mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: Joseph Qi <joseph.qi@linux.alibaba.com>
To: ZhengYuan Huang <gality369@gmail.com>
Cc: mark@fasheh.com, jlbec@evilplan.org, ocfs2-devel@lists.linux.dev,
	linux-kernel@vger.kernel.org, baijiaju1990@gmail.com,
	r33s3n6@gmail.com, zzzccc427@gmail.com, tom442288@tuta.io
Subject: Re: [PATCH] ocfs2: validate truncate log dinode before caching
Date: Thu, 23 Jul 2026 11:40:21 +0800	[thread overview]
Message-ID: <4be16c98-32c1-4d87-beeb-368a45dafa40@linux.alibaba.com> (raw)
In-Reply-To: <CAOmEq9V-g+AxUw9XZr2Kk5_MYffAndsrbTPfXOyKDiH-eGSKGg@mail.gmail.com>



On 7/23/26 11:05 AM, ZhengYuan Huang wrote:
> On Wed, Jul 22, 2026 at 8:56 PM Joseph Qi <joseph.qi@linux.alibaba.com> wrote:
>>
>>
>>
>> On 7/22/26 5:11 PM, ZhengYuan Huang wrote:
>>> [BUG]
>>> A corrupted truncate log dinode can pass through mount initialization and
>>> reach the delayed flush worker, where it triggers:
>>>
>>> kernel BUG at fs/ocfs2/alloc.c:6019!
>>> Oops: invalid opcode: 0000 [#1] SMP KASAN NOPTI
>>> RIP: 0010:__ocfs2_flush_truncate_log+0xa87/0xf10 fs/ocfs2/alloc.c:6019
>>> Call Trace:
>>>  ocfs2_flush_truncate_log fs/ocfs2/alloc.c:6084 [inline]
>>>  ocfs2_truncate_log_worker+0xa9/0x180 fs/ocfs2/alloc.c:6097
>>>  process_one_work+0x8e0/0x1980 kernel/workqueue.c:3263
>>>  ...
>>>
>>
>> I've encountered this BUG occasionality. But I don't see why it happens.
>> Do you have more clues on how to reproduce it?
>>
>> Thanks,
>> Joseph
> 
> Thanks for looking into this.
> 
> This bug was originally found by our fuzzing tool. We tried to
> reproduce it using the automatically saved disk image and syscall
> program, but so far we have been unable to reproduce the BUG in
> __ocfs2_flush_truncate_log directly. Instead, the same artifacts have
> triggered two other issues:
> 
> KASAN: use-after-free Read in ocfs2_dx_dir_search
> kernel BUG in ocfs2_grow_tree
> 
> For the use-after-free in ocfs2_dx_dir_search, I previously submitted
> a patch that addresses what I believe is its root cause:
> 
> https://lore.kernel.org/all/20260416082105.1295887-1-gality369@gmail.com/
> 
> However, I have not received any feedback on the patch yet, and at
> this point we are not sure whether that issue is related to the
> truncate-log corruption reported here.
> 

It seems I've missed the thread.

And I've found a similar one in:
https://lore.kernel.org/ocfs2-devel/20260713205625.92391-1-doruk@0sec.ai/

Could you please check if it fixes the same issue?

Thanks,
Joseph

> We are continuing to investigate and will share any new findings. In
> the meantime, the original artifacts generated by our fuzzer are
> available here:
> 
> https://drive.google.com/file/d/1zCJoUb2uwVqTrGIM4JFLbwkcHRz04TJo/view?usp=sharing
> 
> The archive contains the disk image, the PoC program, and a kernel
> log. To run the reproducer, mount the supplied disk image and execute
> the PoC. Please note that, in our current tests, these artifacts can
> trigger the two issues mentioned above, but they do not reproduce the
> BUG in __ocfs2_flush_truncate_log. The archive also includes the
> kernel log captured when the original BUG occurred, which may help
> with further investigation.
> 
> Thanks,
> ZhengYuan Huang


  reply	other threads:[~2026-07-23  3:40 UTC|newest]

Thread overview: 5+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-07-22  9:11 ZhengYuan Huang
2026-07-22 12:55 ` Joseph Qi
2026-07-23  3:05   ` ZhengYuan Huang
2026-07-23  3:40     ` Joseph Qi [this message]
2026-08-03  2:55       ` ZhengYuan Huang

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=4be16c98-32c1-4d87-beeb-368a45dafa40@linux.alibaba.com \
    --to=joseph.qi@linux.alibaba.com \
    --cc=baijiaju1990@gmail.com \
    --cc=gality369@gmail.com \
    --cc=jlbec@evilplan.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=mark@fasheh.com \
    --cc=ocfs2-devel@lists.linux.dev \
    --cc=r33s3n6@gmail.com \
    --cc=tom442288@tuta.io \
    --cc=zzzccc427@gmail.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®