From: Joseph Qi <joseph.qi@linux.alibaba.com>
To: Andrew Morton <akpm@linux-foundation.org>,
Heming Zhao <heming.zhao@suse.com>
Cc: Mark Fasheh <mark@fasheh.com>, Joel Becker <jlbec@evilplan.org>,
ocfs2-devel@lists.linux.dev, linux-kernel@vger.kernel.org
Subject: [PATCH v2 2/2] ocfs2: validate dl_blkno and dl_fs_generation of dir index leaf blocks
Date: Sat, 5 Sep 2026 22:21:44 +0800 [thread overview]
Message-ID: <20260905142144.2869105-2-joseph.qi@linux.alibaba.com> (raw)
In-Reply-To: <20260905142144.2869105-1-joseph.qi@linux.alibaba.com>
ocfs2_validate_dx_leaf() checks the checksum, the signature and the
entry list counts, but it never checks dl_blkno or dl_fs_generation.
The inode, extent block, xattr block, refcount block and dir index root
validators all check the on-disk block number against bh->b_blocknr and
the generation against the superblock, and both dir index leaf fields
are documented as "Must match super block".
Without the checks, a stale dir index leaf block left on the device from
a previously formatted filesystem at the same physical block number can
pass validation as long as its signature, entry counts and checksum
match. Its index entries would then be used in the new filesystem
context.
Both fields are written unconditionally when a leaf block is formatted
in ocfs2_dx_dir_format_cluster(), from the live superblock generation
and the real block number, so a correctly formatted filesystem cannot
trip the new checks. The leaf block number read back here comes from
on-disk dir index root extent records.
Reject dir index leaf blocks whose dl_blkno or dl_fs_generation does not
match, like the dir index root validator does.
Signed-off-by: Joseph Qi <joseph.qi@linux.alibaba.com>
---
fs/ocfs2/dir.c | 12 ++++++++++++
1 file changed, 12 insertions(+)
diff --git a/fs/ocfs2/dir.c b/fs/ocfs2/dir.c
index 329680b46227..55c4a305a282 100644
--- a/fs/ocfs2/dir.c
+++ b/fs/ocfs2/dir.c
@@ -733,6 +733,18 @@ static int ocfs2_validate_dx_leaf(struct super_block *sb,
return ocfs2_error(sb, "Dir Index Leaf has bad signature %.*s\n",
7, dx_leaf->dl_signature);
+ if (le64_to_cpu(dx_leaf->dl_blkno) != bh->b_blocknr)
+ return ocfs2_error(sb,
+ "Dir Index Leaf # %llu has an invalid dl_blkno of %llu\n",
+ (unsigned long long)bh->b_blocknr,
+ (unsigned long long)le64_to_cpu(dx_leaf->dl_blkno));
+
+ if (le32_to_cpu(dx_leaf->dl_fs_generation) != OCFS2_SB(sb)->fs_generation)
+ return ocfs2_error(sb,
+ "Dir Index Leaf # %llu has an invalid dl_fs_generation of #%u\n",
+ (unsigned long long)bh->b_blocknr,
+ le32_to_cpu(dx_leaf->dl_fs_generation));
+
if (le16_to_cpu(dx_leaf->dl_list.de_count) !=
ocfs2_dx_entries_per_leaf(sb))
return ocfs2_error(sb,
--
2.39.3
next prev parent reply other threads:[~2026-09-05 14:21 UTC|newest]
Thread overview: 3+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-05 14:21 [PATCH v2 1/2] ocfs2: validate dr_fs_generation of dir index root blocks Joseph Qi
2026-09-05 14:21 ` Joseph Qi [this message]
2026-09-05 14:45 ` [PATCH v2 2/2] ocfs2: validate dl_blkno and dl_fs_generation of dir index leaf blocks Heming Zhao
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260905142144.2869105-2-joseph.qi@linux.alibaba.com \
--to=joseph.qi@linux.alibaba.com \
--cc=akpm@linux-foundation.org \
--cc=heming.zhao@suse.com \
--cc=jlbec@evilplan.org \
--cc=linux-kernel@vger.kernel.org \
--cc=mark@fasheh.com \
--cc=ocfs2-devel@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®