From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from us-smtp-delivery-124.mimecast.com (us-smtp-delivery-124.mimecast.com [170.10.133.124]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 2DF953E92BF for ; Tue, 31 Mar 2026 18:08:37 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=170.10.133.124 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1774980519; cv=none; b=GTrYght4LI6Z/NTMIksgkVaBnjHTqDw+uZ7Q2LLExVynoJYhP7T9fPBvhuCzzFxHS5SX4FT+KMIzqDBL1WHmhaZJhfM7NdLtag1rASydevI83JOCHeeex6dWKZhtHecO6EJnZNx9eJS3VZ7xVQE6wV4MZtgLtGs+vrPB1LobjLA= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1774980519; c=relaxed/simple; bh=1kD0roxkx1+TVNYYI9k7IMM/P/inOyXLGaIk+M5AVqE=; h=Message-ID:Subject:From:To:Cc:Date:In-Reply-To:References: Content-Type:MIME-Version; b=aB+iBHzjeU9mIX5N7cxDrvhypeFUsNousOvcwUQ/get/lGr/bae9ese0zpdrL2XPCsTUT0MgSEmc0XaAvu7LQIk0qAZaGZ5LAaM9WNJF1arX82qT8429Au7sh3g/YI428Y1dQ6YkBcn99vDVFoVLM4eU+Y/D3IL7YnS7ZH4Zdik= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com; spf=pass smtp.mailfrom=redhat.com; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b=URaPSjNe; dkim=pass (2048-bit key) header.d=redhat.com header.i=@redhat.com header.b=R5aS4wDu; arc=none smtp.client-ip=170.10.133.124 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=redhat.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b="URaPSjNe"; dkim=pass (2048-bit key) header.d=redhat.com header.i=@redhat.com header.b="R5aS4wDu" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1774980517; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=gc8jHqZGP3DLxPp9zRxMRoVIMkUBfZYmJnOTc8sLpsA=; b=URaPSjNexFu0UUdpIr9LWprCeDdqr6G0hhs/8RKAc91oj1A4EdgGBEItk2XqM/9aJFV1d1 UlPbdB4/AJikNJVTalGGGTdV2wTmn507uHrtNvYoYD3pGYYN8BSyRn7m/f6YApPc1gTmWh kUGt4hOSIaZZUyTEJm/YxGI2IpMmUNk= Received: from mail-yx1-f69.google.com (mail-yx1-f69.google.com [74.125.224.69]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-522-f6cLpYWaNh2Su2iOY0d7ug-1; Tue, 31 Mar 2026 14:08:35 -0400 X-MC-Unique: f6cLpYWaNh2Su2iOY0d7ug-1 X-Mimecast-MFC-AGG-ID: f6cLpYWaNh2Su2iOY0d7ug_1774980515 Received: by mail-yx1-f69.google.com with SMTP id 956f58d0204a3-65019e029c1so7447167d50.0 for ; Tue, 31 Mar 2026 11:08:35 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=google; t=1774980514; x=1775585314; darn=vger.kernel.org; h=mime-version:user-agent:content-transfer-encoding:references :in-reply-to:date:cc:to:from:subject:message-id:from:to:cc:subject :date:message-id:reply-to; bh=gc8jHqZGP3DLxPp9zRxMRoVIMkUBfZYmJnOTc8sLpsA=; b=R5aS4wDukvDrOKsXJTTzIfYLELGYg2shiuoYSgga+jGkaED/3SyP/nCwbF0CVtkhhw /2aBC8jLdZqlap/exr4M7eaemhELCyn5fgZn9iLF63B+r9t6iHSVEQzNf3Yzsikvs9ym b5sgba4Lkir7y1AR6I7l9m8vxTGyxbBdZtKLc4pXBPrpXY5ymbS165h93od7/X3JUtOB yjsnDh1/l9CfPeyVaM9DXpxuK7eFPYXJeNpnTG07UEHXe4JL6LlFl0L23JiIQOYmU74T e4jyPbVgKzVMXX+FpsuIUDASjGMXAc9COvE9YyYw6eoS2u/ns3P09Y98U1Mw94mYCdtO zF6w== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1774980514; x=1775585314; h=mime-version:user-agent:content-transfer-encoding:references :in-reply-to:date:cc:to:from:subject:message-id:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to; bh=gc8jHqZGP3DLxPp9zRxMRoVIMkUBfZYmJnOTc8sLpsA=; b=n/4rUoITQvEvrhAgWMQHz2wW94cQk7lxpBaUP6s0Awqr8rv+GhexZlX/19eVAyJKiU MWHubsg6+R/EybOnyhiHUC1PVVY6HUt9rIpgE1t9S1f2+b4UXXpB8p6uy9SbIjNihuDG mLUiJY3A9rf/WHx6uHezjD4AngKjSrt2kWrA4j8S4VnNmheZuyEuEFnF4Ap1Et1wavM+ BlDaylpyNEhw4UjgF1n/WRbLMUTegtmloWj75JB/2GZqnWyCWf8nRlqsJGcwbGT1Q6c3 JuQAJp+L2uHkjzphzAXnRF2IQFu3B2P86L7tHWyTZWPdb9jFusaM4ModKJxpmIobmKgC ZWfg== X-Forwarded-Encrypted: i=1; AJvYcCVtcVqoZio+EVNuPx+Cy1MGjjjEQAr3O1FCe1Rwgkxtci3uoWpaaToQd0XtFdGNz+N+NsZbRySxesjwN48=@vger.kernel.org X-Gm-Message-State: AOJu0Yw0uXlbCyCLOS2cV5hEs97V0IHU9yFedmHcYoseYr20G8QnSsUV oKvvGT+UEwW+uEw2WhWqcCAc/Gfae6ifUaUg1VdpUfVy3u/9T5KpnKmOOl31R21JpoB9UkWzm0w 0bMnM9XwuAbGrMMcBsyeXiRm5QDkj7js9S7Reo2ewZZEslGvO8UxwU8ds2n29aecZeQ== X-Gm-Gg: ATEYQzxjwjJAVWtZ5SWj/KtVRyZnnUzRSbDXiavsuzi1hzz4brWpPYz7z9YCOBk/Tpf 3UCR6ZfMPBPtA6Dyv0AZx0n4K7CxG6P7yZmsGaLDj/KuUEMSAytNpnZM211zeF5JWFmO38e38+L CdOclJuT8/0162nfEJ5WOsqMJgWOZsGomMvg4ztBuTi0/2U9OM96KyhIpoYcGemPY7d+fCYUT6d rxACYi0lTbdA3GjXDuK/ipjjFjT+4chmiM2kR7FyiFw72Jjh5JZS0x54oaGvHo76RVgOL2SJnhW bz4VpidtN791l5eHVBZS1IjbRRlAZy4uGe3qLnRFWzKb3OeU51c2W7UX4wJu9GD3sINtZEv38pZ 1OudX74xZgBicVG5xHUNQepOSyyRj261aK8T6dcrxmXIYGuN9qqu2 X-Received: by 2002:a05:690c:6a0e:b0:79a:20a5:6f60 with SMTP id 00721157ae682-7a20fcd658emr4782747b3.14.1774980514638; Tue, 31 Mar 2026 11:08:34 -0700 (PDT) X-Received: by 2002:a05:690c:6a0e:b0:79a:20a5:6f60 with SMTP id 00721157ae682-7a20fcd658emr4782307b3.14.1774980514083; Tue, 31 Mar 2026 11:08:34 -0700 (PDT) Received: from li-4c4c4544-0032-4210-804c-c3c04f423534.ibm.com ([2600:1700:6476:1430::29]) by smtp.gmail.com with ESMTPSA id 956f58d0204a3-650093288a1sm5926796d50.11.2026.03.31.11.08.33 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 31 Mar 2026 11:08:33 -0700 (PDT) Message-ID: <0f939206680b19e02ac5a5f11fe0f6c70afd6c06.camel@redhat.com> Subject: Re: [PATCH] nilfs2: reject zero bd_oblocknr in nilfs_ioctl_mark_blocks_dirty() From: Viacheslav Dubeyko To: Ryusuke Konishi , Viacheslav Dubeyko Cc: linux-nilfs , LKML , Deepanshu Kartikey , Junjie Cao Date: Tue, 31 Mar 2026 11:08:32 -0700 In-Reply-To: <20260331175253.32329-1-konishi.ryusuke@gmail.com> References: <20260331175253.32329-1-konishi.ryusuke@gmail.com> Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable User-Agent: Evolution 3.58.3 (3.58.3-1.fc43app2) Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Hi Ryusuke, On Wed, 2026-04-01 at 02:52 +0900, Ryusuke Konishi wrote: > From: Deepanshu Kartikey >=20 > nilfs_ioctl_mark_blocks_dirty() uses bd_oblocknr to detect dead blocks > by comparing it with the current block number bd_blocknr. If they differ, > the block is considered dead and skipped. >=20 > However, bd_oblocknr should never be 0 since block 0 typically stores the > primary superblock and is never a valid GC target block. A corrupted ioct= l > request with bd_oblocknr set to 0 causes the comparison to incorrectly > match when the lookup returns -ENOENT and sets bd_blocknr to 0, bypassing > the dead block check and calling nilfs_bmap_mark() on a non-existent > block. This causes nilfs_btree_do_lookup() to return -ENOENT, triggering > the WARN_ON(ret =3D=3D -ENOENT). >=20 > Fix this by rejecting ioctl requests with bd_oblocknr set to 0 at the > beginning of each iteration. >=20 > [ryusuke: slightly modified the commit message and comments for accuracy] >=20 > Fixes: 7942b919f732 ("nilfs2: ioctl operations") > Reported-by: syzbot+98a040252119df0506f8@syzkaller.appspotmail.com > Closes: https://syzkaller.appspot.com/bug?extid=3D98a040252119df0506f8 > Suggested-by: Ryusuke Konishi > Signed-off-by: Deepanshu Kartikey > Reported-by: syzbot+466a45fcfb0562f5b9a0@syzkaller.appspotmail.com > Closes: https://syzkaller.appspot.com/bug?extid=3D466a45fcfb0562f5b9a0 > Cc: Junjie Cao > Signed-off-by: Ryusuke Konishi > --- > Hi Viacheslav, >=20 > Please add this to the queue for the next cycle. This fixes assertion > failures that can occur with broken GC ioctl calls recently discovered > by syzbot. >=20 > Thanks, > Ryusuke Konishi >=20 > fs/nilfs2/ioctl.c | 6 ++++++ > 1 file changed, 6 insertions(+) >=20 > diff --git a/fs/nilfs2/ioctl.c b/fs/nilfs2/ioctl.c > index e17b8da66491..e0a606643e87 100644 > --- a/fs/nilfs2/ioctl.c > +++ b/fs/nilfs2/ioctl.c > @@ -736,6 +736,12 @@ static int nilfs_ioctl_mark_blocks_dirty(struct the_= nilfs *nilfs, > int ret, i; > =20 > for (i =3D 0; i < nmembs; i++) { > + /* > + * bd_oblocknr must never be 0 as block 0 > + * is never a valid GC target block > + */ > + if (unlikely(!bdescs[i].bd_oblocknr)) > + return -EINVAL; > /* XXX: use macro or inline func to check liveness */ > ret =3D nilfs_bmap_lookup_at_level(bmap, > bdescs[i].bd_offset, Applied on for-next branch of NILFS2 git tree. Thanks, Slava.