* Re: [syzbot] [ext4?] KASAN: slab-use-after-free Write in do_split
2026-09-28 21:54 [syzbot] [ext4?] KASAN: slab-use-after-free Write in do_split syzbot
@ 2026-09-29 0:32 ` syzbot
2026-09-29 1:00 ` Qu Wenruo
2026-10-01 19:48 ` Forwarded: [PATCH] ext4: validate dirents before splitting a directory syzbot
` (5 subsequent siblings)
6 siblings, 1 reply; 9+ messages in thread
From: syzbot @ 2026-09-29 0:32 UTC (permalink / raw)
To: adilger.kernel, boris, dsterba, dsterba, fdmanana, jack,
libaokun, linux-ext4, linux-kernel, ojaswin, ritesh.list,
syzkaller-bugs, tytso, wqu, yi.zhang
syzbot has bisected this issue to:
commit 3f757b56f1c4579fe32b810bce1d39f202964412
Author: Filipe Manana <fdmanana@suse.com>
Date: Fri May 16 16:07:40 2025 +0000
btrfs: unfold transaction aborts at btrfs_create_new_inode()
bisection log: https://syzkaller.appspot.com/x/bisect.txt?x=16bbf315580000
start commit: 72d3fcf802c4 Linux 7.3-rc5
git tree: upstream
final oops: https://syzkaller.appspot.com/x/report.txt?x=15bbf315580000
console output: https://syzkaller.appspot.com/x/log.txt?x=11bbf315580000
kernel config: https://syzkaller.appspot.com/x/.config?x=718e346eb0b8f38
dashboard link: https://syzkaller.appspot.com/bug?extid=09bec78ee77613a3efdd
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=12379605580000
C reproducer: https://syzkaller.appspot.com/x/repro.c?x=127f6325580000
Reported-by: syzbot+09bec78ee77613a3efdd@syzkaller.appspotmail.com
Fixes: 3f757b56f1c4 ("btrfs: unfold transaction aborts at btrfs_create_new_inode()")
For information about bisection process see: https://goo.gl/tpsmEJ#bisection
^ permalink raw reply [flat|nested] 9+ messages in thread* Re: [syzbot] [ext4?] KASAN: slab-use-after-free Write in do_split
2026-09-29 0:32 ` syzbot
@ 2026-09-29 1:00 ` Qu Wenruo
0 siblings, 0 replies; 9+ messages in thread
From: Qu Wenruo @ 2026-09-29 1:00 UTC (permalink / raw)
To: syzbot, adilger.kernel, boris, dsterba, dsterba, fdmanana, jack,
libaokun, linux-ext4, linux-kernel, ojaswin, ritesh.list,
syzkaller-bugs, tytso, yi.zhang
在 2026/9/29 10:02, syzbot 写道:
> syzbot has bisected this issue to:
>
> commit 3f757b56f1c4579fe32b810bce1d39f202964412
> Author: Filipe Manana <fdmanana@suse.com>
> Date: Fri May 16 16:07:40 2025 +0000
>
> btrfs: unfold transaction aborts at btrfs_create_new_inode()
This bisection doesn't make any sense.
The console output is showing ext4_add_entry()->do_split() causing the
KASAN.
Furthermore, there is no btrfs in the whole console output.
There must be some randomness in the reproducer.
>
> bisection log: https://syzkaller.appspot.com/x/bisect.txt?x=16bbf315580000
> start commit: 72d3fcf802c4 Linux 7.3-rc5
> git tree: upstream
> final oops: https://syzkaller.appspot.com/x/report.txt?x=15bbf315580000
> console output: https://syzkaller.appspot.com/x/log.txt?x=11bbf315580000
> kernel config: https://syzkaller.appspot.com/x/.config?x=718e346eb0b8f38
> dashboard link: https://syzkaller.appspot.com/bug?extid=09bec78ee77613a3efdd
> syz repro: https://syzkaller.appspot.com/x/repro.syz?x=12379605580000
> C reproducer: https://syzkaller.appspot.com/x/repro.c?x=127f6325580000
>
> Reported-by: syzbot+09bec78ee77613a3efdd@syzkaller.appspotmail.com
> Fixes: 3f757b56f1c4 ("btrfs: unfold transaction aborts at btrfs_create_new_inode()")
>
> For information about bisection process see: https://goo.gl/tpsmEJ#bisection
^ permalink raw reply [flat|nested] 9+ messages in thread
* Forwarded: [PATCH] ext4: validate dirents before splitting a directory
2026-09-28 21:54 [syzbot] [ext4?] KASAN: slab-use-after-free Write in do_split syzbot
2026-09-29 0:32 ` syzbot
@ 2026-10-01 19:48 ` syzbot
2026-10-01 20:34 ` Forwarded: [PATCH] ext4: don't trust on-disk rec_len in dx_move_dirents() syzbot
` (4 subsequent siblings)
6 siblings, 0 replies; 9+ messages in thread
From: syzbot @ 2026-10-01 19:48 UTC (permalink / raw)
To: linux-kernel
For archival purposes, forwarding an incoming command email to
linux-kernel@vger.kernel.org.
***
Subject: [PATCH] ext4: validate dirents before splitting a directory
Author: adrianox@gmail.com
#syz test: upstream master
syzbot reported a slab-use-after-free write in do_split() while
renaming an entry in a directory that is being converted into an
indexed (htree) directory by make_indexed_dir():
BUG: KASAN: slab-use-after-free in dx_move_dirents [inline]
BUG: KASAN: slab-use-after-free in do_split+0x1241/0x1e90
Write of size 90458 at addr ffff88803b38ac6e by task syz.0.17/6003
do_split() builds a map of the leaf's dirents and then moves a subset
of them to a new block. dx_move_dirents() trusts map[i].offs and uses
the rec_len found there as the length of a memset(). With a corrupted
or crafted directory block, a bogus map entry makes that rec_len
garbage (here 90464), turning the memset() into an out-of-bounds write
that can corrupt arbitrary memory.
Validate each entry that is about to be moved with
ext4_check_dir_entry() before using it, and bail out with
-EFSCORRUPTED if the entry does not lie inside the block. This is the
same class of validation already used elsewhere in the directory code.
This is a filesystem-corruption hardening issue; the crash needs a
corrupt directory, which is why it is not reachable on a consistent
filesystem. The syzbot "introduced by" bisection pointed at an
unrelated btrfs commit and can be ignored.
Closes: https://syzkaller.appspot.com/bug?extid=09bec78ee77613a3efdd
---
fs/ext4/namei.c | 19 +++++++++++++++++++
1 file changed, 19 insertions(+)
diff --git a/fs/ext4/namei.c b/fs/ext4/namei.c
index a6386c1d237f..b2ec222b15e4 100644
--- a/fs/ext4/namei.c
+++ b/fs/ext4/namei.c
@@ -1951,6 +1951,25 @@ static struct ext4_dir_entry_2 *do_split(handle_t *handle, struct inode *dir,
goto journal_error;
}
map -= count;
+ /*
+ * The map is built from the on-disk dirents, so its entries should
+ * always refer to valid dirents. However, if the leaf block is
+ * corrupted (e.g. a crafted image), a bogus map entry can make
+ * dx_move_dirents() read a rec_len from an arbitrary location and use
+ * it as the length of a memset(), writing far out of bounds. Validate
+ * every entry we are about to move before using it.
+ */
+ for (i = 0; i < count; i++) {
+ unsigned int off = map[i].offs << 2;
+
+ if (off > blocksize - sizeof(struct ext4_dir_entry_2) ||
+ ext4_check_dir_entry(dir, NULL,
+ (struct ext4_dir_entry_2 *)(data1 + off),
+ *bh, data1, blocksize, off)) {
+ err = -EFSCORRUPTED;
+ goto out;
+ }
+ }
dx_sort_map(map, count);
/* Ensure that neither split block is over half full */
size = 0;
--
2.51.0
^ permalink raw reply [flat|nested] 9+ messages in thread* Forwarded: [PATCH] ext4: don't trust on-disk rec_len in dx_move_dirents()
2026-09-28 21:54 [syzbot] [ext4?] KASAN: slab-use-after-free Write in do_split syzbot
2026-09-29 0:32 ` syzbot
2026-10-01 19:48 ` Forwarded: [PATCH] ext4: validate dirents before splitting a directory syzbot
@ 2026-10-01 20:34 ` syzbot
2026-10-01 21:30 ` syzbot
` (3 subsequent siblings)
6 siblings, 0 replies; 9+ messages in thread
From: syzbot @ 2026-10-01 20:34 UTC (permalink / raw)
To: linux-kernel
For archival purposes, forwarding an incoming command email to
linux-kernel@vger.kernel.org.
***
Subject: [PATCH] ext4: don't trust on-disk rec_len in dx_move_dirents()
Author: adrianox@gmail.com
#syz test: upstream master
---
fs/ext4/namei.c | 38 ++++++++++++++++++++++++++++++--------
1 file changed, 30 insertions(+), 8 deletions(-)
diff --git a/fs/ext4/namei.c b/fs/ext4/namei.c
index a6386c1d237f..83e4564f9f44 100644
--- a/fs/ext4/namei.c
+++ b/fs/ext4/namei.c
@@ -1840,30 +1840,46 @@ struct dentry *ext4_get_parent(struct dentry *child)
/*
* Move count entries from end of map between two memory locations.
- * Returns pointer to last entry moved.
+ * Returns pointer to last entry moved or an ERR_PTR on a corrupt entry.
*/
static struct ext4_dir_entry_2 *
dx_move_dirents(struct inode *dir, char *from, char *to,
struct dx_map_entry *map, int count,
unsigned blocksize)
{
+ char *to_start = to;
unsigned rec_len = 0;
while (count--) {
- struct ext4_dir_entry_2 *de = (struct ext4_dir_entry_2 *)
- (from + (map->offs<<2));
+ unsigned int off = map->offs << 2;
+ struct ext4_dir_entry_2 *de;
+
+ /*
+ * The map is built from on-disk dirents, but a corrupted or
+ * concurrently reused leaf block can still make an entry point
+ * outside the block. Never dereference such an entry.
+ */
+ if (off > blocksize - sizeof(struct ext4_dir_entry_2))
+ return ERR_PTR(-EFSCORRUPTED);
+ de = (struct ext4_dir_entry_2 *)(from + off);
rec_len = ext4_dir_rec_len(de->name_len, dir);
+ if (off + rec_len > blocksize ||
+ to + rec_len > to_start + blocksize)
+ return ERR_PTR(-EFSCORRUPTED);
memcpy (to, de, rec_len);
((struct ext4_dir_entry_2 *) to)->rec_len =
ext4_rec_len_to_disk(rec_len, blocksize);
- /* wipe dir_entry excluding the rec_len field */
+ /*
+ * Wipe dir_entry excluding the rec_len field. Use the entry's
+ * own (minimal) length instead of the untrusted on-disk rec_len,
+ * which on a corrupt block decodes to an arbitrary huge value
+ * and turns this into an out-of-bounds memset().
+ */
de->inode = 0;
- memset(&de->name_len, 0, ext4_rec_len_from_disk(de->rec_len,
- blocksize) -
- offsetof(struct ext4_dir_entry_2,
- name_len));
+ memset(&de->name_len, 0, rec_len -
+ offsetof(struct ext4_dir_entry_2, name_len));
map++;
to += rec_len;
@@ -1992,6 +2008,12 @@ static struct ext4_dir_entry_2 *do_split(handle_t *handle, struct inode *dir,
/* Fancy dance to stay within two buffers */
de2 = dx_move_dirents(dir, data1, data2, map + split, count - split,
blocksize);
+ if (IS_ERR(de2)) {
+ ext4_error_inode_block(dir, (*bh)->b_blocknr, 0,
+ "bad indexed directory entry");
+ err = PTR_ERR(de2);
+ goto out;
+ }
de = dx_pack_dirents(dir, data1, blocksize);
de->rec_len = ext4_rec_len_to_disk(data1 + (blocksize - csum_size) -
(char *) de,
--
2.51.0
^ permalink raw reply [flat|nested] 9+ messages in thread* Forwarded: [PATCH] ext4: don't trust on-disk rec_len in dx_move_dirents()
2026-09-28 21:54 [syzbot] [ext4?] KASAN: slab-use-after-free Write in do_split syzbot
` (2 preceding siblings ...)
2026-10-01 20:34 ` Forwarded: [PATCH] ext4: don't trust on-disk rec_len in dx_move_dirents() syzbot
@ 2026-10-01 21:30 ` syzbot
2026-10-04 18:49 ` Forwarded: [PATCH] ext4: don't append a directory block already mapped in the inode syzbot
` (2 subsequent siblings)
6 siblings, 0 replies; 9+ messages in thread
From: syzbot @ 2026-10-01 21:30 UTC (permalink / raw)
To: linux-kernel
For archival purposes, forwarding an incoming command email to
linux-kernel@vger.kernel.org.
***
Subject: [PATCH] ext4: don't trust on-disk rec_len in dx_move_dirents()
Author: adrianox@gmail.com
#syz test: upstream master
syzbot reported an out-of-bounds write from do_split() while a directory
is converted to an indexed one:
BUG: KASAN: slab-out-of-bounds in dx_move_dirents [inline]
BUG: KASAN: slab-out-of-bounds in do_split+0xf9c/0x1de0
Write of size 90458
dx_move_dirents() wipes the source entry using its on-disk rec_len.
That field can't be trusted: on a corrupt block it may be garbage
(0x6161 here) and ext4_rec_len_from_disk() turns it into a huge value,
so the memset() runs far past the block. The entry is already copied
using its own real length, so use that length for the wipe as well.
Closes: https://syzkaller.appspot.com/bug?extid=09bec78ee77613a3efdd
---
fs/ext4/namei.c | 6 ++----
1 file changed, 2 insertions(+), 4 deletions(-)
diff --git a/fs/ext4/namei.c b/fs/ext4/namei.c
index a6386c1d237f..71e9e7c9a7fd 100644
--- a/fs/ext4/namei.c
+++ b/fs/ext4/namei.c
@@ -1860,10 +1860,8 @@ dx_move_dirents(struct inode *dir, char *from, char *to,
/* wipe dir_entry excluding the rec_len field */
de->inode = 0;
- memset(&de->name_len, 0, ext4_rec_len_from_disk(de->rec_len,
- blocksize) -
- offsetof(struct ext4_dir_entry_2,
- name_len));
+ memset(&de->name_len, 0, rec_len -
+ offsetof(struct ext4_dir_entry_2, name_len));
map++;
to += rec_len;
--
2.51.0
^ permalink raw reply [flat|nested] 9+ messages in thread* Forwarded: [PATCH] ext4: don't append a directory block already mapped in the inode
2026-09-28 21:54 [syzbot] [ext4?] KASAN: slab-use-after-free Write in do_split syzbot
` (3 preceding siblings ...)
2026-10-01 21:30 ` syzbot
@ 2026-10-04 18:49 ` syzbot
2026-10-04 23:01 ` syzbot
2026-10-05 1:01 ` syzbot
6 siblings, 0 replies; 9+ messages in thread
From: syzbot @ 2026-10-04 18:49 UTC (permalink / raw)
To: linux-kernel
For archival purposes, forwarding an incoming command email to
linux-kernel@vger.kernel.org.
***
Subject: [PATCH] ext4: don't append a directory block already mapped in the inode
Author: adrianox@gmail.com
#syz test: upstream master
---
fs/ext4/namei.c | 30 ++++++++++++++++++++++++++++++
1 file changed, 30 insertions(+)
diff --git a/fs/ext4/namei.c b/fs/ext4/namei.c
index 3b9740c1c16d..7b356baf7bd4 100644
--- a/fs/ext4/namei.c
+++ b/fs/ext4/namei.c
@@ -83,6 +83,36 @@ static struct buffer_head *ext4_append(handle_t *handle,
bh = ext4_bread(handle, inode, *block, EXT4_GET_BLOCKS_CREATE);
if (IS_ERR(bh))
return bh;
+
+ /*
+ * The logical block was a hole, but a corrupt block bitmap can make
+ * the allocator hand out a physical block that is already in use,
+ * possibly by another block of this very inode. Callers such as
+ * do_split()/make_indexed_dir() assume the newly appended block is
+ * distinct from the blocks they are about to modify; if it aliases
+ * one of them, moving directory entries between the two buffers
+ * corrupts the directory. Make sure the new block is not already
+ * mapped by this inode.
+ */
+ for (map.m_lblk = 0; map.m_lblk < *block; ) {
+ map.m_len = *block - map.m_lblk;
+ err = ext4_map_blocks(NULL, inode, &map, 0);
+ if (err < 0)
+ goto out;
+ if (err == 0) {
+ map.m_lblk++;
+ continue;
+ }
+ if (unlikely(map.m_pblk == bh->b_blocknr)) {
+ EXT4_ERROR_INODE(inode,
+ "new block %llu already mapped",
+ (unsigned long long)bh->b_blocknr);
+ err = -EFSCORRUPTED;
+ goto out;
+ }
+ map.m_lblk += map.m_len;
+ }
+
inode->i_size += inode->i_sb->s_blocksize;
EXT4_I(inode)->i_disksize = inode->i_size;
err = ext4_mark_inode_dirty(handle, inode);
--
2.51.0
^ permalink raw reply [flat|nested] 9+ messages in thread* Forwarded: [PATCH] ext4: don't append a directory block already mapped in the inode
2026-09-28 21:54 [syzbot] [ext4?] KASAN: slab-use-after-free Write in do_split syzbot
` (4 preceding siblings ...)
2026-10-04 18:49 ` Forwarded: [PATCH] ext4: don't append a directory block already mapped in the inode syzbot
@ 2026-10-04 23:01 ` syzbot
2026-10-05 1:01 ` syzbot
6 siblings, 0 replies; 9+ messages in thread
From: syzbot @ 2026-10-04 23:01 UTC (permalink / raw)
To: linux-kernel
For archival purposes, forwarding an incoming command email to
linux-kernel@vger.kernel.org.
***
Subject: [PATCH] ext4: don't append a directory block already mapped in the inode
Author: adrianox@gmail.com
#syz test: upstream 72d3fcf802c45d00b300f25b848a93c3a2bd7c7e
---
fs/ext4/namei.c | 19 +++++++++++++++++++
1 file changed, 19 insertions(+)
diff --git a/fs/ext4/namei.c b/fs/ext4/namei.c
index 3b9740c1c16d..ff6013306b74 100644
--- a/fs/ext4/namei.c
+++ b/fs/ext4/namei.c
@@ -83,6 +83,25 @@ static struct buffer_head *ext4_append(handle_t *handle,
bh = ext4_bread(handle, inode, *block, EXT4_GET_BLOCKS_CREATE);
if (IS_ERR(bh))
return bh;
+
+ for (map.m_lblk = 0; map.m_lblk < *block; map.m_lblk += map.m_len) {
+ map.m_len = *block - map.m_lblk;
+ err = ext4_map_blocks(NULL, inode, &map, 0);
+ if (err < 0)
+ goto out;
+ if (err == 0) {
+ map.m_len = 1;
+ continue;
+ }
+ if (unlikely(map.m_pblk == bh->b_blocknr)) {
+ EXT4_ERROR_INODE(inode,
+ "new block %llu already mapped",
+ (unsigned long long)bh->b_blocknr);
+ err = -EFSCORRUPTED;
+ goto out;
+ }
+ }
+
inode->i_size += inode->i_sb->s_blocksize;
EXT4_I(inode)->i_disksize = inode->i_size;
err = ext4_mark_inode_dirty(handle, inode);
--
2.51.0
^ permalink raw reply [flat|nested] 9+ messages in thread* Forwarded: [PATCH] ext4: don't append a directory block already mapped in the inode
2026-09-28 21:54 [syzbot] [ext4?] KASAN: slab-use-after-free Write in do_split syzbot
` (5 preceding siblings ...)
2026-10-04 23:01 ` syzbot
@ 2026-10-05 1:01 ` syzbot
6 siblings, 0 replies; 9+ messages in thread
From: syzbot @ 2026-10-05 1:01 UTC (permalink / raw)
To: linux-kernel
For archival purposes, forwarding an incoming command email to
linux-kernel@vger.kernel.org.
***
Subject: [PATCH] ext4: don't append a directory block already mapped in the inode
Author: adrianox@gmail.com
#syz test: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git 72d3fcf802c45d00b300f25b848a93c3a2bd7c7e
ext4_append() grows a directory by one block. It checks that the target
logical block is a hole, but a corrupt block bitmap can still make the
allocator hand back a physical block that is already in use by this
inode. The in-memory copy of a block is keyed by its physical block
number, so the "new" block and that existing one are the same memory;
callers that split a directory (make_indexed_dir()/do_split()) then move
entries between two aliased buffers and corrupt the directory, until a
bogus rec_len read from the middle of a name runs the wipe out of bounds:
BUG: KASAN: slab-use-after-free in dx_move_dirents [inline]
Write of size 90458 ...
Reject the block and report the corrupt bitmap instead of corrupting
memory.
Closes: https://syzkaller.appspot.com/bug?extid=09bec78ee77613a3efdd
---
fs/ext4/namei.c | 19 +++++++++++++++++++
1 file changed, 19 insertions(+)
diff --git a/fs/ext4/namei.c b/fs/ext4/namei.c
index 3b9740c1c16d..7a0dadf6c5fe 100644
--- a/fs/ext4/namei.c
+++ b/fs/ext4/namei.c
@@ -83,6 +83,25 @@ static struct buffer_head *ext4_append(handle_t *handle,
bh = ext4_bread(handle, inode, *block, EXT4_GET_BLOCKS_CREATE);
if (IS_ERR(bh))
return bh;
+
+ for (map.m_lblk = 0; map.m_lblk < *block; map.m_lblk += map.m_len) {
+ map.m_len = *block - map.m_lblk;
+ err = ext4_map_blocks(NULL, inode, &map, 0);
+ if (err < 0) {
+ brelse(bh);
+ return ERR_PTR(err);
+ }
+ if (err > 0 && bh->b_blocknr - map.m_pblk < map.m_len) {
+ EXT4_ERROR_INODE(inode,
+ "new block %llu already mapped",
+ (unsigned long long)bh->b_blocknr);
+ brelse(bh);
+ return ERR_PTR(-EFSCORRUPTED);
+ }
+ if (map.m_len < 1)
+ map.m_len = 1;
+ }
+
inode->i_size += inode->i_sb->s_blocksize;
EXT4_I(inode)->i_disksize = inode->i_size;
err = ext4_mark_inode_dirty(handle, inode);
--
2.51.0
^ permalink raw reply [flat|nested] 9+ messages in thread