mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: Nirmoy Das <nirmoyd@nvidia.com>
To: Amir Goldstein <amir73il@gmail.com>
Cc: Miklos Szeredi <miklos@szeredi.hu>,
	<linux-unionfs@vger.kernel.org>, <linux-kernel@vger.kernel.org>,
	<syzbot+a16fb0cce329a320661c@syzkaller.appspotmail.com>,
	Nirmoy Das <nirmoyd@nvidia.com>
Subject: Re: [RFC PATCH] ovl: keep merged and impure readdir caches separate
Date: Thu, 14 May 2026 05:13:36 -0700	[thread overview]
Message-ID: <20260514121336.439565-1-nirmoyd@nvidia.com> (raw)
In-Reply-To: <CAOQ4uxg+DkTuinnf9AMR6gdHqAydbD88+oBkTtQtABJfdC0vVw@mail.gmail.com>

Hi Amir,

After a lot of debug and traces I found another bug in
ovl_iterate_merged(): err is set from PTR_ERR(cache) before the
IS_ERR(cache) check, so on success err holds the truncated cache
pointer.

Claude generated this: 
  getdents64
  └── iterate_dir(outer_overlay_file)
      └── ovl_iterate_merged                                    [OUTER]
          │
          ├── cache = ovl_cache_get(dentry):                    [OUTER ovl_cache_get]
          │   │   cache_local = kzalloc(...)
          │   │   res = ovl_dir_read_merged(...)
          │   │   │
          │   │   └── iterate_dir(inner_overlay_file)
          │   │       └── ovl_iterate_merged                    [INNER]
          │   │           ├── cache_inner = ovl_cache_get(...)  valid 0xFFFF8881_CAC4D940
          │   │           ├── err = PTR_ERR(cache_inner)        = -893068992 (low32 of ptr)
          │   │           ├── IS_ERR(cache_inner) → FALSE
          │   │           └── return err;                       ← leaked stale int
          │   │
          │   └── return ERR_PTR(res);                          res = -893068992 (int)
          │                                                     sign-extended →
          │                                                     (void *)0xFFFFFFFF_CAC4D940
          │
          ├── err = PTR_ERR(cache);                             err = -893068992
          ├── if (IS_ERR(cache))   ← FALSE: IS_ERR only trips on top 4K
          │                                  (errno window);
          │                                  0xFFFFFFFF_CAC4D940 sits below
          │       return err;                                    ← skipped
          ├── od->cache = cache;   ★ corrupted pointer stored
          └── ovl_seek_cursor(od, ctx->pos)
                  list_for_each(p, &od->cache->entries)
                  p = *(&od->cache->entries) on bad pointer     ★ PAGE FAULT

Sent it as a separate patch: "[PATCH] ovl: keep err zero after
successful ovl_cache_get()".

Let me know what you think.

Regards,
Nirmoy

  reply	other threads:[~2026-05-14 12:14 UTC|newest]

Thread overview: 8+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-05-11  6:20 Nirmoy Das
2026-05-11 20:54 ` Amir Goldstein
2026-05-12 18:27   ` Nirmoy Das
2026-05-12 19:21     ` Amir Goldstein
2026-05-14 12:13       ` Nirmoy Das [this message]
2026-05-14 13:09         ` Amir Goldstein
     [not found]           ` <f9f0e951-a52d-4272-a44e-890d7e7555fa@nvidia.com>
2026-05-14 15:16             ` Amir Goldstein
2026-05-14 21:16               ` Amir Goldstein

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260514121336.439565-1-nirmoyd@nvidia.com \
    --to=nirmoyd@nvidia.com \
    --cc=amir73il@gmail.com \
    --cc=linux-kernel@vger.kernel.org \
    --cc=linux-unionfs@vger.kernel.org \
    --cc=miklos@szeredi.hu \
    --cc=syzbot+a16fb0cce329a320661c@syzkaller.appspotmail.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®