Re: [f2fs-dev] [PATCH] f2fs: reject overlapping move range after len expansion
Chao Yu via Linux-f2fs-devel <[email protected]> Mon, 3 Aug 2026 15:07:59 +0800
| Newsgroups | net.sourceforge.lists.linux-f2fs-devel,org.kernel.vger.linux-kernel,org.kernel.vger.stable |
|---|---|
| Message-ID | <[email protected]> |
On 7/8/26 14:54, Hao-Qun Huang wrote:
> F2FS_IOC_MOVE_RANGE treats a zero length as a request to move data
> from pos_in to EOF. However, the same-file overlap check runs before
> that expansion, so a request with len == 0 bypasses the overlap
> rejection added for same-file moves.
>
> For example, with a four-block file, moving from block 0 to block 1
> with len == 0 is accepted by the old check because pos_in + len is
> still pos_in at that point. The code then expands len to cover the
> rest of the file and calls __exchange_data_block() on overlapping
> source and destination ranges in the same inode, which is the
> data-corruption case the overlap check was meant to reject.
>
> Move the overlap check after the source range has been validated and
> len == 0 has been expanded, so it sees the effective length. This is a
> no-op for non-zero len (the value is unchanged there) and keeps the
> existing early return for identical positions.
>
> Fixes: d95fd91c1ac1 ("f2fs: exclude special cases for f2fs_move_file_range")
> Cc: [email protected]
> Assisted-by: Claude:claude-fable-5
> Signed-off-by: Hao-Qun Huang <[email protected]>
> ---
> diff --git a/fs/f2fs/file.c b/fs/f2fs/file.c
> index 4b52c56d71f0..fdfef01dc799 100644
> --- a/fs/f2fs/file.c
> +++ b/fs/f2fs/file.c
> @@ -3144,8 +3144,6 @@ static int f2fs_move_file_range(struct file *file_in, loff_t pos_in,
> if (src == dst) {
> if (pos_in == pos_out)
> return 0;
> - if (pos_out > pos_in && pos_out < pos_in + len)
> - return -EINVAL;
> }
>
> inode_lock(src);
> @@ -3171,6 +3169,8 @@ static int f2fs_move_file_range(struct file *file_in, loff_t pos_in,
> goto out_unlock;
> if (len == 0)
> olen = len = src->i_size - pos_in;
> + if (src == dst && pos_out > pos_in && pos_out < pos_in + len)
> + goto out_unlock;
Reviewed-by: Chao Yu <[email protected]>
Thanks,
> if (pos_in + len == src->i_size)
> len = ALIGN(src->i_size, F2FS_BLKSIZE) - pos_in;
> if (len == 0) {
_______________________________________________
Linux-f2fs-devel mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/linux-f2fs-devel