* [PATCH 1/2] nilfs2: reject non-regular inodes in dsync recovery
2026-10-08 11:52 [PATCH 0/2] nilfs2: robustness fixes from Jake Labelle Ryusuke Konishi
@ 2026-10-08 11:52 ` Ryusuke Konishi
2026-10-08 11:52 ` [PATCH 2/2] nilfs2: validate directory position after llseek in readdir Ryusuke Konishi
2026-10-08 16:41 ` [PATCH 0/2] nilfs2: robustness fixes from Jake Labelle Viacheslav Dubeyko
2 siblings, 0 replies; 4+ messages in thread
From: Ryusuke Konishi @ 2026-10-08 11:52 UTC (permalink / raw)
To: Viacheslav Dubeyko; +Cc: linux-nilfs, LKML, Jake Labelle
From: Jake Labelle <southampton.jake.labelle@gmail.com>
During roll-forward recovery, nilfs_recover_dsync_blocks() obtains the
inode designated by fi_ino of a dsync log without checking its type.
If a corrupted image designates a special inode (e.g. a device node)
there, the inode's embedded bmap was never initialized:
__nilfs_read_inode() calls nilfs_bmap_read() only for regular files,
directories and symlinks. The subsequent nilfs_get_block() then
dereferences the uninitialized bmap->b_ops and jumps through it,
crashing the kernel or worse.
Regular files, directories, and symlinks are the only inode types
with data blocks to recover; reject anything else before touching
its block mapping.
[ryusuke: conformed AI tag to guidelines]
Fixes: 0f3e1c7f23f8 ("nilfs2: recovery functions")
Assisted-by: Claude:claude-mythos-5
Signed-off-by: Jake Labelle <southampton.jake.labelle@gmail.com>
Signed-off-by: Ryusuke Konishi <konishi.ryusuke@gmail.com>
---
fs/nilfs2/recovery.c | 17 +++++++++++++++++
1 file changed, 17 insertions(+)
diff --git a/fs/nilfs2/recovery.c b/fs/nilfs2/recovery.c
index abe4101f7550..c384325a57d0 100644
--- a/fs/nilfs2/recovery.c
+++ b/fs/nilfs2/recovery.c
@@ -545,6 +545,23 @@ static int nilfs_recover_dsync_blocks(struct the_nilfs *nilfs,
goto failed_inode;
}
+ /*
+ * Regular files, directories, and symlinks are the only
+ * inode types with data blocks and an initialized bmap;
+ * a crafted image can reference some other inode type
+ * here, whose i_bmap_data was never set up by
+ * __nilfs_read_inode().
+ */
+ if (!likely(S_ISREG(inode->i_mode) || S_ISDIR(inode->i_mode) ||
+ S_ISLNK(inode->i_mode))) {
+ nilfs_warn(sb,
+ "%s: invalid inode type (ino=%lu, mode=0%o)",
+ __func__, (unsigned long)rb->ino,
+ inode->i_mode);
+ err = -EINVAL;
+ goto failed_inode;
+ }
+
pos = rb->blkoff << inode->i_blkbits;
err = block_write_begin(inode->i_mapping, pos, blocksize,
&folio, nilfs_get_block);
--
2.53.0
^ permalink raw reply [flat|nested] 4+ messages in thread* [PATCH 2/2] nilfs2: validate directory position after llseek in readdir
2026-10-08 11:52 [PATCH 0/2] nilfs2: robustness fixes from Jake Labelle Ryusuke Konishi
2026-10-08 11:52 ` [PATCH 1/2] nilfs2: reject non-regular inodes in dsync recovery Ryusuke Konishi
@ 2026-10-08 11:52 ` Ryusuke Konishi
2026-10-08 16:41 ` [PATCH 0/2] nilfs2: robustness fixes from Jake Labelle Viacheslav Dubeyko
2 siblings, 0 replies; 4+ messages in thread
From: Ryusuke Konishi @ 2026-10-08 11:52 UTC (permalink / raw)
To: Viacheslav Dubeyko; +Cc: linux-nilfs, LKML, Jake Labelle
From: Jake Labelle <southampton.jake.labelle@gmail.com>
nilfs_readdir() uses ctx->pos, which userspace can set to an arbitrary
value via llseek, as an offset into the directory folio and parses
whatever bytes sit there as a directory entry. A position pointing
into the middle of an entry -- or at unused bytes of a corrupted image
that the page validator never inspected -- makes dir_emit() copy up to
255 (name_len) bytes from a bogus entry, possibly reading past the end
of the folio and returning unrelated memory contents to userspace.
Snap unaligned positions onto a valid entry boundary by walking the
rec_len chain from the chunk start before parsing, as ext2 does in
ext2_validate_entry().
[ryusuke: fixed offset wrap-around in nilfs_validate_entry() and
conformed AI tag to guidelines]
Fixes: 2ba466d74ed7 ("nilfs2: directory entry operations")
Assisted-by: Claude:claude-mythos-5
Signed-off-by: Jake Labelle <southampton.jake.labelle@gmail.com>
Cc: stable@vger.kernel.org
Signed-off-by: Ryusuke Konishi <konishi.ryusuke@gmail.com>
---
fs/nilfs2/dir.c | 34 ++++++++++++++++++++++++++++++++++
1 file changed, 34 insertions(+)
diff --git a/fs/nilfs2/dir.c b/fs/nilfs2/dir.c
index 8b53802b6ebd..7686ca9228fc 100644
--- a/fs/nilfs2/dir.c
+++ b/fs/nilfs2/dir.c
@@ -231,11 +231,27 @@ static struct nilfs_dir_entry *nilfs_next_entry(struct nilfs_dir_entry *p)
nilfs_rec_len_from_disk(p->rec_len));
}
+static inline unsigned int
+nilfs_validate_entry(char *base, unsigned int offset, unsigned int mask)
+{
+ struct nilfs_dir_entry *de = (struct nilfs_dir_entry *)(base + offset);
+ struct nilfs_dir_entry *p =
+ (struct nilfs_dir_entry *)(base + (offset & mask));
+
+ while ((char *)p < (char *)de) {
+ if (p->rec_len == 0)
+ break;
+ p = nilfs_next_entry(p);
+ }
+ return (char *)p - base;
+}
+
static int nilfs_readdir(struct file *file, struct dir_context *ctx)
{
loff_t pos = ctx->pos;
struct inode *inode = file_inode(file);
struct super_block *sb = inode->i_sb;
+ unsigned int chunk_size = nilfs_chunk_size(inode);
unsigned int offset = pos & ~PAGE_MASK;
unsigned long n = pos >> PAGE_SHIFT;
unsigned long npages = dir_pages(inode);
@@ -254,6 +270,24 @@ static int nilfs_readdir(struct file *file, struct dir_context *ctx)
ctx->pos += PAGE_SIZE - offset;
return -EIO;
}
+ /*
+ * ctx->pos comes from userspace via llseek and may point
+ * into the middle of an entry -- or at unvalidated bytes
+ * of a crafted image. offset is only nonzero here on the
+ * very first iteration (subsequent pages always start at
+ * offset 0, which -- like any chunk boundary -- is always
+ * a legitimate entry start, since no rec_len chain crosses
+ * a chunk boundary). Snap a non-chunk-aligned offset onto
+ * a real entry boundary by walking the chain from the
+ * enclosing chunk's start, as ext2 does; otherwise
+ * dir_emit() copies name_len bytes from a fake entry,
+ * reading past the end of the folio.
+ */
+ if (offset & (chunk_size - 1)) {
+ offset = nilfs_validate_entry(kaddr, offset,
+ ~(chunk_size - 1));
+ ctx->pos = ((loff_t)n << PAGE_SHIFT) + offset;
+ }
de = (struct nilfs_dir_entry *)(kaddr + offset);
limit = kaddr + nilfs_last_byte(inode, n) -
NILFS_DIR_REC_LEN(1);
--
2.53.0
^ permalink raw reply [flat|nested] 4+ messages in thread* Re: [PATCH 0/2] nilfs2: robustness fixes from Jake Labelle
2026-10-08 11:52 [PATCH 0/2] nilfs2: robustness fixes from Jake Labelle Ryusuke Konishi
2026-10-08 11:52 ` [PATCH 1/2] nilfs2: reject non-regular inodes in dsync recovery Ryusuke Konishi
2026-10-08 11:52 ` [PATCH 2/2] nilfs2: validate directory position after llseek in readdir Ryusuke Konishi
@ 2026-10-08 16:41 ` Viacheslav Dubeyko
2 siblings, 0 replies; 4+ messages in thread
From: Viacheslav Dubeyko @ 2026-10-08 16:41 UTC (permalink / raw)
To: Ryusuke Konishi; +Cc: linux-nilfs, LKML, Jake Labelle
On Thu, 2026-10-08 at 20:52 +0900, Ryusuke Konishi wrote:
> Hi Viacheslav,
>
> Please add the following two commits from Jake Labelle to your queue
> for the next cycle.
>
> As this cycle is getting closer to its end, I am sending these ahead
> with
> a minor fix applied. If Jake responds with further comments or
> revised
> proposals later, we can discuss them as needed.
>
> These patches address two robustness issues:
>
> - Patch 1/2 rejects special inodes during dsync recovery to prevent
> dereferencing uninitialized bmap function pointers.
> - Patch 2/2 validates and snaps the directory position after llseek
> in
> nilfs_readdir() to prevent invalid or out-of-bounds page reads.
>
> For full context and background details, please refer to the original
> cover letter here:
>
> https://lore.kernel.org/all/20260930000954.371774-1-southampton.jake.labelle@gmail.com
>
> Thanks,
> Ryusuke Konishi
>
> Jake Labelle (2):
> nilfs2: reject non-regular inodes in dsync recovery
> nilfs2: validate directory position after llseek in readdir
>
> fs/nilfs2/dir.c | 34 ++++++++++++++++++++++++++++++++++
> fs/nilfs2/recovery.c | 17 +++++++++++++++++
> 2 files changed, 51 insertions(+)
Applied.
Thanks,
Slava.
^ permalink raw reply [flat|nested] 4+ messages in thread