From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-qv1-f41.google.com (mail-qv1-f41.google.com [209.85.219.41]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 9DAB13A6B8A for ; Fri, 12 Jun 2026 23:41:41 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.219.41 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1781307702; cv=none; b=h7lP40XXHvP8MNaMS/aIdn0/8Lm2owoBWZ+RY/hp7MdO7wpwPZpbMq5zvmC7sZpBvwo4aPhCtJPu6LC2YQihoHdqHf3ch2jeAI0IN3K7BRMO+PipokMNKg0YR7SS84ZtlWrZq5q0HfA5zSysSwXvUbecPBmU8G4cvQ5Ps3ycDyw= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1781307702; c=relaxed/simple; bh=3k5EOV2H7Ew1pBeahoyYXsJrMNLueDRTtGteJGX5rq8=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=mV7KeWG0mYD47GTgoyvq89ZSu7pztbkIE3BwiLsgmRDnWIAwvSfAxwk1N5FZ1LW7v6Z5YC31A8sLLf/BVQD9+mNCsRoqZtUy/TUN1l4iFaMeSyr9SFz6KUTAnfUVsWMQS0fIDXu2KUXLmMff8G1ypX5/9tYb88FzACZ2eVxhgsg= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=openai.com; spf=pass smtp.mailfrom=openai.com; dkim=pass (1024-bit key) header.d=openai.com header.i=@openai.com header.b=IxCUT53V; arc=none smtp.client-ip=209.85.219.41 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=openai.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=openai.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=openai.com header.i=@openai.com header.b="IxCUT53V" Received: by mail-qv1-f41.google.com with SMTP id 6a1803df08f44-8ce9e56f68cso12495776d6.2 for ; Fri, 12 Jun 2026 16:41:41 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=openai.com; s=google; t=1781307700; x=1781912500; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to; bh=64IeahYqMleypy9da2mixo6bk83c69QHdNbzudLxr7k=; b=IxCUT53V4bwP4f7aEI3+uDjh6ARWaFiH4+GAq9GQSZbNDIz1Q7wB9KaHDzDu0cPZ+f 6mTOFZBve98lu7tf6LQXfTvDn8KZfqYqM3EKkf1vpDq8N+jDMm1Yw+dooXxD+X32pk+5 csnWcnaWjQIjbxF2C5xElA7nSpZxjTjJXRTQ4= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1781307700; x=1781912500; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to; bh=64IeahYqMleypy9da2mixo6bk83c69QHdNbzudLxr7k=; b=MBuom6qak7sSkJMSZY0hr0AlvDV1a1VZZ6Lq0yQ+7A75lEJSwx5chhAv3zQHCjXmGO s5pzXYIFeI06l49eVHH7n7pyzxOa72BK7X+tfcll4KGTL3ugf1C9+Tw7uRkLPAEJu4Tt ds4IwUB4Q37t0AvTQ7eofHeK9g1nq3VxxmNe+OKr3FB9n8vSit9r5D/V5dqd3Ffx8Gxb Dfj3VSDsOPtSm2AECDvwOWGlGxBznMybw8mDvzn1QoReTbFVoFzW6ue8eqv9OisKOo2x uCNxHAQUr571BDgzMkghhmKgjqev+WnYFxfS313NFof6HAbzg7sUbd2BVYz+4eamz5rV bdPQ== X-Gm-Message-State: AOJu0YysxAthBxXfHi3KzqZ42sfKtBa61BdDdEU9x0n62BOr5x8FFTq0 U4mWs9F8HXE8aRliTshtYxyt9A1UnnWeL/gHQgeVmBTQeEemia21who+ISQd7eXl9VE= X-Gm-Gg: Acq92OFBvgxzMOxLRthLUDJOQkCcXaTcmYuMBFT033zOPFcDulXUPoMKVq5IB9NWBeD 3jvviBlmYWdBJFLrdYH7hb23jNd5MveyopyLA9RbmJl7p41luonBVx6us2cZJk52cb/MBqzPsK/ 7yCpGjIgZac9IaQ1orGV77vdF2RBMkruw81HDZo+a9Nxf/4o5c1fJcLqa/57CBnMV38LgTz668j remLeOR6EBGQ/ifDLAM85IHiaoCtDq9K5oRDBgaIyaK5pYHVFqsF+dUMII5hlsFk1b/6Zuqk+zm 5Hgh166aBJikeJnsNE0lThi0pkegGI5srFnWAyUMRWJxJuqj2gXRi8k07sLm2SxMIxoXUE5/75P m9X4jvEoDZ75gJBjAfBE4nR9Sa54WpoZy7n5lIRwv/4bU5PanUffdwhaKqwlX9SoDmk22kZfWH7 6RMBfkx+/5xd40X86o4NitTfoaPM9x4XkMcjeQC/+EDTvPZPlZJ3C8c0D9JTSA0VtZ4dxmIfROE hScUkCoMZHE5cwmjmadL5CsbYNOYndn4VE= X-Received: by 2002:a05:6214:238a:b0:8ce:ba08:fbe6 with SMTP id 6a1803df08f44-8d32eadaa55mr90575206d6.40.1781307700413; Fri, 12 Jun 2026 16:41:40 -0700 (PDT) Received: from com-75606.node.ndb.openai.org ([209.249.37.149]) by smtp.gmail.com with ESMTPSA id 6a1803df08f44-8d300f6b1c5sm38296276d6.3.2026.06.12.16.41.39 (version=TLS1_3 cipher=TLS_CHACHA20_POLY1305_SHA256 bits=256/256); Fri, 12 Jun 2026 16:41:40 -0700 (PDT) From: Kyle Zeng To: jfs-discussion@lists.sourceforge.net Cc: linux-kernel@vger.kernel.org, Christian Brauner , Dave Kleikamp , outbounddisclosures@openai.com, Kyle Zeng , stable@vger.kernel.org Subject: [PATCH v2] jfs: validate active AG before updating db_active Date: Fri, 12 Jun 2026 16:41:35 -0700 Message-ID: <20260612234135.47450-1-kylebot@openai.com> X-Mailer: git-send-email 2.54.0 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit When an empty regular file is opened for write, jfs_open() tracks a single active file per allocation group. The allocation group is derived from ji->ixpxd, which is copied from the on-disk inode in copy_from_dinode(). A corrupted image can set di_ixpxd to an address that maps beyond the mounted bmap's db_numag. The existing code stores that unchecked result in signed char active_ag and then uses it to index db_active[]. For example, an AG value of 249 wraps to -7 before the atomic increment, causing a write before db_active and corrupting adjacent struct bmap state. Compute the AG in an unsigned type and reject values outside db_numag before storing active_ag or indexing db_active[]. dbMount() already validates db_numag <= MAXAG, so accepted values fit in active_ag and in the db_active[] array. Fixes: d31b53e3cd06 ("JFS: Don't save agno in the inode") Cc: stable@vger.kernel.org Assisted-by: Codex:gpt-5.5 Signed-off-by: Kyle Zeng --- Changes in v2: - Fix build issues. - Avoid unnecessary type casts. fs/jfs/file.c | 32 +++++++++++++++++++++++++++++--- 1 file changed, 29 insertions(+), 3 deletions(-) diff --git a/fs/jfs/file.c b/fs/jfs/file.c index 81556da507b9..d34a4e95a809 100644 --- a/fs/jfs/file.c +++ b/fs/jfs/file.c @@ -12,6 +12,7 @@ #include "jfs_incore.h" #include "jfs_inode.h" #include "jfs_dmap.h" +#include "jfs_superblock.h" #include "jfs_txnmgr.h" #include "jfs_xattr.h" #include "jfs_acl.h" @@ -38,6 +38,24 @@ int jfs_fsync(struct file *file, loff_t start, loff_t end, int datasync) return rc ? -EIO : 0; } +static int jfs_get_active_ag(struct inode *inode, int *agp) +{ + struct jfs_inode_info *ji = JFS_IP(inode); + struct jfs_sb_info *sbi = JFS_SBI(inode->i_sb); + struct bmap *bmap = sbi->bmap; + u64 ag = BLKTOAG(addressPXD(&ji->ixpxd), sbi); + + if (ag >= bmap->db_numag) { + jfs_error(inode->i_sb, + "inode %llu has invalid active ag %llu\n", + inode->i_ino, ag); + return -EIO; + } + + *agp = ag; + return 0; +} + static int jfs_open(struct inode *inode, struct file *file) { int rc; @@ -63,11 +82,18 @@ static int jfs_open(struct inode *inode, struct file *file) if (S_ISREG(inode->i_mode) && file->f_mode & FMODE_WRITE && (inode->i_size == 0)) { struct jfs_inode_info *ji = JFS_IP(inode); + struct bmap *bmap; + int active_ag; + + rc = jfs_get_active_ag(inode, &active_ag); + if (rc) + return rc; + spin_lock_irq(&ji->ag_lock); if (ji->active_ag == -1) { - struct jfs_sb_info *jfs_sb = JFS_SBI(inode->i_sb); - ji->active_ag = BLKTOAG(addressPXD(&ji->ixpxd), jfs_sb); - atomic_inc(&jfs_sb->bmap->db_active[ji->active_ag]); + bmap = JFS_SBI(inode->i_sb)->bmap; + ji->active_ag = active_ag; + atomic_inc(&bmap->db_active[active_ag]); } spin_unlock_irq(&ji->ag_lock); } -- 2.43.0