mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* [PATCH] f2fs: reject device aliasing without a multi-device configuration
@ 2026-09-18 13:39 Seongjae Jeong
  2026-09-30  8:10 ` Chao Yu
  2026-09-30 17:20 ` [f2fs-dev] " patchwork-bot+f2fs
  0 siblings, 2 replies; 3+ messages in thread
From: Seongjae Jeong @ 2026-09-18 13:39 UTC (permalink / raw)
  To: jaegeuk, chao
  Cc: daehojeong, linux-f2fs-devel, linux-kernel, Seongjae Jeong,
	syzbot+ae5b8eb92ed40411ce16

A malformed F2FS image can enable F2FS_FEATURE_DEVICE_ALIAS without
providing a multi-device configuration. For a regular single-device
filesystem, f2fs_scan_devices() returns without allocating sbi->devs.

In this state, f2fs_dev_is_alloc_blocked() passes the device alias
feature check and dereferences FDEV(0), resulting in a NULL pointer
dereference during segment allocation.

Device aliasing requires at least one secondary device. Reject
superblocks that enable device aliasing without entries for both the
main and secondary devices in sanity_check_raw_super().

Fixes: eae3faf210bd ("f2fs: support dynamic reserve/release for device aliasing")
Reported-by: syzbot+ae5b8eb92ed40411ce16@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=ae5b8eb92ed40411ce16
Signed-off-by: Seongjae Jeong <jsjlee1020@gmail.com>
---
 fs/f2fs/super.c | 6 ++++++
 1 file changed, 6 insertions(+)

diff --git a/fs/f2fs/super.c b/fs/f2fs/super.c
index 6a2f09c61dcd..f980f67cd199 100644
--- a/fs/f2fs/super.c
+++ b/fs/f2fs/super.c
@@ -4153,6 +4153,12 @@ static int sanity_check_raw_super(struct f2fs_sb_info *sbi,
 		return -EFSCORRUPTED;
 	}
 
+	if (__F2FS_HAS_FEATURE(raw_super, F2FS_FEATURE_DEVICE_ALIAS) &&
+	    (!RDEV(0).path[0] || !RDEV(1).path[0])) {
+		f2fs_info(sbi, "Device aliasing requires a multi-device configuration");
+		return -EFSCORRUPTED;
+	}
+
 	if (RDEV(0).path[0]) {
 		block_t dev_seg_count = le32_to_cpu(RDEV(0).total_segments);
 		int i = 1;
-- 
2.53.0


^ permalink raw reply	[flat|nested] 3+ messages in thread

* Re: [PATCH] f2fs: reject device aliasing without a multi-device configuration
  2026-09-18 13:39 [PATCH] f2fs: reject device aliasing without a multi-device configuration Seongjae Jeong
@ 2026-09-30  8:10 ` Chao Yu
  2026-09-30 17:20 ` [f2fs-dev] " patchwork-bot+f2fs
  1 sibling, 0 replies; 3+ messages in thread
From: Chao Yu @ 2026-09-30  8:10 UTC (permalink / raw)
  To: Seongjae Jeong, jaegeuk
  Cc: chao, daehojeong, linux-f2fs-devel, linux-kernel,
	syzbot+ae5b8eb92ed40411ce16

On 9/18/26 21:39, Seongjae Jeong wrote:
> A malformed F2FS image can enable F2FS_FEATURE_DEVICE_ALIAS without
> providing a multi-device configuration. For a regular single-device
> filesystem, f2fs_scan_devices() returns without allocating sbi->devs.
> 
> In this state, f2fs_dev_is_alloc_blocked() passes the device alias
> feature check and dereferences FDEV(0), resulting in a NULL pointer
> dereference during segment allocation.
> 
> Device aliasing requires at least one secondary device. Reject
> superblocks that enable device aliasing without entries for both the
> main and secondary devices in sanity_check_raw_super().
> 
> Fixes: eae3faf210bd ("f2fs: support dynamic reserve/release for device aliasing")
> Reported-by: syzbot+ae5b8eb92ed40411ce16@syzkaller.appspotmail.com
> Closes: https://syzkaller.appspot.com/bug?extid=ae5b8eb92ed40411ce16
> Signed-off-by: Seongjae Jeong <jsjlee1020@gmail.com>

Reviewed-by: Chao Yu <chao@kernel.org>

Thanks,

^ permalink raw reply	[flat|nested] 3+ messages in thread

* Re: [f2fs-dev] [PATCH] f2fs: reject device aliasing without a multi-device configuration
  2026-09-18 13:39 [PATCH] f2fs: reject device aliasing without a multi-device configuration Seongjae Jeong
  2026-09-30  8:10 ` Chao Yu
@ 2026-09-30 17:20 ` patchwork-bot+f2fs
  1 sibling, 0 replies; 3+ messages in thread
From: patchwork-bot+f2fs @ 2026-09-30 17:20 UTC (permalink / raw)
  To: Seongjae Jeong
  Cc: jaegeuk, chao, syzbot+ae5b8eb92ed40411ce16, linux-kernel,
	daehojeong, linux-f2fs-devel

Hello:

This patch was applied to jaegeuk/f2fs.git (dev)
by Jaegeuk Kim <jaegeuk@kernel.org>:

On Fri, 18 Sep 2026 13:39:22 +0000 you wrote:
> A malformed F2FS image can enable F2FS_FEATURE_DEVICE_ALIAS without
> providing a multi-device configuration. For a regular single-device
> filesystem, f2fs_scan_devices() returns without allocating sbi->devs.
> 
> In this state, f2fs_dev_is_alloc_blocked() passes the device alias
> feature check and dereferences FDEV(0), resulting in a NULL pointer
> dereference during segment allocation.
> 
> [...]

Here is the summary with links:
  - [f2fs-dev] f2fs: reject device aliasing without a multi-device configuration
    https://git.kernel.org/jaegeuk/f2fs/c/7566fec606d2

You are awesome, thank you!
-- 
Deet-doot-dot, I am a bot.
https://korg.docs.kernel.org/patchwork/pwbot.html



^ permalink raw reply	[flat|nested] 3+ messages in thread

end of thread, other threads:[~2026-09-30 17:20 UTC | newest]

Thread overview: 3+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-09-18 13:39 [PATCH] f2fs: reject device aliasing without a multi-device configuration Seongjae Jeong
2026-09-30  8:10 ` Chao Yu
2026-09-30 17:20 ` [f2fs-dev] " patchwork-bot+f2fs

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®