From: Matthias Goergens <matthias.goergens@gmail.com>
To: Namjae Jeon <linkinjeon@kernel.org>, Hyunchul Lee <hyc.lee@gmail.com>
Cc: ntfs@lists.linux.dev, linux-kernel@vger.kernel.org
Subject: [PATCH v2 0/6] ntfs: fix the $MFT bootstrap hang and reads of unmapped runlist ranges
Date: Sun, 27 Sep 2026 13:08:19 +0800 [thread overview]
Message-ID: <cover.1790417653.git.matthias.goergens@gmail.com> (raw)
In-Reply-To: <arMoap0ZgeORuktT@hyunchul-PC02>
Hi Hyunchul,
This is v2 of "ntfs: fail the mount when $MFT needs its own extent
records", now patch 3. As you suggested, the mark now stays set for the
whole $DATA enumeration in ntfs_read_inode_mount(). A crafted image
that puts $MFT's second $DATA extent in an extent record the first
extent does not cover hung v1 in that loop; with v2 the mount fails.
One correction to v1: lockdep stayed silent not because of the folio
lock, but because ntfs_fill_super() turns it off for the whole mount.
Patch 3 needs patch 1. With clusters smaller than a page, patch 3 can
refuse the tail of a folio holding an $MFT record, and without patch 1
the refused range is mapped as a hole and the mount carries on with an
all-zero mft record.
That hole is not specific to $MFT. Patches 1 and 2 fix it for any file
whose runlist is partly in an extent record that cannot be read: reads
of that range return zeros with no error, and buffered writes into it
report success and are lost. Patch 4 does the same for a runlist that
ends before allocated_size, which a crafted $MFT used to get past patch
3. Patch 5 refuses a $MFT whose data_size exceeds its allocation, and
patch 6 requires initialized_size <= data_size <= allocated_size, with
allocated_size a multiple of the cluster size, for every non-resident
attribute, as fs/ntfs3 does.
Tested under qemu with KASAN and the hung-task detector on ntfs-next,
with and without the series. Nine crafted images that hang or crash the
mount without it fail to mount with it, and six that read zeros that are
not on disk return errors instead. Eighteen images that mount without
the series, among them eight public test volumes written by Windows or
mkntfs, read every file the same with it, and six small mkntfs images
still mount. The images and the scripts that generate them are at
https://github.com/matthiasgoergens/linux/tree/reproducer/2026-09-26-ntfs-mft-runlist
and, for the ordinary file of patch 4, the unaligned allocated_size of
patch 6 and three of the volumes that mount, at
https://github.com/matthiasgoergens/linux/tree/reproducer/2026-09-26-ntfs-v2-extra
v1: https://lore.kernel.org/all/20260922153931.1976405-1-matthias.goergens@gmail.com/
Thanks,
Matthias
Matthias Goergens (6):
ntfs: do not map an unmappable runlist fragment as a hole
ntfs: do not turn an unmappable runlist fragment into delalloc on
write
ntfs: fail the mount when $MFT needs its own extent records
ntfs: do not map a vcn as a hole when its runlist lookup failed
ntfs: fail the mount when $MFT's data size exceeds its allocation
ntfs: reject non-resident attributes whose sizes exceed their
allocation
fs/ntfs/attrib.c | 54 +++++++++++++++++++++++++++++++++++++++----
fs/ntfs/attrlist.c | 8 +++++--
fs/ntfs/inode.c | 57 ++++++++++++++++++++++++++++++++++++++++++++++
fs/ntfs/iomap.c | 16 +++++++++++--
fs/ntfs/layout.h | 13 +++++++----
fs/ntfs/volume.h | 3 +++
6 files changed, 137 insertions(+), 14 deletions(-)
base-commit: 259abb551e2944998cad4214c201954ab1ac5c8d
--
2.55.0
next prev parent reply other threads:[~2026-09-27 5:08 UTC|newest]
Thread overview: 15+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-22 15:39 [PATCH] ntfs: fail the mount when $MFT needs its own extent records Matthias Goergens
2026-09-23 1:16 ` Hyunchul Lee
2026-09-27 5:08 ` Matthias Goergens [this message]
2026-09-27 5:08 ` [PATCH v2 1/6] ntfs: do not map an unmappable runlist fragment as a hole Matthias Goergens
2026-09-27 23:03 ` liubaolin
2026-09-27 5:08 ` [PATCH v2 2/6] ntfs: do not turn an unmappable runlist fragment into delalloc on write Matthias Goergens
2026-09-28 0:21 ` Hyunchul Lee
2026-09-28 1:46 ` Hyunchul Lee
2026-09-27 5:08 ` [PATCH v2 3/6] ntfs: fail the mount when $MFT needs its own extent records Matthias Goergens
2026-09-27 5:08 ` [PATCH v2 4/6] ntfs: do not map a vcn as a hole when its runlist lookup failed Matthias Goergens
2026-09-28 1:09 ` Hyunchul Lee
2026-09-27 5:08 ` [PATCH v2 5/6] ntfs: fail the mount when $MFT's data size exceeds its allocation Matthias Goergens
2026-09-27 5:08 ` [PATCH v2 6/6] ntfs: reject non-resident attributes whose sizes exceed their allocation Matthias Goergens
2026-09-28 1:42 ` Hyunchul Lee
2026-09-29 0:26 ` liubaolin
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=cover.1790417653.git.matthias.goergens@gmail.com \
--to=matthias.goergens@gmail.com \
--cc=hyc.lee@gmail.com \
--cc=linkinjeon@kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=ntfs@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®