From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-ej1-f45.google.com (mail-ej1-f45.google.com [209.85.218.45]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 7EFBD15535A for ; Tue, 14 Jan 2025 14:51:17 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.218.45 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1736866279; cv=none; b=mQjJTa07oOkjzK6V0hoGQXXDrardeG1fQvtz7rxqaaxpfVWyU+eYwlK3W73itdUT6xAlqrPgXacqSE2fGjPqfiUfc/vWCHn8M3LzxoSICvyTr7yUP41HBiwHf2xv9A7yID/43Rn7noZpD6HIOxNIf/orCfbni2fLK47A9ejMu8Q= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1736866279; c=relaxed/simple; bh=OnivAETXnsBl7mXrjeIuhqyy2UMVgs8PMFytRZ0/6SI=; h=Message-ID:Date:MIME-Version:Subject:To:Cc:References:From: In-Reply-To:Content-Type; b=pJwARyUtWBelLqdsY8YqMgaFVlb+cSUwo2/pZwvpUIctDuBieMWbr+sLlysHLD0xtIi8JvMCHiC7fv0CIYUHfFs7Sfm8MLy5vP7jp7AUa1sjophdta89SpSm2X8Qs1qp4V5vGmiubNmsTxgTiDS6iOoos6oWKyJ5xDIa6YwFMbU= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=suse.com; spf=pass smtp.mailfrom=suse.com; dkim=pass (2048-bit key) header.d=suse.com header.i=@suse.com header.b=SPqUfLLb; arc=none smtp.client-ip=209.85.218.45 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=suse.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=suse.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=suse.com header.i=@suse.com header.b="SPqUfLLb" Received: by mail-ej1-f45.google.com with SMTP id a640c23a62f3a-ab30614c1d6so58008966b.1 for ; Tue, 14 Jan 2025 06:51:17 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=suse.com; s=google; t=1736866276; x=1737471076; darn=vger.kernel.org; h=content-transfer-encoding:in-reply-to:from:content-language :references:cc:to:subject:user-agent:mime-version:date:message-id :from:to:cc:subject:date:message-id:reply-to; bh=pGaLjip8ws2aBkJc+HkZKzrNkaPfpsakY2s6/rWCOro=; b=SPqUfLLbtWwrVB4RhYKh9aeX9GlxvkdK+OwG8Py3l7JqXiCusJScv4GzdghTQmg2Aj eexdqyaLTSlju51DU0obUjfhjUtF1kaHGQrCcEk+rGJyOJt1CcnSr8StIXQbJQ/gwHcQ rwb+bp7bo4VY3NqhLzmU7+fQYMw3c4xUDc2P2w7D5Gp+4PwoeC17I+MTnDtXWDBKbjjb 7C3ijSur3NvYWwi9gZrEXtSKQGKyyp8t0AANkhHhxyxexW9HT//KruIH2sMz2Vu+Hkjq nyYL4fkUoPFEvwruPB+1CRLDY4LP6pelPUsBWzMk4kzYZrdRG3l2PfKEaOD0a2n2XgfQ yS2Q== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1736866276; x=1737471076; h=content-transfer-encoding:in-reply-to:from:content-language :references:cc:to:subject:user-agent:mime-version:date:message-id :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to; bh=pGaLjip8ws2aBkJc+HkZKzrNkaPfpsakY2s6/rWCOro=; b=T7WMDL7df5PXVWExCg6lxcmVb8D76b4mjcrk3nohzLm4Uhr9BJtlFZH4Dksz1e6O0Y F7S2aFDSArWifW17sgzqImsXyZiK0SAyBMJNF/g7iV1yAFjqFLp1c8UVmBFiqhz8q4al GTZVap4EBzKV3zyAOB+y+p1MvEr7lzwXcgxOe1+2IrmOZATebB2bHvRSrQgiBQgC1Nft NQAEh55eKlymK+WuLYpGQPNdDtInXve1CF4n8me5xY8gP0aorKT5XFf0+B8ZH/aPCbJ3 ocQmo1AtuzRLYiQ9q54R+dTgON7tsPaGR++PL4GGXFM4y7DwK/rao8NzOP5klS+V/n4d Efeg== X-Forwarded-Encrypted: i=1; AJvYcCWT5YllWWh3enDSf9HAzPi/Fj6GrIf8ZpHkr8lboQe/rJuc2K3dzOjwLak6qbAdkIZm/HULrji8W0evFUE=@vger.kernel.org X-Gm-Message-State: AOJu0YyGOylu3nj2Fydw90BqKI35G7Wm7oHda7ZlmKb8a6ScBY/acOhk 9R5M7T6dKmwMxfISij5la54Ty5mzeCjZIyjuDrVnjWCRD9+SZ6ip/VC0zMYsMzs= X-Gm-Gg: ASbGnct1p5cuNaikj9TPncK0J2YFytfIpYSbcJCeEjjfjcQ6O4KGm4Ml9IwPoTItSna sGfPVbd7NqLWMB3fqb0w/Y37P29BwAMHFsFqTUXPuEjox8TybVQQW56pycOrKVfcnXACbWAPaSF 6dWkwq1AkST97vvVigRE+Mp/qp7WYAjagjPjARV5bcTwz7DirerL7iJsxE4T2a13z3tvkwz/n3t c6HjaBAIDKwxnAS2HLJb1rLsqr3/UAWTxIzulaxBY4dAa8uDdxztYD8By0DqWs= X-Google-Smtp-Source: AGHT+IEekbyRZetOC3fp4MjYg219+9eB5QuJKqBG/xAtl77M4ni+Kg/FKCcbgOEGbgD4MYoZu3NqAQ== X-Received: by 2002:a17:907:d0f:b0:aae:83c7:fd4e with SMTP id a640c23a62f3a-ab2abc95fcbmr744650666b.13.1736866275808; Tue, 14 Jan 2025 06:51:15 -0800 (PST) Received: from [10.202.112.30] ([202.127.77.110]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-72d40692172sm7496304b3a.154.2025.01.14.06.51.12 (version=TLS1_3 cipher=TLS_AES_128_GCM_SHA256 bits=128/128); Tue, 14 Jan 2025 06:51:15 -0800 (PST) Message-ID: <3655551d-b881-4f2b-8419-03efe4d3aca7@suse.com> Date: Tue, 14 Jan 2025 22:51:10 +0800 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 User-Agent: Mozilla Thunderbird Subject: Re: WARNING in jbd2_journal_update_sb_log_tail To: Theodore Ts'o Cc: Jan Kara , Liebes Wang , jack@suse.com, linux-ext4@vger.kernel.org, linux-kernel@vger.kernel.org, syzkaller@googlegroups.com, Joseph Qi , ocfs2-devel@lists.linux.dev References: <24f378c8-7a27-47b8-bd79-dba4a2e92f6d@suse.com> <20250114133815.GA1997324@mit.edu> Content-Language: en-US From: Heming Zhao In-Reply-To: <20250114133815.GA1997324@mit.edu> Content-Type: text/plain; charset=UTF-8; format=flowed Content-Transfer-Encoding: 7bit Hi Ted, On 1/14/25 21:38, Theodore Ts'o wrote: > On Tue, Jan 14, 2025 at 02:25:21PM +0800, Heming Zhao wrote: >> >> The root cause appears to be that the jbd2 bypass recovery logic >> is incorrect. > > Heming, thanks for taking a look. > > I'm not convinced the root cause is what you've stated. When > jbd2_journal_wipe() calls jbd2_mark_journal_empty(), s_start gets set > to zero: Actually, ocfs2 calls jbd2_journal_wipe() with 'write=0' (hard coded), so jbd2_mark_journal_empty() isn't called during the ocfs2 mount phase. This means the following deduction won't apply in this case. -- Heming > > sb->s_start = cpu_to_be32(0); > > This then gets checked in jbd2_journal_recovery: > > if (!sb->s_start) { > jbd2_debug(1, "No recovery required, last transaction %d, head block %u\n", > be32_to_cpu(sb->s_sequence), be32_to_cpu(sb->s_head)); > journal->j_transaction_sequence = be32_to_cpu(sb->s_sequence) + 1; > journal->j_head = be32_to_cpu(sb->s_head); > return 0; > } > > I suspect that there is something else wrong with jbd2's superblock, > since this normally works in the absence of malicious fs image > fuzzing, such that when jbd2_journal_load() calls reset_journal() > after jbd2_journal_recover() correctly bypasses recovery, the WARN_ON > gets triggered. > > I'd suggest that you enable jbd2 debugging so we can see all of the > jbd2_debug() message to understand what might be going on. > > By the way, given that this is only a WARN_ON, and it involves > malicious image fuzzing, this is probably a valid jbd2 bug, but it's > not actually a security bug. Sure, someone silly enough to pick up a > maliciously corrupted USB thumb drive dropped in a parking lot and > insert it into their desktop, and the distribution is silly enoough to > allow automount, the worse that can happen is that the system to > reboot if the system is configured to panic on a WARNING. So feel > free to prioritize your investigation appropriately. :-) > > Cheers, > > - Ted