mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* [syzbot] [f2fs?] WARNING in f2fs_rename2 (2)
@ 2025-10-13 21:57 syzbot
  2025-10-22  9:09 ` Forwarded: [PATCH] f2fs: add validation for directory depth in sanity_check_inode syzbot
  2025-10-22 16:30 ` Forwarded: [PATCH] f2fs: invalidate dentry cache on failed whiteout creation syzbot
  0 siblings, 2 replies; 3+ messages in thread
From: syzbot @ 2025-10-13 21:57 UTC (permalink / raw)
  To: chao, jaegeuk, linux-f2fs-devel, linux-kernel, syzkaller-bugs

Hello,

syzbot found the following issue on:

HEAD commit:    bf45a62baffc Merge branch 'for-next/core' into for-kernelci
git tree:       git://git.kernel.org/pub/scm/linux/kernel/git/arm64/linux.git for-kernelci
console output: https://syzkaller.appspot.com/x/log.txt?x=113b0c58580000
kernel config:  https://syzkaller.appspot.com/x/.config?x=bd2356106f507975
dashboard link: https://syzkaller.appspot.com/bug?extid=632cf32276a9a564188d
compiler:       Debian clang version 20.1.8 (++20250708063551+0c9f909b7976-1~exp1~20250708183702.136), Debian LLD 20.1.8
userspace arch: arm64
syz repro:      https://syzkaller.appspot.com/x/repro.syz?x=100a3892580000
C reproducer:   https://syzkaller.appspot.com/x/repro.c?x=151c5b34580000

Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/f0d4874557e9/disk-bf45a62b.raw.xz
vmlinux: https://storage.googleapis.com/syzbot-assets/0bf44a13b5b2/vmlinux-bf45a62b.xz
kernel image: https://storage.googleapis.com/syzbot-assets/18db8bc9907c/Image-bf45a62b.gz.xz
mounted in repro: https://storage.googleapis.com/syzbot-assets/33a03f772bd8/mount_0.gz
  fsck result: failed (log: https://syzkaller.appspot.com/x/fsck.log?x=15cce542580000)

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+632cf32276a9a564188d@syzkaller.appspotmail.com

F2FS-fs (loop0): Mounted with checkpoint version = 48b305e4
F2FS-fs (loop0): Corrupted max_depth of 3: 16842753
------------[ cut here ]------------
WARNING: CPU: 0 PID: 6707 at fs/inode.c:417 drop_nlink+0xe4/0x138 fs/inode.c:417
Modules linked in:
CPU: 0 UID: 0 PID: 6707 Comm: syz.0.17 Not tainted syzkaller #0 PREEMPT 
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 06/30/2025
pstate: 83400005 (Nzcv daif +PAN -UAO +TCO +DIT -SSBS BTYPE=--)
pc : drop_nlink+0xe4/0x138 fs/inode.c:417
lr : drop_nlink+0xe4/0x138 fs/inode.c:417
sp : ffff80009e187740
x29: ffff80009e187740 x28: 0000000000000000 x27: ffff0000d416503f
x26: ffff0000f68508f8 x25: ffff0000f69f08f8 x24: 0000000000000000
x23: 1fffe0001ed0a247 x22: dfff800000000000 x21: 0000000000000000
x20: ffff0000f6851238 x19: ffff0000f68511f0 x18: 00000000ffffffff
x17: ffff800093605000 x16: ffff800080528494 x15: 0000000000000001
x14: 1fffe0001ed0a2d5 x13: 0000000000000000 x12: 0000000000000000
x11: ffff60001ed0a2d6 x10: 0000000000ff0100 x9 : 0000000000000000
x8 : ffff0000c7453d00 x7 : ffff80008269f9fc x6 : 0000000000000000
x5 : 0000000000000000 x4 : 0000000000000001 x3 : ffff80008052866c
x2 : 0000000000000001 x1 : 0000000000000000 x0 : 0000000000000000
Call trace:
 drop_nlink+0xe4/0x138 fs/inode.c:417 (P)
 f2fs_i_links_write fs/f2fs/f2fs.h:3233 [inline]
 f2fs_rename fs/f2fs/namei.c:1017 [inline]
 f2fs_rename2+0x1288/0x1fb4 fs/f2fs/namei.c:1290
 vfs_rename+0x934/0xce0 fs/namei.c:5129
 do_renameat2+0x614/0x8c8 fs/namei.c:5278
 __do_sys_renameat2 fs/namei.c:5312 [inline]
 __se_sys_renameat2 fs/namei.c:5309 [inline]
 __arm64_sys_renameat2+0xd8/0xf4 fs/namei.c:5309
 __invoke_syscall arch/arm64/kernel/syscall.c:35 [inline]
 invoke_syscall+0x98/0x254 arch/arm64/kernel/syscall.c:49
 el0_svc_common+0x130/0x23c arch/arm64/kernel/syscall.c:132
 do_el0_svc+0x48/0x58 arch/arm64/kernel/syscall.c:151
 el0_svc+0x5c/0x254 arch/arm64/kernel/entry-common.c:744
 el0t_64_sync_handler+0x84/0x12c arch/arm64/kernel/entry-common.c:763
 el0t_64_sync+0x198/0x19c arch/arm64/kernel/entry.S:596
irq event stamp: 170020
hardirqs last  enabled at (170019): [<ffff800080630af8>] seqcount_lockdep_reader_access+0x7c/0xf8 include/linux/seqlock.h:74
hardirqs last disabled at (170020): [<ffff80008b05ee64>] el1_brk64+0x20/0x54 arch/arm64/kernel/entry-common.c:434
softirqs last  enabled at (169238): [<ffff800080202608>] local_bh_enable+0x10/0x34 include/linux/bottom_half.h:32
softirqs last disabled at (169236): [<ffff8000802025d4>] local_bh_disable+0x10/0x34 include/linux/bottom_half.h:19
---[ end trace 0000000000000000 ]---


---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzkaller@googlegroups.com.

syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

If the report is already addressed, let syzbot know by replying with:
#syz fix: exact-commit-title

If you want syzbot to run the reproducer, reply with:
#syz test: git://repo/address.git branch-or-commit-hash
If you attach or paste a git patch, syzbot will apply it before testing.

If you want to overwrite report's subsystems, reply with:
#syz set subsystems: new-subsystem
(See the list of subsystem names on the web dashboard)

If the report is a duplicate of another one, reply with:
#syz dup: exact-subject-of-another-report

If you want to undo deduplication, reply with:
#syz undup

^ permalink raw reply	[flat|nested] 3+ messages in thread

* Forwarded: [PATCH] f2fs: add validation for directory depth in sanity_check_inode
  2025-10-13 21:57 [syzbot] [f2fs?] WARNING in f2fs_rename2 (2) syzbot
@ 2025-10-22  9:09 ` syzbot
  2025-10-22 16:30 ` Forwarded: [PATCH] f2fs: invalidate dentry cache on failed whiteout creation syzbot
  1 sibling, 0 replies; 3+ messages in thread
From: syzbot @ 2025-10-22  9:09 UTC (permalink / raw)
  To: linux-kernel, syzkaller-bugs

For archival purposes, forwarding an incoming command email to
linux-kernel@vger.kernel.org, syzkaller-bugs@googlegroups.com.

***

Subject: [PATCH] f2fs: add validation for directory depth in sanity_check_inode
Author: kartikey406@gmail.com

#syz test git://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git master


F2FS can mount a corrupted filesystem with an invalid directory depth
value (i_current_depth). When this corrupted directory is accessed
during operations like rename, F2FS fails to properly locate and delete
directory entries, leading to inconsistent inode state.

This triggers a warning in drop_nlink() when attempting to decrement
i_nlink from 0, as directory entries persist even after the link count
reaches zero.

Add validation in sanity_check_inode() to reject inodes with
i_current_depth exceeding MAX_DIR_HASH_DEPTH (63). This prevents
mounting corrupted filesystems and avoids subsequent filesystem
inconsistencies.

Reproducer:
1. Mount corrupted F2FS image with i_current_depth = 16842753
2. Perform rename operations on files in the corrupted directory
3. System triggers WARNING in drop_nlink() due to i_nlink underflow

With this fix, the corrupted filesystem is rejected at mount time
with a clear error message.

Reported-by: syzbot+632cf32276a9a564188d@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=632cf32276a9a564188d
Signed-off-by: Deepanshu Kartikey <kartikey406@gmail.com>
---
 fs/f2fs/inode.c | 10 ++++++++++
 1 file changed, 10 insertions(+)

diff --git a/fs/f2fs/inode.c b/fs/f2fs/inode.c
index 8c4eafe9ffac..276adfbd5b30 100644
--- a/fs/f2fs/inode.c
+++ b/fs/f2fs/inode.c
@@ -294,6 +294,17 @@ static bool sanity_check_inode(struct inode *inode, struct folio *node_folio)
 		return false;
 	}
 
+	/* Validate directory depth */
+	if (S_ISDIR(le16_to_cpu(ri->i_mode))) {
+		unsigned int current_depth = le32_to_cpu(ri->i_current_depth);
+
+		if (current_depth > MAX_DIR_HASH_DEPTH) {
+			f2fs_warn(sbi, "%s: corrupted inode i_ino=%lx has invalid i_current_depth: %u, max: %u, run fsck to fix.",
+				  __func__, inode->i_ino, current_depth, MAX_DIR_HASH_DEPTH);
+			return false;
+		}
+	}
+
 	if (f2fs_has_extra_attr(inode)) {
 		if (!f2fs_sb_has_extra_attr(sbi)) {
 			f2fs_warn(sbi, "%s: inode (ino=%lx) is with extra_attr, but extra_attr feature is off",
-- 
2.43.0


^ permalink raw reply	[flat|nested] 3+ messages in thread

* Forwarded: [PATCH] f2fs: invalidate dentry cache on failed whiteout creation
  2025-10-13 21:57 [syzbot] [f2fs?] WARNING in f2fs_rename2 (2) syzbot
  2025-10-22  9:09 ` Forwarded: [PATCH] f2fs: add validation for directory depth in sanity_check_inode syzbot
@ 2025-10-22 16:30 ` syzbot
  1 sibling, 0 replies; 3+ messages in thread
From: syzbot @ 2025-10-22 16:30 UTC (permalink / raw)
  To: linux-kernel, syzkaller-bugs

For archival purposes, forwarding an incoming command email to
linux-kernel@vger.kernel.org, syzkaller-bugs@googlegroups.com.

***

Subject: [PATCH] f2fs: invalidate dentry cache on failed whiteout creation
Author: kartikey406@gmail.com

#syz test git://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git master

F2FS can mount filesystems with corrupted directory depth values that
get runtime-clamped to MAX_DIR_HASH_DEPTH. When RENAME_WHITEOUT
operations are performed on such directories, f2fs_rename performs
directory modifications (updating target entry and deleting source
entry) before attempting to add the whiteout entry via f2fs_add_link.

If f2fs_add_link fails due to the corrupted directory structure, the
function returns an error to VFS, but the partial directory
modifications have already been committed to disk. VFS assumes the
entire rename operation failed and does not update the dentry cache,
leaving stale mappings.

This causes subsequent operations to use cached dentry information that
no longer matches the on-disk state. When a second rename targets the
same entry, VFS attempts to decrement i_nlink on the stale inode, which
may already have i_nlink=0, triggering a WARNING in drop_nlink().

Example sequence:
1. First rename (RENAME_WHITEOUT): file2 → file1
   - f2fs updates file1 entry on disk (points to inode 8)
   - f2fs deletes file2 entry on disk
   - f2fs_add_link(whiteout) fails (corrupted directory)
   - Returns error to VFS
   - VFS cache still has: file1 → inode 7 (stale!)

2. Second rename: file3 → file1
   - VFS uses stale cache: file1 → inode 7
   - Tries to drop_nlink on inode 7 (i_nlink already 0)
   - WARNING in drop_nlink()

Fix this by explicitly invalidating old_dentry and new_dentry when
f2fs_add_link fails during whiteout creation. This forces VFS to
refresh from disk on subsequent operations, ensuring cache consistency
even when the rename partially succeeds.

Reproducer:
1. Mount F2FS image with corrupted i_current_depth
2. renameat2(file2, file1, RENAME_WHITEOUT)
3. renameat2(file3, file1, 0)
4. System triggers WARNING in drop_nlink()

Reported-by: syzbot+632cf32276a9a564188d@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=632cf32276a9a564188d
Signed-off-by: Deepanshu Kartikey <kartikey406@gmail.com>
---
 fs/f2fs/namei.c | 6 ++++--
 1 file changed, 4 insertions(+), 2 deletions(-)

diff --git a/fs/f2fs/namei.c b/fs/f2fs/namei.c
index b882771e4699..712479b7b93d 100644
--- a/fs/f2fs/namei.c
+++ b/fs/f2fs/namei.c
@@ -1053,9 +1053,11 @@ static int f2fs_rename(struct mnt_idmap *idmap, struct inode *old_dir,
 	if (whiteout) {
 		set_inode_flag(whiteout, FI_INC_LINK);
 		err = f2fs_add_link(old_dentry, whiteout);
-		if (err)
+		if (err) {
+			d_invalidate(old_dentry);
+			d_invalidate(new_dentry);
 			goto put_out_dir;
-
+		}
 		spin_lock(&whiteout->i_lock);
 		whiteout->i_state &= ~I_LINKABLE;
 		spin_unlock(&whiteout->i_lock);
-- 
2.43.0


^ permalink raw reply	[flat|nested] 3+ messages in thread

end of thread, other threads:[~2025-10-22 16:30 UTC | newest]

Thread overview: 3+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2025-10-13 21:57 [syzbot] [f2fs?] WARNING in f2fs_rename2 (2) syzbot
2025-10-22  9:09 ` Forwarded: [PATCH] f2fs: add validation for directory depth in sanity_check_inode syzbot
2025-10-22 16:30 ` Forwarded: [PATCH] f2fs: invalidate dentry cache on failed whiteout creation syzbot

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®