]> git.ipfire.org Git - thirdparty/kernel/linux.git/commit
ntfs3: fix circular locking dependency in run_unpack_ex
authorSzymon Wilczek <swilczek.lx@gmail.com>
Sat, 27 Dec 2025 14:43:07 +0000 (15:43 +0100)
committerKonstantin Komarov <almaz.alexandrovich@paragon-software.com>
Thu, 15 Jan 2026 04:57:48 +0000 (05:57 +0100)
commit08ce2fee1b869ecbfbd94e0eb2630e52203a2e03
tree9dbb6de88001b1745c7b0615a74bb282d9340335
parent099ef9ab9203dff327f2d61e44773f9acbc01f13
ntfs3: fix circular locking dependency in run_unpack_ex

Syzbot reported a circular locking dependency between wnd->rw_lock
(sbi->used.bitmap) and ni->file.run_lock.

The deadlock scenario:
1. ntfs_extend_mft() takes ni->file.run_lock then wnd->rw_lock.
2. run_unpack_ex() takes wnd->rw_lock then tries to acquire
   ni->file.run_lock inside ntfs_refresh_zone().

This creates an AB-BA deadlock.

Fix this by using down_read_trylock() instead of down_read() when
acquiring run_lock in run_unpack_ex(). If the lock is contended,
skip ntfs_refresh_zone() - the MFT zone will be refreshed on the
next MFT operation. This breaks the circular dependency since we
never block waiting for run_lock while holding wnd->rw_lock.

Reported-by: syzbot+d27edf9f96ae85939222@syzkaller.appspotmail.com
Tested-by: syzbot+d27edf9f96ae85939222@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=d27edf9f96ae85939222
Signed-off-by: Szymon Wilczek <swilczek.lx@gmail.com>
Signed-off-by: Konstantin Komarov <almaz.alexandrovich@paragon-software.com>
fs/ntfs3/run.c