* [PATCH] f2fs: fix to set sbi->log_blocksize in advance
@ 2026-10-01 0:04 Chao Yu
0 siblings, 0 replies; only message in thread
From: Chao Yu @ 2026-10-01 0:04 UTC (permalink / raw)
To: jaegeuk
Cc: linux-f2fs-devel, linux-kernel, Chao Yu, syzbot+dfcbc1741488709db4b2
From: Chao Yu <chao@kernel.org>
syzbot reported a shift-out-of-bounds in __f2fs_commit_super():
UBSAN: shift-out-of-bounds in fs/f2fs/super.c:3950:27
shift exponent 4294967287 is too large for 64-bit type 'sector_t'
(aka 'unsigned long long')
CPU: 1 UID: 0 PID: 5622 Comm: syz-executor329 Not tainted
Call Trace:
<TASK>
dump_stack_lvl+0xe8/0x150 lib/dump_stack.c:120
ubsan_epilogue+0xa/0x30 lib/ubsan.c:233
__ubsan_handle_shift_out_of_bounds+0x36d/0x400 lib/ubsan.c:494
__f2fs_commit_super+0x43e/0x4d0 fs/f2fs/super.c:3950
sanity_check_area_boundary+0x7c5/0xe20 fs/f2fs/super.c:4040
sanity_check_raw_super fs/f2fs/super.c:4215 [inline]
read_raw_super_block fs/f2fs/super.c:4625 [inline]
f2fs_fill_super+0x1920/0x7fa0 fs/f2fs/super.c:5160
Commit b32d4bdbae61 ("f2fs: parameterize sector conversion macros")
parameterized SECTOR_FROM_BLOCK() with sbi->log_blocksize, where
F2FS_LOG_SECTORS_PER_BLOCK(sbi) evaluates to (sbi->log_blocksize - 9).
During mount, read_raw_super_block() calls sanity_check_raw_super()
before sbi->log_blocksize is initialized in init_sb_info(). If the
image requires alignment fixing (main_end_blkaddr < seg_end_blkaddr),
sanity_check_area_boundary() updates raw_super->segment_count and calls
__f2fs_commit_super() to write back the superblock.
At this point, sbi->log_blocksize is still zero, leading to an underflow
in (0 - 9) = 4294967287 and triggering UBSAN shift-out-of-bounds when
computing SECTOR_FROM_BLOCK(sbi, folio->index).
Fix this by initializing sbi->log_blocksize from raw_super->log_blocksize
prior to calling __f2fs_commit_super() in sanity_check_area_boundary().
Note that raw_super->log_blocksize has already been validated against
PAGE_SHIFT earlier in sanity_check_raw_super().
Fixes: b32d4bdbae61 ("f2fs: parameterize sector conversion macros")
Reported-by: syzbot+dfcbc1741488709db4b2@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=dfcbc1741488709db4b2
Signed-off-by: Chao Yu <chao@kernel.org>
---
fs/f2fs/super.c | 6 ++++++
1 file changed, 6 insertions(+)
diff --git a/fs/f2fs/super.c b/fs/f2fs/super.c
index fc3be097285b..8d9aaf21655a 100644
--- a/fs/f2fs/super.c
+++ b/fs/f2fs/super.c
@@ -4038,6 +4038,12 @@ static inline bool sanity_check_area_boundary(struct f2fs_sb_info *sbi,
set_sbi_flag(sbi, SBI_NEED_SB_WRITE);
res = "internally";
} else {
+ /*
+ * __f2fs_commit_super() will access log_blocksize
+ * in SECTOR_FROM_BLOCK(), init it in advance.
+ */
+ sbi->log_blocksize =
+ le32_to_cpu(raw_super->log_blocksize);
err = __f2fs_commit_super(sbi, folio, index, false);
res = err ? "failed" : "done";
}
--
2.49.0
^ permalink raw reply [flat|nested] only message in thread
only message in thread, other threads:[~2026-10-01 0:05 UTC | newest]
Thread overview: (only message) (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-10-01 0:04 [PATCH] f2fs: fix to set sbi->log_blocksize in advance Chao Yu
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®