From: Ryusuke Konishi <konishi.ryusuke@gmail.com>
To: Viacheslav Dubeyko <slava@dubeyko.com>
Cc: linux-nilfs <linux-nilfs@vger.kernel.org>,
LKML <linux-kernel@vger.kernel.org>,
Jake Labelle <southampton.jake.labelle@gmail.com>
Subject: [PATCH 1/2] nilfs2: reject non-regular inodes in dsync recovery
Date: Thu, 8 Oct 2026 20:52:47 +0900 [thread overview]
Message-ID: <20261008115312.18482-2-konishi.ryusuke@gmail.com> (raw)
In-Reply-To: <20261008115312.18482-1-konishi.ryusuke@gmail.com>
From: Jake Labelle <southampton.jake.labelle@gmail.com>
During roll-forward recovery, nilfs_recover_dsync_blocks() obtains the
inode designated by fi_ino of a dsync log without checking its type.
If a corrupted image designates a special inode (e.g. a device node)
there, the inode's embedded bmap was never initialized:
__nilfs_read_inode() calls nilfs_bmap_read() only for regular files,
directories and symlinks. The subsequent nilfs_get_block() then
dereferences the uninitialized bmap->b_ops and jumps through it,
crashing the kernel or worse.
Regular files, directories, and symlinks are the only inode types
with data blocks to recover; reject anything else before touching
its block mapping.
[ryusuke: conformed AI tag to guidelines]
Fixes: 0f3e1c7f23f8 ("nilfs2: recovery functions")
Assisted-by: Claude:claude-mythos-5
Signed-off-by: Jake Labelle <southampton.jake.labelle@gmail.com>
Signed-off-by: Ryusuke Konishi <konishi.ryusuke@gmail.com>
---
fs/nilfs2/recovery.c | 17 +++++++++++++++++
1 file changed, 17 insertions(+)
diff --git a/fs/nilfs2/recovery.c b/fs/nilfs2/recovery.c
index abe4101f7550..c384325a57d0 100644
--- a/fs/nilfs2/recovery.c
+++ b/fs/nilfs2/recovery.c
@@ -545,6 +545,23 @@ static int nilfs_recover_dsync_blocks(struct the_nilfs *nilfs,
goto failed_inode;
}
+ /*
+ * Regular files, directories, and symlinks are the only
+ * inode types with data blocks and an initialized bmap;
+ * a crafted image can reference some other inode type
+ * here, whose i_bmap_data was never set up by
+ * __nilfs_read_inode().
+ */
+ if (!likely(S_ISREG(inode->i_mode) || S_ISDIR(inode->i_mode) ||
+ S_ISLNK(inode->i_mode))) {
+ nilfs_warn(sb,
+ "%s: invalid inode type (ino=%lu, mode=0%o)",
+ __func__, (unsigned long)rb->ino,
+ inode->i_mode);
+ err = -EINVAL;
+ goto failed_inode;
+ }
+
pos = rb->blkoff << inode->i_blkbits;
err = block_write_begin(inode->i_mapping, pos, blocksize,
&folio, nilfs_get_block);
--
2.53.0
next prev parent reply other threads:[~2026-10-08 11:53 UTC|newest]
Thread overview: 4+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-10-08 11:52 [PATCH 0/2] nilfs2: robustness fixes from Jake Labelle Ryusuke Konishi
2026-10-08 11:52 ` Ryusuke Konishi [this message]
2026-10-08 11:52 ` [PATCH 2/2] nilfs2: validate directory position after llseek in readdir Ryusuke Konishi
2026-10-08 16:41 ` [PATCH 0/2] nilfs2: robustness fixes from Jake Labelle Viacheslav Dubeyko
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20261008115312.18482-2-konishi.ryusuke@gmail.com \
--to=konishi.ryusuke@gmail.com \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-nilfs@vger.kernel.org \
--cc=slava@dubeyko.com \
--cc=southampton.jake.labelle@gmail.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®