From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-pg1-f176.google.com (mail-pg1-f176.google.com [209.85.215.176]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 4509B21767D for ; Sun, 7 Jun 2026 05:17:29 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.215.176 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1780809450; cv=none; b=lV9rDO9Vouf+uZOncUXgGNnITgnuj2+CPpYfWabrMUvHqbOk8Z3b7jatldm3Ijq8vfPucFgvD7WIbuATcGmqqh7GPL4E9s0tYK8kJNQ4iGBqXHwN8x/vPEvWmyc7Pkr4fIzljkRcFCLaNbtyXRgpPa8Q61jXsPGyRmxGCDp2IaA= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1780809450; c=relaxed/simple; bh=BzcwqwmkbuNr2Myu7m9WfZdIqMCu8JCUo6H4qhFJ0FE=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=RV3qwW6PvFiT7zJSOpmpiC1YCvT2A7/dubYbez4huBTs8vpR9x85KqKjibBSKMpcwJ6hq1oHdkqFrxb1u5rLQLpcoIEf9ob1tYC5zsOtVZ8TowRdbtl9JlqGCgcWKAweetFKNazeXccgthDrixs4fiR7jnNYfh/nF6t58ogIx/A= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=kTCUKbcx; arc=none smtp.client-ip=209.85.215.176 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="kTCUKbcx" Received: by mail-pg1-f176.google.com with SMTP id 41be03b00d2f7-c862186ccaaso4968a12.3 for ; Sat, 06 Jun 2026 22:17:29 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1780809448; x=1781414248; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to; bh=mKWyZ9RL9JnW73ObQxrP4w2rasSr9tGKj3O0aXlEuyk=; b=kTCUKbcxOXQyLslfOlod8raW9+5LJ98ehTeQ/xLiW/Dmd52hW7ZXDYPnVlwI/j7kNw OpnFNsVc9itwcnQRJFj5be1rEawFCO8Sw7sTpLeK5Cjf8hFZyZJj6T9SwFGuSqevbZAn 20qwRtj4WcPiOufOnWHSV0E49PurlU/tkBOPVxhKaeYQD5NNvhTkSe1OZvU6ovn7pvM+ QiG0J7Bwry+VH99bF4KwttVVLhdsiiKGojqdnJoyivWmWmnX1LDws6Gt+85d15H/Jysm gE3M+LmDKbIsmpu3CaP8aID0YUUaZapLNjpex06UinEdN3BwBvfy2cJnQbeEFC3VKZFq crZw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1780809448; x=1781414248; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to; bh=mKWyZ9RL9JnW73ObQxrP4w2rasSr9tGKj3O0aXlEuyk=; b=bE+H7M+7UqcUrJTdzynKZSPi4Nsw8hn118LyzP+bJtd8xtEXQSPvl+/M69hI56UPhc G5n8fugT5bsB3nHIv8I84ZdbXzYx+Ua52cszfc5vH5QEgURGlkwYAHSDIstwsUVWguJS KI6nXrrBw6ASv/h/Ezdn2d6i2lR1sIpvihjVBp3mq6ISeHIn/tnLQ7oAoxgy0Pk+ryTY N+hxw2Paks0ZpJplZrjNZAyJ5HQl/r/RtgvM6MtlZf2FpfNh+oT2K+WtNb2coxYcZPMS ZxtSd2P8WO/F06qdjm9i9/lJMxBaT3Zd98WofDUtvTgKkVk0m+/r57G4uhnWpJM0sjnr J78w== X-Forwarded-Encrypted: i=1; AFNElJ+yiqB2BQhIImDRp9uWqWU7QHSOOpZZy/Fp1gcju/GNa8L99Wmspe50OFP9lNi1Z38ndXIIdF5bQQXeoMM=@vger.kernel.org X-Gm-Message-State: AOJu0YzZjO18bAF476KDANlVgWuiHwWXDcxjIBjls6QWPGkM5roV+Us7 D1gAszOOFvYCfe7Dv2Khlm/qvfWnzX72D0l57TsS4RJvlrzR0pB7Ob7B X-Gm-Gg: Acq92OGeQr7kZuVkXmN/X8uxRTky0yKlaetmugP6nrVkMLrplQUHmVAC5f4e7Ppk+XB RNFCPufLXvJPzjeMnn10ES9TWdByOvlizs1flexAuh1qDrUnP9OrVt9Q9FQlbsk3WGUJazcuRGQ v2Aa+5I4jvpo42SKCR4UueMOe60ccF3g5V18OOZSk7v20clOzMg2lnkOJXzCCh2IcC4xYl7FONk xJPyjOolATW3kmR6mF6kmO2TsbJ2wMEJEywYdrsttCRsp3glFGNqRS8jylH820kQYdIhrodEwJD PMuWx87GDOKMOKGSjm1SCS/Sh1O0OrEPAQWSThYZ3CQujkHQbbjMQry44JUCW41pIt7bzt2ulKn Ic6z8SY9Ar3GJDPtAn4z73FYZ98I6aYeLe7ifyHKzNTWJNr5C9e3tfkNWvlUYAxHSky3TlWtiF7 lEBd9XWwYqCEcJ99th7mRaW84Gg5U= X-Received: by 2002:a05:6a00:1146:b0:842:5a15:6fa6 with SMTP id d2e1a72fcca58-842b0e8decfmr4577687b3a.3.1780809448349; Sat, 06 Jun 2026 22:17:28 -0700 (PDT) Received: from ser8.. ([221.156.231.192]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-842828e5638sm14494648b3a.50.2026.06.06.22.17.26 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sat, 06 Jun 2026 22:17:27 -0700 (PDT) From: DaeMyung Kang To: Namjae Jeon , Hyunchul Lee Cc: linux-fsdevel@vger.kernel.org, linux-kernel@vger.kernel.org, DaeMyung Kang Subject: [PATCH v5 0/4] ntfs: finish index root lookup validation Date: Sun, 7 Jun 2026 14:17:19 +0900 Message-ID: <20260607051723.1499833-1-charsyam@gmail.com> X-Mailer: git-send-email 2.43.0 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit This v5 is based on the current linux-ntfs ntfs-next branch at commit c864077b8d73 ("ntfs: use d_splice_alias() for ->lookup() return value"). That branch already contains v4 patches 1/6 through 4/6, the ntfs_readdir() index-root entries_offset validation, and the initial resident $INDEX_ROOT lookup validator. This series does not resend those applied patches. The extent inode lifetime fix is independent of this attribute validation work and is not included in this series. The merged lookup-time $INDEX_ROOT validator does not yet validate index.allocated_size. Enabling that check exposed a generic/013 failure in earlier testing because ntfs_ir_reparent() could publish a larger resident root header before growing the resident value. In the failing case, the root had value_len=48, index_size=32, index_length=40, and allocated_size=40, so allocated_size validation correctly rejected the transient layout and ntfsprogs-plus ntfsck reported a corrupt index root. Patches 2 and 3 are the prerequisite resize-ordering fixes for enabling that allocated_size validation: patch 2 fixes the grow side, and patch 3 keeps the shrink side consistent for the same validator. Patch 1 also finishes the lookup contract for resident-only attributes. The current shared validator rejects non-resident $FILE_NAME and $VOLUME_NAME records, but other resident-only attribute types can still pass the non-resident path. That is unsafe for callers such as $STANDARD_INFORMATION and $VOLUME_INFORMATION users that read data.resident.value_offset after lookup, and it also makes the $INDEX_ROOT lookup contract incomplete. The patch factors the existing checks into a resident-only helper and extends it to the remaining resident-only types. Patch 4 extends the merged $INDEX_ROOT validator to check index.allocated_size. The driver does consume root index.allocated_size as the capacity field in ntfs_ie_add() when deciding whether an insert can be done in place, and ntfs_ie_insert() does not re-check that boundary. The validation only rejects layouts where allocated_size extends past the resident value; valid slack remains allowed as index_length <= allocated_size <= the resident index area. The current series applies cleanly to linux-ntfs ntfs-next commit c864077b8d73 ("ntfs: use d_splice_alias() for ->lookup() return value") with `git am -p3`. checkpatch.pl --strict and git diff --check were clean. The same final validator and resize-ordering changes were also tested on the earlier clean v4 application stack used for runtime testing. A KASAN kernel with CONFIG_NTFS_FS=y built successfully, and KASAN generic/013 passed three consecutive runs. ntfsprogs-plus ntfsck v1.0.0, built from ntfsprogs-plus revision 53943dae, reported the three resulting generic/013 test images clean with `ntfsck -n` (errors:0, fixed:0). Changes since v4: - Do not resend v4 patches 1/6 through 4/6, which have already been applied. - Add a resident-only attribute helper and reject non-resident records for the remaining resident-only attribute types. - Add the ntfs_ir_reparent() grow-before-header fix required before enabling the allocated_size part of the $INDEX_ROOT validator. - Keep the ntfs_ir_truncate() shrink-ordering fix, now framed as the shrink-side consistency fix for lookup-time $INDEX_ROOT validation. - Rework the final patch as an incremental allocated_size check for the $INDEX_ROOT validator already merged in ntfs-next. DaeMyung Kang (4): ntfs: reject non-resident records for resident-only attributes ntfs: grow index root value before reparent header update ntfs: update index root allocated size before shrink ntfs: validate index root allocated_size on lookup fs/ntfs/attrib.c | 24 ++++++++++++++-- fs/ntfs/index.c | 96 ++++++++++++++++++++++++++++++++++++++++++---------------------- 2 files changed, 85 insertions(+), 35 deletions(-) -- 2.43.0