[PATCH] ext4: defend against inline-to-block conversion race in write completion

Deepanshu Kartikey <[email protected]>
Newsgroups org.kernel.vger.linux-ext4,org.kernel.vger.linux-kernel
Message-ID <[email protected]>
Replace BUG_ON(!ext4_has_inline_data(inode)) with defensive error handling
in ext4_write_inline_data_end(). A file can be converted from inline to block
storage by concurrent paths while a write completion is in flight.

Lock-based synchronization is impractical here since multiple conversion paths
use different locks. Defensive check with proper cleanup
handles all races uniformly and safely.

Reported-by: [email protected]
Closes: https://syzkaller.appspot.com/bug?extid=293a57918b36cfae3d48
Tested-by: [email protected]
Signed-off-by: Deepanshu Kartikey <[email protected]>
---
 fs/ext4/inline.c | 9 ++++++++-
 1 file changed, 8 insertions(+), 1 deletion(-)

diff --git a/fs/ext4/inline.c b/fs/ext4/inline.c
index 8045e4ff270c..53d783235da9 100644
--- a/fs/ext4/inline.c
+++ b/fs/ext4/inline.c
@@ -812,7 +812,14 @@ int ext4_write_inline_data_end(struct inode *inode, loff_t pos, unsigned len,
 			goto out;
 		}
 		ext4_write_lock_xattr(inode, &no_expand);
-		BUG_ON(!ext4_has_inline_data(inode));
+		/* File may have been converted to block storage by concurrent path */
+		if (!ext4_has_inline_data(inode)) {
+			ext4_write_unlock_xattr(inode, &no_expand);
+			brelse(iloc.bh);
+			folio_unlock(folio);
+			folio_put(folio);
+			return -EIO;
+		}
 
 		/*
 		 * ei->i_inline_off may have changed since
-- 
2.43.0
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.