mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* [PATCH 0/2] nilfs2: robustness fixes from Jake Labelle
@ 2026-10-08 11:52 Ryusuke Konishi
  2026-10-08 11:52 ` [PATCH 1/2] nilfs2: reject non-regular inodes in dsync recovery Ryusuke Konishi
                   ` (2 more replies)
  0 siblings, 3 replies; 4+ messages in thread
From: Ryusuke Konishi @ 2026-10-08 11:52 UTC (permalink / raw)
  To: Viacheslav Dubeyko; +Cc: linux-nilfs, LKML, Jake Labelle

Hi Viacheslav,

Please add the following two commits from Jake Labelle to your queue
for the next cycle.

As this cycle is getting closer to its end, I am sending these ahead with
a minor fix applied.  If Jake responds with further comments or revised
proposals later, we can discuss them as needed.

These patches address two robustness issues:

- Patch 1/2 rejects special inodes during dsync recovery to prevent
  dereferencing uninitialized bmap function pointers.
- Patch 2/2 validates and snaps the directory position after llseek in
  nilfs_readdir() to prevent invalid or out-of-bounds page reads.

For full context and background details, please refer to the original
cover letter here:

https://lore.kernel.org/all/20260930000954.371774-1-southampton.jake.labelle@gmail.com

Thanks,
Ryusuke Konishi

Jake Labelle (2):
  nilfs2: reject non-regular inodes in dsync recovery
  nilfs2: validate directory position after llseek in readdir

 fs/nilfs2/dir.c      | 34 ++++++++++++++++++++++++++++++++++
 fs/nilfs2/recovery.c | 17 +++++++++++++++++
 2 files changed, 51 insertions(+)

-- 
2.53.0


^ permalink raw reply	[flat|nested] 4+ messages in thread

* [PATCH 1/2] nilfs2: reject non-regular inodes in dsync recovery
  2026-10-08 11:52 [PATCH 0/2] nilfs2: robustness fixes from Jake Labelle Ryusuke Konishi
@ 2026-10-08 11:52 ` Ryusuke Konishi
  2026-10-08 11:52 ` [PATCH 2/2] nilfs2: validate directory position after llseek in readdir Ryusuke Konishi
  2026-10-08 16:41 ` [PATCH 0/2] nilfs2: robustness fixes from Jake Labelle Viacheslav Dubeyko
  2 siblings, 0 replies; 4+ messages in thread
From: Ryusuke Konishi @ 2026-10-08 11:52 UTC (permalink / raw)
  To: Viacheslav Dubeyko; +Cc: linux-nilfs, LKML, Jake Labelle

From: Jake Labelle <southampton.jake.labelle@gmail.com>

During roll-forward recovery, nilfs_recover_dsync_blocks() obtains the
inode designated by fi_ino of a dsync log without checking its type.
If a corrupted image designates a special inode (e.g. a device node)
there, the inode's embedded bmap was never initialized:
__nilfs_read_inode() calls nilfs_bmap_read() only for regular files,
directories and symlinks.  The subsequent nilfs_get_block() then
dereferences the uninitialized bmap->b_ops and jumps through it,
crashing the kernel or worse.

Regular files, directories, and symlinks are the only inode types
with data blocks to recover; reject anything else before touching
its block mapping.

[ryusuke: conformed AI tag to guidelines]

Fixes: 0f3e1c7f23f8 ("nilfs2: recovery functions")
Assisted-by: Claude:claude-mythos-5
Signed-off-by: Jake Labelle <southampton.jake.labelle@gmail.com>
Signed-off-by: Ryusuke Konishi <konishi.ryusuke@gmail.com>
---
 fs/nilfs2/recovery.c | 17 +++++++++++++++++
 1 file changed, 17 insertions(+)

diff --git a/fs/nilfs2/recovery.c b/fs/nilfs2/recovery.c
index abe4101f7550..c384325a57d0 100644
--- a/fs/nilfs2/recovery.c
+++ b/fs/nilfs2/recovery.c
@@ -545,6 +545,23 @@ static int nilfs_recover_dsync_blocks(struct the_nilfs *nilfs,
 			goto failed_inode;
 		}
 
+		/*
+		 * Regular files, directories, and symlinks are the only
+		 * inode types with data blocks and an initialized bmap;
+		 * a crafted image can reference some other inode type
+		 * here, whose i_bmap_data was never set up by
+		 * __nilfs_read_inode().
+		 */
+		if (!likely(S_ISREG(inode->i_mode) || S_ISDIR(inode->i_mode) ||
+			    S_ISLNK(inode->i_mode))) {
+			nilfs_warn(sb,
+				   "%s: invalid inode type (ino=%lu, mode=0%o)",
+				   __func__, (unsigned long)rb->ino,
+				   inode->i_mode);
+			err = -EINVAL;
+			goto failed_inode;
+		}
+
 		pos = rb->blkoff << inode->i_blkbits;
 		err = block_write_begin(inode->i_mapping, pos, blocksize,
 					&folio, nilfs_get_block);
-- 
2.53.0


^ permalink raw reply	[flat|nested] 4+ messages in thread

* [PATCH 2/2] nilfs2: validate directory position after llseek in readdir
  2026-10-08 11:52 [PATCH 0/2] nilfs2: robustness fixes from Jake Labelle Ryusuke Konishi
  2026-10-08 11:52 ` [PATCH 1/2] nilfs2: reject non-regular inodes in dsync recovery Ryusuke Konishi
@ 2026-10-08 11:52 ` Ryusuke Konishi
  2026-10-08 16:41 ` [PATCH 0/2] nilfs2: robustness fixes from Jake Labelle Viacheslav Dubeyko
  2 siblings, 0 replies; 4+ messages in thread
From: Ryusuke Konishi @ 2026-10-08 11:52 UTC (permalink / raw)
  To: Viacheslav Dubeyko; +Cc: linux-nilfs, LKML, Jake Labelle

From: Jake Labelle <southampton.jake.labelle@gmail.com>

nilfs_readdir() uses ctx->pos, which userspace can set to an arbitrary
value via llseek, as an offset into the directory folio and parses
whatever bytes sit there as a directory entry.  A position pointing
into the middle of an entry -- or at unused bytes of a corrupted image
that the page validator never inspected -- makes dir_emit() copy up to
255 (name_len) bytes from a bogus entry, possibly reading past the end
of the folio and returning unrelated memory contents to userspace.

Snap unaligned positions onto a valid entry boundary by walking the
rec_len chain from the chunk start before parsing, as ext2 does in
ext2_validate_entry().

[ryusuke: fixed offset wrap-around in nilfs_validate_entry() and
 conformed AI tag to guidelines]

Fixes: 2ba466d74ed7 ("nilfs2: directory entry operations")
Assisted-by: Claude:claude-mythos-5
Signed-off-by: Jake Labelle <southampton.jake.labelle@gmail.com>
Cc: stable@vger.kernel.org
Signed-off-by: Ryusuke Konishi <konishi.ryusuke@gmail.com>
---
 fs/nilfs2/dir.c | 34 ++++++++++++++++++++++++++++++++++
 1 file changed, 34 insertions(+)

diff --git a/fs/nilfs2/dir.c b/fs/nilfs2/dir.c
index 8b53802b6ebd..7686ca9228fc 100644
--- a/fs/nilfs2/dir.c
+++ b/fs/nilfs2/dir.c
@@ -231,11 +231,27 @@ static struct nilfs_dir_entry *nilfs_next_entry(struct nilfs_dir_entry *p)
 					  nilfs_rec_len_from_disk(p->rec_len));
 }
 
+static inline unsigned int
+nilfs_validate_entry(char *base, unsigned int offset, unsigned int mask)
+{
+	struct nilfs_dir_entry *de = (struct nilfs_dir_entry *)(base + offset);
+	struct nilfs_dir_entry *p =
+		(struct nilfs_dir_entry *)(base + (offset & mask));
+
+	while ((char *)p < (char *)de) {
+		if (p->rec_len == 0)
+			break;
+		p = nilfs_next_entry(p);
+	}
+	return (char *)p - base;
+}
+
 static int nilfs_readdir(struct file *file, struct dir_context *ctx)
 {
 	loff_t pos = ctx->pos;
 	struct inode *inode = file_inode(file);
 	struct super_block *sb = inode->i_sb;
+	unsigned int chunk_size = nilfs_chunk_size(inode);
 	unsigned int offset = pos & ~PAGE_MASK;
 	unsigned long n = pos >> PAGE_SHIFT;
 	unsigned long npages = dir_pages(inode);
@@ -254,6 +270,24 @@ static int nilfs_readdir(struct file *file, struct dir_context *ctx)
 			ctx->pos += PAGE_SIZE - offset;
 			return -EIO;
 		}
+		/*
+		 * ctx->pos comes from userspace via llseek and may point
+		 * into the middle of an entry -- or at unvalidated bytes
+		 * of a crafted image. offset is only nonzero here on the
+		 * very first iteration (subsequent pages always start at
+		 * offset 0, which -- like any chunk boundary -- is always
+		 * a legitimate entry start, since no rec_len chain crosses
+		 * a chunk boundary). Snap a non-chunk-aligned offset onto
+		 * a real entry boundary by walking the chain from the
+		 * enclosing chunk's start, as ext2 does; otherwise
+		 * dir_emit() copies name_len bytes from a fake entry,
+		 * reading past the end of the folio.
+		 */
+		if (offset & (chunk_size - 1)) {
+			offset = nilfs_validate_entry(kaddr, offset,
+					~(chunk_size - 1));
+			ctx->pos = ((loff_t)n << PAGE_SHIFT) + offset;
+		}
 		de = (struct nilfs_dir_entry *)(kaddr + offset);
 		limit = kaddr + nilfs_last_byte(inode, n) -
 			NILFS_DIR_REC_LEN(1);
-- 
2.53.0


^ permalink raw reply	[flat|nested] 4+ messages in thread

* Re: [PATCH 0/2] nilfs2: robustness fixes from Jake Labelle
  2026-10-08 11:52 [PATCH 0/2] nilfs2: robustness fixes from Jake Labelle Ryusuke Konishi
  2026-10-08 11:52 ` [PATCH 1/2] nilfs2: reject non-regular inodes in dsync recovery Ryusuke Konishi
  2026-10-08 11:52 ` [PATCH 2/2] nilfs2: validate directory position after llseek in readdir Ryusuke Konishi
@ 2026-10-08 16:41 ` Viacheslav Dubeyko
  2 siblings, 0 replies; 4+ messages in thread
From: Viacheslav Dubeyko @ 2026-10-08 16:41 UTC (permalink / raw)
  To: Ryusuke Konishi; +Cc: linux-nilfs, LKML, Jake Labelle

On Thu, 2026-10-08 at 20:52 +0900, Ryusuke Konishi wrote:
> Hi Viacheslav,
> 
> Please add the following two commits from Jake Labelle to your queue
> for the next cycle.
> 
> As this cycle is getting closer to its end, I am sending these ahead
> with
> a minor fix applied.  If Jake responds with further comments or
> revised
> proposals later, we can discuss them as needed.
> 
> These patches address two robustness issues:
> 
> - Patch 1/2 rejects special inodes during dsync recovery to prevent
>   dereferencing uninitialized bmap function pointers.
> - Patch 2/2 validates and snaps the directory position after llseek
> in
>   nilfs_readdir() to prevent invalid or out-of-bounds page reads.
> 
> For full context and background details, please refer to the original
> cover letter here:
> 
> https://lore.kernel.org/all/20260930000954.371774-1-southampton.jake.labelle@gmail.com
> 
> Thanks,
> Ryusuke Konishi
> 
> Jake Labelle (2):
>   nilfs2: reject non-regular inodes in dsync recovery
>   nilfs2: validate directory position after llseek in readdir
> 
>  fs/nilfs2/dir.c      | 34 ++++++++++++++++++++++++++++++++++
>  fs/nilfs2/recovery.c | 17 +++++++++++++++++
>  2 files changed, 51 insertions(+)

Applied.

Thanks,
Slava.

^ permalink raw reply	[flat|nested] 4+ messages in thread

end of thread, other threads:[~2026-10-08 16:41 UTC | newest]

Thread overview: 4+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-10-08 11:52 [PATCH 0/2] nilfs2: robustness fixes from Jake Labelle Ryusuke Konishi
2026-10-08 11:52 ` [PATCH 1/2] nilfs2: reject non-regular inodes in dsync recovery Ryusuke Konishi
2026-10-08 11:52 ` [PATCH 2/2] nilfs2: validate directory position after llseek in readdir Ryusuke Konishi
2026-10-08 16:41 ` [PATCH 0/2] nilfs2: robustness fixes from Jake Labelle Viacheslav Dubeyko

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®