mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: Siddh Raman Pant <siddh.raman.pant@oracle.com>
To: stable@vger.kernel.org, Greg KH <gregkh@linuxfoundation.org>,
	"Darrick J . Wong" <djwong@kernel.org>,
	Dave Chinner <dchinner@redhat.com>
Cc: linux-kernel@vger.kernel.org, Mark Tinguely <mark.tinguely@oracle.com>
Subject: [PATCH 5.10 06/21] xfs: improve the code that checks recovered refcount intent items
Date: Thu,  1 Oct 2026 20:21:19 +0530	[thread overview]
Message-ID: <737dd3a07dba9ca1f528b6d69499034d6cebc06b.1790866131.git.siddh.raman.pant@oracle.com> (raw)
In-Reply-To: <cover.1790866131.git.siddh.raman.pant@oracle.com>

From: "Darrick J. Wong" <darrick.wong@oracle.com>

The code that validates recovered refcount intent items is kind of a
mess -- it doesn't use the standard xfs type validators, and it doesn't
check for things that it should.  Fix the validator function to use the
standard validation helpers and look for more types of obvious errors.

Signed-off-by: Darrick J. Wong <darrick.wong@oracle.com>
Reviewed-by: Christoph Hellwig <hch@lst.de>
Reviewed-by: Brian Foster <bfoster@redhat.com>
(cherry picked from commit 0d79781a1aa6a6a567e63294012eee2384f406f2)
Stable-dep-of: 7b5f775be14a ("xfs: fix unmount hang with unflushable inodes stuck in the AIL")
Signed-off-by: Siddh Raman Pant <siddh.raman.pant@oracle.com>
---
 fs/xfs/xfs_refcount_item.c | 23 +++++++++++------------
 1 file changed, 11 insertions(+), 12 deletions(-)

diff --git a/fs/xfs/xfs_refcount_item.c b/fs/xfs/xfs_refcount_item.c
index 83dddec08f3c..2532a2a1cd59 100644
--- a/fs/xfs/xfs_refcount_item.c
+++ b/fs/xfs/xfs_refcount_item.c
@@ -423,27 +423,26 @@ xfs_cui_validate_phys(
 	struct xfs_mount		*mp,
 	struct xfs_phys_extent		*refc)
 {
-	xfs_fsblock_t			startblock_fsb;
-	bool				op_ok;
+	if (refc->pe_flags & ~XFS_REFCOUNT_EXTENT_FLAGS)
+		return false;
 
-	startblock_fsb = XFS_BB_TO_FSB(mp,
-			   XFS_FSB_TO_DADDR(mp, refc->pe_startblock));
 	switch (refc->pe_flags & XFS_REFCOUNT_EXTENT_TYPE_MASK) {
 	case XFS_REFCOUNT_INCREASE:
 	case XFS_REFCOUNT_DECREASE:
 	case XFS_REFCOUNT_ALLOC_COW:
 	case XFS_REFCOUNT_FREE_COW:
-		op_ok = true;
 		break;
 	default:
-		op_ok = false;
-		break;
+		return false;
 	}
-	if (!op_ok || startblock_fsb == 0 ||
-	    refc->pe_len == 0 ||
-	    startblock_fsb >= mp->m_sb.sb_dblocks ||
-	    refc->pe_len >= mp->m_sb.sb_agblocks ||
-	    (refc->pe_flags & ~XFS_REFCOUNT_EXTENT_FLAGS))
+
+	if (refc->pe_startblock + refc->pe_len <= refc->pe_startblock)
+		return false;
+
+	if (!xfs_verify_fsbno(mp, refc->pe_startblock))
+		return false;
+
+	if (!xfs_verify_fsbno(mp, refc->pe_startblock + refc->pe_len - 1))
 		return false;
 
 	return true;
-- 
2.53.0


  parent reply	other threads:[~2026-10-01 14:52 UTC|newest]

Thread overview: 55+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
     [not found] <2026090954-revisit-dowry-37ee@gregkh>
2026-10-01 14:50 ` [PATCH 6.12 0/6] Backport of XFS umount hang fixes Siddh Raman Pant
2026-10-01 14:50   ` [PATCH 6.12 1/6] xfs: xfs_ifree_cluster vs xfs_iflush_shutdown_abort deadlock Siddh Raman Pant
2026-10-01 14:50   ` [PATCH 6.12 2/6] xfs: catch stale AGF/AGF metadata Siddh Raman Pant
2026-10-01 14:50   ` [PATCH 6.12 3/6] xfs: avoid dquot buffer pin deadlock Siddh Raman Pant
2026-10-01 14:50   ` [PATCH 6.12 4/6] xfs: rearrange code in xfs_buf_item.c Siddh Raman Pant
2026-10-01 14:50   ` [PATCH 6.12 5/6] xfs: factor out stale buffer item completion Siddh Raman Pant
2026-10-01 14:50   ` [PATCH 6.12 6/6] xfs: fix unmount hang with unflushable inodes stuck in the AIL Siddh Raman Pant
2026-10-01 14:50 ` [PATCH 6.6 0/6] Backport of XFS umount hang fixes Siddh Raman Pant
2026-10-01 14:50   ` [PATCH 6.6 1/6] xfs: xfs_ifree_cluster vs xfs_iflush_shutdown_abort deadlock Siddh Raman Pant
2026-10-01 14:50   ` [PATCH 6.6 2/6] xfs: catch stale AGF/AGF metadata Siddh Raman Pant
2026-10-01 14:51   ` [PATCH 6.6 3/6] xfs: avoid dquot buffer pin deadlock Siddh Raman Pant
2026-10-01 14:51   ` [PATCH 6.6 4/6] xfs: rearrange code in xfs_buf_item.c Siddh Raman Pant
2026-10-01 14:51   ` [PATCH 6.6 5/6] xfs: factor out stale buffer item completion Siddh Raman Pant
2026-10-01 14:51   ` [PATCH 6.6 6/6] xfs: fix unmount hang with unflushable inodes stuck in the AIL Siddh Raman Pant
2026-10-01 14:51 ` [PATCH 5.10 00/21] Backport of XFS umount hang fixes Siddh Raman Pant
2026-10-01 14:51   ` [PATCH 5.10 01/21] xfs: hoist recovered bmap intent checks out of xfs_bui_item_recover Siddh Raman Pant
2026-10-01 14:51   ` [PATCH 5.10 02/21] xfs: improve the code that checks recovered bmap intent items Siddh Raman Pant
2026-10-01 14:51   ` [PATCH 5.10 03/21] xfs: hoist recovered rmap intent checks out of xfs_rui_item_recover Siddh Raman Pant
2026-10-01 14:51   ` [PATCH 5.10 04/21] xfs: improve the code that checks recovered rmap intent items Siddh Raman Pant
2026-10-01 14:51   ` [PATCH 5.10 05/21] xfs: hoist recovered refcount intent checks out of xfs_cui_item_recover Siddh Raman Pant
2026-10-01 14:51   ` Siddh Raman Pant [this message]
2026-10-01 14:51   ` [PATCH 5.10 07/21] xfs: don't nest icloglock inside ic_callback_lock Siddh Raman Pant
2026-10-01 14:51   ` [PATCH 5.10 08/21] xfs: convert XLOG_FORCED_SHUTDOWN() to xlog_is_shutdown() Siddh Raman Pant
2026-10-01 14:51   ` [PATCH 5.10 09/21] xfs: log items should have a xlog pointer, not a mount Siddh Raman Pant
2026-10-01 14:51   ` [PATCH 5.10 10/21] xfs: aborting inodes on shutdown may need buffer lock Siddh Raman Pant
2026-10-01 14:51   ` [PATCH 5.10 11/21] xfs: remove xfs_buf_t typedef Siddh Raman Pant
2026-10-01 14:51   ` [PATCH 5.10 12/21] xfs: fix super block buf log item UAF during force shutdown Siddh Raman Pant
2026-10-01 14:51   ` [PATCH 5.10 13/21] xfs: fix intermittent hang during quotacheck Siddh Raman Pant
2026-10-01 14:51   ` [PATCH 5.10 14/21] xfs: dquot shrinker doesn't check for XFS_DQFLAG_FREEING Siddh Raman Pant
2026-10-01 14:51   ` [PATCH 5.10 15/21] xfs: buffer pins need to hold a buffer reference Siddh Raman Pant
2026-10-01 14:51   ` [PATCH 5.10 16/21] xfs: xfs_ifree_cluster vs xfs_iflush_shutdown_abort deadlock Siddh Raman Pant
2026-10-01 14:51   ` [PATCH 5.10 17/21] xfs: catch stale AGF/AGF metadata Siddh Raman Pant
2026-10-01 14:51   ` [PATCH 5.10 18/21] xfs: avoid dquot buffer pin deadlock Siddh Raman Pant
2026-10-01 14:51   ` [PATCH 5.10 19/21] xfs: rearrange code in xfs_buf_item.c Siddh Raman Pant
2026-10-01 14:51   ` [PATCH 5.10 20/21] xfs: factor out stale buffer item completion Siddh Raman Pant
2026-10-01 14:51   ` [PATCH 5.10 21/21] xfs: fix unmount hang with unflushable inodes stuck in the AIL Siddh Raman Pant
2026-10-01 14:51 ` [PATCH 5.15 00/11] Backport of XFS umount hang fixes Siddh Raman Pant
2026-10-01 14:51   ` [PATCH 5.15 01/11] xfs: log items should have a xlog pointer, not a mount Siddh Raman Pant
2026-10-01 14:51   ` [PATCH 5.15 02/11] xfs: aborting inodes on shutdown may need buffer lock Siddh Raman Pant
2026-10-01 14:51   ` [PATCH 5.15 03/11] xfs: fix super block buf log item UAF during force shutdown Siddh Raman Pant
2026-10-01 14:51   ` [PATCH 5.15 04/11] xfs: dquot shrinker doesn't check for XFS_DQFLAG_FREEING Siddh Raman Pant
2026-10-01 14:51   ` [PATCH 5.15 05/11] xfs: buffer pins need to hold a buffer reference Siddh Raman Pant
2026-10-01 14:51   ` [PATCH 5.15 06/11] xfs: xfs_ifree_cluster vs xfs_iflush_shutdown_abort deadlock Siddh Raman Pant
2026-10-01 14:51   ` [PATCH 5.15 07/11] xfs: catch stale AGF/AGF metadata Siddh Raman Pant
2026-10-01 14:51   ` [PATCH 5.15 08/11] xfs: avoid dquot buffer pin deadlock Siddh Raman Pant
2026-10-01 14:51   ` [PATCH 5.15 09/11] xfs: rearrange code in xfs_buf_item.c Siddh Raman Pant
2026-10-01 14:51   ` [PATCH 5.15 10/11] xfs: factor out stale buffer item completion Siddh Raman Pant
2026-10-01 14:51   ` [PATCH 5.15 11/11] xfs: fix unmount hang with unflushable inodes stuck in the AIL Siddh Raman Pant
2026-10-01 14:51 ` [PATCH 6.1 0/6] Backport of XFS umount hang fixes Siddh Raman Pant
2026-10-01 14:51   ` [PATCH 6.1 1/6] xfs: xfs_ifree_cluster vs xfs_iflush_shutdown_abort deadlock Siddh Raman Pant
2026-10-01 14:51   ` [PATCH 6.1 2/6] xfs: catch stale AGF/AGF metadata Siddh Raman Pant
2026-10-01 14:51   ` [PATCH 6.1 3/6] xfs: avoid dquot buffer pin deadlock Siddh Raman Pant
2026-10-01 14:51   ` [PATCH 6.1 4/6] xfs: rearrange code in xfs_buf_item.c Siddh Raman Pant
2026-10-01 14:51   ` [PATCH 6.1 5/6] xfs: factor out stale buffer item completion Siddh Raman Pant
2026-10-01 14:51   ` [PATCH 6.1 6/6] xfs: fix unmount hang with unflushable inodes stuck in the AIL Siddh Raman Pant

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=737dd3a07dba9ca1f528b6d69499034d6cebc06b.1790866131.git.siddh.raman.pant@oracle.com \
    --to=siddh.raman.pant@oracle.com \
    --cc=dchinner@redhat.com \
    --cc=djwong@kernel.org \
    --cc=gregkh@linuxfoundation.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=mark.tinguely@oracle.com \
    --cc=stable@vger.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®