From: Chao Yu <chao@kernel.org>
To: jaegeuk@kernel.org
Cc: linux-f2fs-devel@lists.sourceforge.net,
linux-kernel@vger.kernel.org, Chao Yu <chao@kernel.org>,
syzbot+dfcbc1741488709db4b2@syzkaller.appspotmail.com
Subject: [PATCH] f2fs: fix to set sbi->log_blocksize in advance
Date: Thu, 1 Oct 2026 00:04:50 +0000 [thread overview]
Message-ID: <20261001000450.3822520-1-chao@kernel.org> (raw)
From: Chao Yu <chao@kernel.org>
syzbot reported a shift-out-of-bounds in __f2fs_commit_super():
UBSAN: shift-out-of-bounds in fs/f2fs/super.c:3950:27
shift exponent 4294967287 is too large for 64-bit type 'sector_t'
(aka 'unsigned long long')
CPU: 1 UID: 0 PID: 5622 Comm: syz-executor329 Not tainted
Call Trace:
<TASK>
dump_stack_lvl+0xe8/0x150 lib/dump_stack.c:120
ubsan_epilogue+0xa/0x30 lib/ubsan.c:233
__ubsan_handle_shift_out_of_bounds+0x36d/0x400 lib/ubsan.c:494
__f2fs_commit_super+0x43e/0x4d0 fs/f2fs/super.c:3950
sanity_check_area_boundary+0x7c5/0xe20 fs/f2fs/super.c:4040
sanity_check_raw_super fs/f2fs/super.c:4215 [inline]
read_raw_super_block fs/f2fs/super.c:4625 [inline]
f2fs_fill_super+0x1920/0x7fa0 fs/f2fs/super.c:5160
Commit b32d4bdbae61 ("f2fs: parameterize sector conversion macros")
parameterized SECTOR_FROM_BLOCK() with sbi->log_blocksize, where
F2FS_LOG_SECTORS_PER_BLOCK(sbi) evaluates to (sbi->log_blocksize - 9).
During mount, read_raw_super_block() calls sanity_check_raw_super()
before sbi->log_blocksize is initialized in init_sb_info(). If the
image requires alignment fixing (main_end_blkaddr < seg_end_blkaddr),
sanity_check_area_boundary() updates raw_super->segment_count and calls
__f2fs_commit_super() to write back the superblock.
At this point, sbi->log_blocksize is still zero, leading to an underflow
in (0 - 9) = 4294967287 and triggering UBSAN shift-out-of-bounds when
computing SECTOR_FROM_BLOCK(sbi, folio->index).
Fix this by initializing sbi->log_blocksize from raw_super->log_blocksize
prior to calling __f2fs_commit_super() in sanity_check_area_boundary().
Note that raw_super->log_blocksize has already been validated against
PAGE_SHIFT earlier in sanity_check_raw_super().
Fixes: b32d4bdbae61 ("f2fs: parameterize sector conversion macros")
Reported-by: syzbot+dfcbc1741488709db4b2@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=dfcbc1741488709db4b2
Signed-off-by: Chao Yu <chao@kernel.org>
---
fs/f2fs/super.c | 6 ++++++
1 file changed, 6 insertions(+)
diff --git a/fs/f2fs/super.c b/fs/f2fs/super.c
index fc3be097285b..8d9aaf21655a 100644
--- a/fs/f2fs/super.c
+++ b/fs/f2fs/super.c
@@ -4038,6 +4038,12 @@ static inline bool sanity_check_area_boundary(struct f2fs_sb_info *sbi,
set_sbi_flag(sbi, SBI_NEED_SB_WRITE);
res = "internally";
} else {
+ /*
+ * __f2fs_commit_super() will access log_blocksize
+ * in SECTOR_FROM_BLOCK(), init it in advance.
+ */
+ sbi->log_blocksize =
+ le32_to_cpu(raw_super->log_blocksize);
err = __f2fs_commit_super(sbi, folio, index, false);
res = err ? "failed" : "done";
}
--
2.49.0
reply other threads:[~2026-10-01 0:05 UTC|newest]
Thread overview: [no followups] expand[flat|nested] mbox.gz Atom feed
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20261001000450.3822520-1-chao@kernel.org \
--to=chao@kernel.org \
--cc=jaegeuk@kernel.org \
--cc=linux-f2fs-devel@lists.sourceforge.net \
--cc=linux-kernel@vger.kernel.org \
--cc=syzbot+dfcbc1741488709db4b2@syzkaller.appspotmail.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®