* [PATCH 1/3] Add error handling to minix filesystem for inode corruption detection
2025-11-04 14:30 [PATCH 0/3] Fix two syzbot corruption bugs in minix filesystem Jori Koolstra
@ 2025-11-04 14:30 ` Jori Koolstra
2025-11-04 14:30 ` [PATCH 2/3] Fix a drop_nlink warning in minix_rmdir Jori Koolstra
` (3 subsequent siblings)
4 siblings, 0 replies; 6+ messages in thread
From: Jori Koolstra @ 2025-11-04 14:30 UTC (permalink / raw)
To: Christian Brauner, Tetsuo Handa, Taotao Chen, Jeff Layton,
Jan Kara, NeilBrown
Cc: jkoolstra, linux-kernel
We would like to provide early and specific warnings of filesystem
corruption without running into generic WARN_ONs and BUG_ONs.
Towards this goal, ext4, e.g., has a EFSCORRUPTED errno and a
standardized inode corruption message format. This patch adds this
errno and message format to the minix filesystem.
Signed-off-by: Jori Koolstra <jkoolstra@xs4all.nl>
---
fs/minix/inode.c | 16 ++++++++++++++++
fs/minix/minix.h | 9 +++++++++
2 files changed, 25 insertions(+)
diff --git a/fs/minix/inode.c b/fs/minix/inode.c
index 32db676127a9..7897f5123b3d 100644
--- a/fs/minix/inode.c
+++ b/fs/minix/inode.c
@@ -26,6 +26,22 @@ static int minix_write_inode(struct inode *inode,
struct writeback_control *wbc);
static int minix_statfs(struct dentry *dentry, struct kstatfs *buf);
+void __minix_error_inode(struct inode *inode, const char *function,
+ unsigned int line, const char *fmt, ...)
+{
+ struct va_format vaf;
+ va_list args;
+
+ va_start(args, fmt);
+ vaf.fmt = fmt;
+ vaf.va = &args;
+ printk(KERN_CRIT "minix-fs error (device %s): %s:%d: "
+ "inode #%lu: comm %s: %pV\n",
+ inode->i_sb->s_id, function, line, inode->i_ino,
+ current->comm, &vaf);
+ va_end(args);
+}
+
static void minix_evict_inode(struct inode *inode)
{
truncate_inode_pages_final(&inode->i_data);
diff --git a/fs/minix/minix.h b/fs/minix/minix.h
index d54273c3c9ff..2bfaf377f208 100644
--- a/fs/minix/minix.h
+++ b/fs/minix/minix.h
@@ -42,6 +42,9 @@ struct minix_sb_info {
unsigned short s_version;
};
+void __minix_error_inode(struct inode *inode, const char *function,
+ unsigned int line, const char *fmt, ...);
+
struct inode *minix_iget(struct super_block *, unsigned long);
struct minix_inode *minix_V1_raw_inode(struct super_block *, ino_t, struct buffer_head **);
struct minix2_inode *minix_V2_raw_inode(struct super_block *, ino_t, struct buffer_head **);
@@ -168,4 +171,10 @@ static inline int minix_test_bit(int nr, const void *vaddr)
#endif
+#define minix_error_inode(inode, fmt, ...) \
+ __minix_error_inode((inode), __func__, __LINE__, \
+ (fmt), ##__VA_ARGS__)
+
+#define EFSCORRUPTED EUCLEAN /* Filesystem is corrupted */
+
#endif /* FS_MINIX_H */
--
2.51.2
^ permalink raw reply [flat|nested] 6+ messages in thread* [PATCH 2/3] Fix a drop_nlink warning in minix_rmdir
2025-11-04 14:30 [PATCH 0/3] Fix two syzbot corruption bugs in minix filesystem Jori Koolstra
2025-11-04 14:30 ` [PATCH 1/3] Add error handling to minix filesystem for inode corruption detection Jori Koolstra
@ 2025-11-04 14:30 ` Jori Koolstra
2025-11-04 14:30 ` [PATCH 3/3] Fix a drop_nlink warning in minix_rename Jori Koolstra
` (2 subsequent siblings)
4 siblings, 0 replies; 6+ messages in thread
From: Jori Koolstra @ 2025-11-04 14:30 UTC (permalink / raw)
To: Christian Brauner, Tetsuo Handa, Taotao Chen, Jeff Layton,
Jan Kara, NeilBrown
Cc: jkoolstra, linux-kernel, syzbot+4e49728ec1cbaf3b91d2
Syzbot found a drop_nlink warning that is triggered by an easy to
detect nlink corruption of a directory. This patch adds a sanity check
to minix_rmdir to prevent the warning and instead return EFSCORRUPTED to
the caller.
The changes were tested using the syzbot reproducer as well as local
testing.
Signed-off-by: Jori Koolstra <jkoolstra@xs4all.nl>
Reported-by: syzbot+4e49728ec1cbaf3b91d2@syzkaller.appspotmail.com
Closes: https://syzbot.org/bug?extid=4e49728ec1cbaf3b91d2
---
fs/minix/namei.c | 25 +++++++++++++++++--------
1 file changed, 17 insertions(+), 8 deletions(-)
diff --git a/fs/minix/namei.c b/fs/minix/namei.c
index 8938536d8d3c..68d2dd75b97f 100644
--- a/fs/minix/namei.c
+++ b/fs/minix/namei.c
@@ -161,15 +161,24 @@ static int minix_unlink(struct inode * dir, struct dentry *dentry)
static int minix_rmdir(struct inode * dir, struct dentry *dentry)
{
struct inode * inode = d_inode(dentry);
- int err = -ENOTEMPTY;
-
- if (minix_empty_dir(inode)) {
- err = minix_unlink(dir, dentry);
- if (!err) {
- inode_dec_link_count(dir);
- inode_dec_link_count(inode);
- }
+ int err = -EFSCORRUPTED;
+
+ if (dir->i_nlink <= 2) {
+ minix_error_inode(dir, "inode has corrupted nlink");
+ goto out;
+ }
+
+ err = -ENOTEMPTY;
+ if (!minix_empty_dir(inode))
+ goto out;
+
+ err = minix_unlink(dir, dentry);
+ if (!err) {
+ inode_dec_link_count(dir);
+ inode_dec_link_count(inode);
}
+
+out:
return err;
}
--
2.51.2
^ permalink raw reply [flat|nested] 6+ messages in thread* [PATCH 3/3] Fix a drop_nlink warning in minix_rename
2025-11-04 14:30 [PATCH 0/3] Fix two syzbot corruption bugs in minix filesystem Jori Koolstra
2025-11-04 14:30 ` [PATCH 1/3] Add error handling to minix filesystem for inode corruption detection Jori Koolstra
2025-11-04 14:30 ` [PATCH 2/3] Fix a drop_nlink warning in minix_rmdir Jori Koolstra
@ 2025-11-04 14:30 ` Jori Koolstra
2025-11-04 14:50 ` [PATCH 0/3] Fix two syzbot corruption bugs in minix filesystem Jan Kara
2025-11-05 12:45 ` Christian Brauner
4 siblings, 0 replies; 6+ messages in thread
From: Jori Koolstra @ 2025-11-04 14:30 UTC (permalink / raw)
To: Christian Brauner, Tetsuo Handa, Taotao Chen, Jeff Layton,
Jan Kara, NeilBrown
Cc: jkoolstra, linux-kernel, syzbot+a65e824272c5f741247d
Syzbot found a drop_nlink warning that is triggered by an easy to
detect nlink corruption. This patch adds sanity checks to minix_unlink
and minix_rename to prevent the warning and instead return EFSCORRUPTED
to the caller.
The changes were tested using the syzbot reproducer as well as local
testing.
Signed-off-by: Jori Koolstra <jkoolstra@xs4all.nl>
Reported-by: syzbot+a65e824272c5f741247d@syzkaller.appspotmail.com
Closes: https://syzbot.org/bug?extid=a65e824272c5f741247d
---
fs/minix/namei.c | 16 ++++++++++++++++
1 file changed, 16 insertions(+)
diff --git a/fs/minix/namei.c b/fs/minix/namei.c
index 68d2dd75b97f..263e4ba8b1c8 100644
--- a/fs/minix/namei.c
+++ b/fs/minix/namei.c
@@ -145,6 +145,11 @@ static int minix_unlink(struct inode * dir, struct dentry *dentry)
struct minix_dir_entry * de;
int err;
+ if (inode->i_nlink == 0) {
+ minix_error_inode(inode, "inode has corrupted nlink");
+ return -EFSCORRUPTED;
+ }
+
de = minix_find_entry(dentry, &folio);
if (!de)
return -ENOENT;
@@ -217,6 +222,17 @@ static int minix_rename(struct mnt_idmap *idmap,
if (dir_de && !minix_empty_dir(new_inode))
goto out_dir;
+ err = -EFSCORRUPTED;
+ if (new_inode->i_nlink == 0 || (dir_de && new_inode->i_nlink != 2)) {
+ minix_error_inode(new_inode, "inode has corrupted nlink");
+ goto out_dir;
+ }
+
+ if (dir_de && old_dir->i_nlink <= 2) {
+ minix_error_inode(old_dir, "inode has corrupted nlink");
+ goto out_dir;
+ }
+
err = -ENOENT;
new_de = minix_find_entry(new_dentry, &new_folio);
if (!new_de)
--
2.51.2
^ permalink raw reply [flat|nested] 6+ messages in thread* Re: [PATCH 0/3] Fix two syzbot corruption bugs in minix filesystem
2025-11-04 14:30 [PATCH 0/3] Fix two syzbot corruption bugs in minix filesystem Jori Koolstra
` (2 preceding siblings ...)
2025-11-04 14:30 ` [PATCH 3/3] Fix a drop_nlink warning in minix_rename Jori Koolstra
@ 2025-11-04 14:50 ` Jan Kara
2025-11-05 12:45 ` Christian Brauner
4 siblings, 0 replies; 6+ messages in thread
From: Jan Kara @ 2025-11-04 14:50 UTC (permalink / raw)
To: Jori Koolstra
Cc: Christian Brauner, Tetsuo Handa, Taotao Chen, Jeff Layton,
Jan Kara, NeilBrown, linux-kernel
On Tue 04-11-25 15:30:02, Jori Koolstra wrote:
> Syzbot fuzzes /fs by trying to mount and manipulate deliberately
> corrupted filesystems. This should not lead to BUG_ONs and WARN_ONs for
> easy to detect corruptions. This series adds code to be able to report
> such corruptions and fixes two syzbot bugs on this kind.
>
> Jori Koolstra (3):
> Add error handling to minix filesystem for inode corruption detection
> Fix a drop_nlink warning in minix_rmdir
> Fix a drop_nlink warning in minix_rename
The series looks good to me. Feel free to add:
Reviewed-by: Jan Kara <jack@suse.cz>
Honza
>
> fs/minix/inode.c | 16 ++++++++++++++++
> fs/minix/minix.h | 9 +++++++++
> fs/minix/namei.c | 39 ++++++++++++++++++++++++++++++++-------
> 3 files changed, 57 insertions(+), 7 deletions(-)
>
> --
> 2.51.2
>
--
Jan Kara <jack@suse.com>
SUSE Labs, CR
^ permalink raw reply [flat|nested] 6+ messages in thread* Re: [PATCH 0/3] Fix two syzbot corruption bugs in minix filesystem
2025-11-04 14:30 [PATCH 0/3] Fix two syzbot corruption bugs in minix filesystem Jori Koolstra
` (3 preceding siblings ...)
2025-11-04 14:50 ` [PATCH 0/3] Fix two syzbot corruption bugs in minix filesystem Jan Kara
@ 2025-11-05 12:45 ` Christian Brauner
4 siblings, 0 replies; 6+ messages in thread
From: Christian Brauner @ 2025-11-05 12:45 UTC (permalink / raw)
To: Jori Koolstra
Cc: Christian Brauner, linux-kernel, Tetsuo Handa, Taotao Chen,
Jeff Layton, Jan Kara, NeilBrown
On Tue, 04 Nov 2025 15:30:02 +0100, Jori Koolstra wrote:
> Syzbot fuzzes /fs by trying to mount and manipulate deliberately
> corrupted filesystems. This should not lead to BUG_ONs and WARN_ONs for
> easy to detect corruptions. This series adds code to be able to report
> such corruptions and fixes two syzbot bugs on this kind.
>
> Jori Koolstra (3):
> Add error handling to minix filesystem for inode corruption detection
> Fix a drop_nlink warning in minix_rmdir
> Fix a drop_nlink warning in minix_rename
>
> [...]
Applied to the vfs-6.19.minix branch of the vfs/vfs.git tree.
Patches in the vfs-6.19.minix branch should appear in linux-next soon.
Please report any outstanding bugs that were missed during review in a
new review to the original patch series allowing us to drop it.
It's encouraged to provide Acked-bys and Reviewed-bys even though the
patch has now been applied. If possible patch trailers will be updated.
Note that commit hashes shown below are subject to change due to rebase,
trailer updates or similar. If in doubt, please check the listed branch.
tree: https://git.kernel.org/pub/scm/linux/kernel/git/vfs/vfs.git
branch: vfs-6.19.minix
[1/3] Add error handling to minix filesystem for inode corruption detection
https://git.kernel.org/vfs/vfs/c/21215ce7a95a
[2/3] Fix a drop_nlink warning in minix_rmdir
https://git.kernel.org/vfs/vfs/c/d3e0e8661ceb
[3/3] Fix a drop_nlink warning in minix_rename
https://git.kernel.org/vfs/vfs/c/009a2ba40303
^ permalink raw reply [flat|nested] 6+ messages in thread