily setting
> SB_RDONLY
> makes it impossible to distinguish an error suppressed by
> ntfs_handle_error()
> from a successful check. In particular, errors from optional WSL EA loading may neither propagate through the hibernation check nor set
> NVolErrors()
> , allowing the flag to be cleared incorrectly.
>
> Hi all:
> One question: with errors=panic, a corrupt $LogFile can still panic
> during load_system_files(), before the hibernation fallback is reached.
> For example, ntfs_check_logfile() panics on "LogFile is too small".
>
> Should mount-time metadata errors generally avoid errors=panic before
> the superblock is published? If so, that seems like a separate follow-up
> to extend the temporary policy substitution over load_system_files().
>
> Thanks!
Hi Hongling,
Yes, the earlier $LogFile check can still panic. I would keep that
behavior and limit the temporary substitution to the hibernation check.
The intention of this exception is to preserve read-only access where
possible when we cannot establish whether Windows is hibernated.Refusing
write access provides a conservative outcome in that case, without
bringing down the whole system. Temporarily substituting remount-ro lets
us reach that outcome even when nested lookup or inode-loading helpers
call ntfs_error().
This deliberately also covers genuine metadata errors encountered
during the probe. It is a limited policy exception for the hibernation
check,rather than a requirement to suppress panic throughout mount.
A corrupt $LogFile detected earlier is an independent filesystem
error.Honoring the user's explicit errors=panic choice there is
reasonable,and that path will not proceed to the subsequent $LogFile
emptying.I do not think the hibernation exception requires changing that
behavior.
Also, extending the substitution over load_system_files() would not
cover the whole mount process: boot-sector processing and the initial
$MFT loading happen before it. Extending it further to cover all mount
stages would effectively make errors=panic apply only after a successful
mount, while using remount-ro during mount. I think that would override
the user's selected policy too broadly.
So my preference is to keep the temporary substitution around
check_windows_hibernation_status() and preserve the existing policy
elsewhere.
Thanks,
Baolin.
>
> At 2026-09-21 15:57:29, "Hyunchul Lee" <hyc.lee@gmail.com> wrote:
>> Hi Baolin, Hongling
>>
>>> If you agree with this approach, could you please incorporate it and
>>> send another revision? I'd appreciate feedback from you, Namjae, and
>>> Hyunchul.
>>
>> I agree with this approach. It looks sound to me.
>>
>>>
>>> feel free to add:
>>> Suggested-by: Baolin Liu <liubaolin@kylinos.cn>
>>>
>>> Thanks,
>>> Baolin.
>>>
>>>
>>>
>>>
>>>
>>>
>>>
>>>> if (unlikely(err)) {
>>>> static const char *es1a = "Failed to determine if Windows is hibernated";
>>>> static const char *es1b = "Windows is hibernated";
>>>> @@ -1581,12 +1594,25 @@ static bool load_system_files(struct ntfs_volume *vol)
>>>> const char *es1;
>>>>
>>>> es1 = err < 0 ? es1a : es1b;
>>>> - /* If a read-write mount, convert it to a read-only mount. */
>>>> - if (!sb_rdonly(sb) && vol->on_errors == ON_ERRORS_REMOUNT_RO) {
>>>> - sb->s_flags |= SB_RDONLY;
>>>> - ntfs_error(sb, "%s. Mounting read-only%s", es1, es2);
>>>> - }
>>>> + /*
>>>> + * A Windows hibernation image is not a filesystem error, so
>>>> + * this is a safety interlock rather than something the
>>>> + * errors= policy may downgrade. The super block is already
>>>> + * read-only here: the temporary flag taken for the check
>>>> + * above is not restored when the check failed.
>>>> + */
>>>> + ntfs_error(sb, "%s. Mounting read-only%s", es1, es2);
>>>> NVolSetErrors(vol);
>>>> + } else if (unlikely(temporary_ro && sb_rdonly(sb))) {
>>>> + static const char *es1 = "Errors were recorded during mount";
>>>> + static const char *es2 = ". Run chkdsk.";
>>>> +
>>>> + /*
>>>> + * Errors were recorded during the check or earlier, e.g. when
>>>> + * loading the LogFile. Stay read-only, like ntfs_reconfigure()
>>>> + * does for volumes with recorded errors.
>>>> + */
>>>> + ntfs_error(sb, "%s. Mounting read-only%s", es1, es2);
>>>> }
>>>>
>>>> /* If (still) a read-write mount, empty the logfile. */
>>>
>>
>>
>> --
>> Thanks,
>> Hyunchul
next prev parent reply other threads:[~2026-09-22 0:17 UTC|newest]
Thread overview: 6+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-20 2:59 Hongling Zeng
2026-09-20 11:25 ` liubaolin
2026-09-21 7:57 ` Hyunchul Lee
2026-09-21 9:30 ` dd
2026-09-22 0:16 ` liubaolin [this message]
2026-09-22 1:26 ` Hyunchul Lee
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=3b2dc68a-08fb-45c7-aaa9-bfa8de52affd@163.com \
--to=liubaolin12138@163.com \
--cc=hyc.lee@gmail.com \
--cc=linkinjeon@kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=ntfs@lists.linux.dev \
--cc=stable@vger.kernel.org \
--cc=zenghongling@kylinos.cn \
--cc=zhongling0719@126.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®