From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail.parknet.co.jp (mail.parknet.co.jp [210.171.160.6]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 6C0831E89C for ; Sun, 1 Mar 2026 03:39:53 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=210.171.160.6 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1772336396; cv=none; b=tYSu1Di8n5ywO5K1G4XyiCvAJmHMPws6Ilo3W3zUWhjf7QEJhB1xxx66epc+I7Dn7T3eSvnPYkF6p3dA2KJQRAHGTHcES8O6XPuYTYZDTnlcMwC1+8TDHnKoXOKut0KEvylNFoj0lph095CBo7QMbKOYrfMZIsni9CvdRazrjO0= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1772336396; c=relaxed/simple; bh=qw9kSmEs9oM4LtFtD/Be2Nqju3hVi0eXsc3q3XpADko=; h=From:To:Cc:Subject:In-Reply-To:References:Date:Message-ID: MIME-Version:Content-Type; b=FnebFPu0zwQrqkPmQOvTpksJo2Hutf6cpsHg6Cihc4nVXvccbIMfOnaFVUiGtgNQI1bdLNLGIA+Co0du+eRK4sl2I4v7DNXCqefPz+BGUTvSIb1KXUUe8NwEBSydt5hD0RP7yoCHVyxg4fySuzzUiEmubSRv83AzGISWaDr2tY0= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=mail.parknet.co.jp; spf=pass smtp.mailfrom=parknet.co.jp; dkim=pass (2048-bit key) header.d=parknet.co.jp header.i=@parknet.co.jp header.b=h4pa3sqb; dkim=permerror (0-bit key) header.d=parknet.co.jp header.i=@parknet.co.jp header.b=MqaPULfn; arc=none smtp.client-ip=210.171.160.6 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=mail.parknet.co.jp Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=parknet.co.jp Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=parknet.co.jp header.i=@parknet.co.jp header.b="h4pa3sqb"; dkim=permerror (0-bit key) header.d=parknet.co.jp header.i=@parknet.co.jp header.b="MqaPULfn" Received: from ibmpc.myhome.or.jp (server.parknet.ne.jp [210.171.168.39]) by mail.parknet.co.jp (Postfix) with ESMTPSA id 5553A26F765C; Sun, 1 Mar 2026 12:33:29 +0900 (JST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=parknet.co.jp; s=20250114; t=1772336009; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: in-reply-to:in-reply-to:references:references; bh=0GYh2M22hCz7RorkdhXEFjwbuVbCe1p4Bo1PHAVp3UE=; b=h4pa3sqbT8cL81/F1VGO+HZ+JMPiynN/CEWvZyCwyMGOdEN54ZUXCTjdwwDa1tWCl8Za+7 YhQNZTo3rt4SuqfY/qyFq/UNERKZeBjRTZxrRvPvRrp4XtBKGGn6iLcyYYH/s4zqMnoj1Z qSaXvCh0qRGNtYhr5Q9soHaFejJQ4qsY7XsW2DpSokEl5NJT+YfXMvBNzbnbJNJrh2TIBE nl/tcjIjgcQq3nk8YkTY0fGIUs6uo551ykN0ir2zdqjGadhOaTDdfTN+Gsnp2oTKEVHVL5 /jon6OYbpQtSaeYt4UA3WnnMwGnYk7Qq3gwYHrcbeSqeY5EBxfwvnovRDqfvfg== DKIM-Signature: v=1; a=ed25519-sha256; c=relaxed/relaxed; d=parknet.co.jp; s=20250114-ed25519; t=1772336009; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: in-reply-to:in-reply-to:references:references; bh=0GYh2M22hCz7RorkdhXEFjwbuVbCe1p4Bo1PHAVp3UE=; b=MqaPULfn91pBdG4AQlO1ThrhK9F8ExSG7RSpr0fuCFTbzJIgSEVzIPx3Pt50l3WIsBIFjT CQ8S6GnWXcj3tSBw== Received: from devron.myhome.or.jp (foobar@devron.myhome.or.jp [192.168.0.3]) by ibmpc.myhome.or.jp (8.18.2/8.18.2/Debian-1) with ESMTPS id 6213XSdl057048 (version=TLSv1.3 cipher=TLS_AES_256_GCM_SHA384 bits=256 verify=NOT); Sun, 1 Mar 2026 12:33:29 +0900 Received: from devron.myhome.or.jp (foobar@localhost [127.0.0.1]) by devron.myhome.or.jp (8.18.2/8.18.2/Debian-1) with ESMTPS id 6213XROQ164842 (version=TLSv1.3 cipher=TLS_AES_256_GCM_SHA384 bits=256 verify=NOT); Sun, 1 Mar 2026 12:33:27 +0900 Received: (from hirofumi@localhost) by devron.myhome.or.jp (8.18.2/8.18.2/Submit) id 6213XRfG164841; Sun, 1 Mar 2026 12:33:27 +0900 From: OGAWA Hirofumi To: tejas bharambe Cc: "linux-kernel@vger.kernel.org" , "syzbot+56be2a55de6142438317@syzkaller.appspotmail.com" Subject: Re: [PATCH] fat: fix data race in fat_clusters_flush between free_clusters access In-Reply-To: References: Date: Sun, 01 Mar 2026 12:33:27 +0900 Message-ID: <87bjh8b4vs.fsf@mail.parknet.co.jp> User-Agent: Gnus/5.13 (Gnus v5.13) Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain tejas bharambe writes: > From b1b914bdde5bc450eb586141823ba34924606b49 Mon Sep 17 00:00:00 2001 > From: Tejas Bharambe > Date: Sat, 28 Feb 2026 09:58:20 -0800 > Subject: [PATCH] fat: fix data race in fat_clusters_flush between > free_clusters access > > fat_clusters_flush() reads sbi->free_clusters and sbi->prev_free > without holding sbi->fat_lock, while fat_alloc_clusters() modifies > these fields under the lock. This causes a data race detected by KCSAN. > > Fix this by acquiring sbi->fat_lock around the read of these fields > in fat_clusters_flush(). > > Reported-by: syzbot+56be2a55de6142438317@syzkaller.appspotmail.com > Closes: https://syzkaller.appspot.com/bug?extid=56be2a55de6142438317 > Signed-off-by: Tejas Bharambe What is the real issue with this race other than KCSAN says? fat_clusters_flush() is called only after marked as dirty. And it is dirty only after completed the modification of those fields. AFAICT, on disk data is fixed until unmount even if there is temporary corruption. Or can you reproduce the real corruption with this race? Thanks. > --- > fs/fat/misc.c | 2 ++ > 1 file changed, 2 insertions(+) > > diff --git a/fs/fat/misc.c b/fs/fat/misc.c > index b154a51627..7d257a5694 100644 > --- a/fs/fat/misc.c > +++ b/fs/fat/misc.c > @@ -89,10 +89,12 @@ int fat_clusters_flush(struct super_block *sb) > le32_to_cpu(fsinfo->signature2), > sbi->fsinfo_sector); > } else { > + mutex_lock(&sbi->fat_lock); > if (sbi->free_clusters != -1) > fsinfo->free_clusters = cpu_to_le32(sbi->free_clusters); > if (sbi->prev_free != -1) > fsinfo->next_cluster = cpu_to_le32(sbi->prev_free); > + mutex_unlock(&sbi->fat_lock); > mark_buffer_dirty(bh); > } > brelse(bh); -- OGAWA Hirofumi