From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-ed1-f51.google.com (mail-ed1-f51.google.com [209.85.208.51]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 739BF399CF5 for ; Mon, 3 Aug 2026 06:37:38 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.208.51 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785739060; cv=none; b=aYBOCLUOY92kM84RF6pwtRzfOoKw1v+dTFr77e2iDcJqJLJs7D6G4/tNS5vf0FPRd6J8lovgzc1dT5wnW46kOL6tYyxpUXyXaNSx0JcEi43rMG7nEh5T1L2pWXIBXUklmhe0W0YU8eHpygWswGOTYIwVj6511Tu2qAyaDAzmqWU= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785739060; c=relaxed/simple; bh=jw3ba/wvfD8Ah6zyMXHFHCwWGezpZZhoFih/Fe1tpcQ=; h=Date:From:To:Cc:Subject:Message-ID:References:MIME-Version: Content-Type:Content-Disposition:In-Reply-To; b=gYUM2jpxvRN8R6kaSr3FnZzGc4MFVIwrfPlxDjTBt2uMdgfLloYW3W+7WJuCJvNydOXk4Hfw/C8xvT2RGMjNFBhwHFkja0EERh8BjlzBrlckmchUizmY/tj5/pqWTRE1IyURc9Si0Qzkq0RBAv/TiQRnygRwhddUtzB0dOJleaM= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=suse.com; spf=pass smtp.mailfrom=suse.com; dkim=pass (2048-bit key) header.d=suse.com header.i=@suse.com header.b=Du9WVLVN; arc=none smtp.client-ip=209.85.208.51 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=suse.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=suse.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=suse.com header.i=@suse.com header.b="Du9WVLVN" Received: by mail-ed1-f51.google.com with SMTP id 4fb4d7f45d1cf-69a33fb0031so563725a12.1 for ; Sun, 02 Aug 2026 23:37:38 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=suse.com; s=google; t=1785739057; x=1786343857; darn=vger.kernel.org; h=in-reply-to:content-disposition:content-type:mime-version :references:message-id:subject:cc:to:from:date:from:to:cc:subject :date:message-id:reply-to:content-type; bh=HjtHRYSsspzas55sgzq+ZHE05NUJv5wxQswJPDQ5sBY=; b=Du9WVLVNGRW9j8sZ2pMz0+qvyeIdhyfaQlgtPVXvuVPEWKycXvScvk7pF7mKzGSmNm XDhGkOWSRQn2b7IR/dUA9+Zk/PyckwfoyVgZIynoBtfNZp9qYu0S/7GnoanQsUsUt4B5 RVsgAS1iPUBMlpp38hYoxptYhqEaHxR538QR9QSO8mqwbPygvJ4RPl120eucow1Zb+r3 w6t/hSzbasZM4i6Mqc5DXi7P1r3piV6LC/fJw2xOmB/8XJ/ISoswVmPjpzBHBZCWfKhU gS/tVAap3/Rl9vhHeHFI9KzDgNFTg7LtbtVv/BwHmxDi2JXMdcbv64wQ3f/1fJo9M99i nnUQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785739057; x=1786343857; h=in-reply-to:content-disposition:content-type:mime-version :references:message-id:subject:cc:to:from:date:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=HjtHRYSsspzas55sgzq+ZHE05NUJv5wxQswJPDQ5sBY=; b=oqgmdiM/ehjmCWcpskD5mKIp85Y2dHDPDdoNHtcXlPkAu6R7vi+UF159quXs5fQ+88 1geWB0RZQlarBadTsj/mZZLwD9AbHU1MEdj/IT2ucgvnQ+gIp8GoMk3xJ+VHX1MU0vMy 6V/ZQjnm7D9LkLo2rDGhVCl5iLa8Ms8KzFSlgYo5t646yfPjRx/felhyVWIvx2968w64 OvBQ80Cf9KDxkMuVEAPZWHw+MoTgUjjj4L5NHD4sCgqtTxAHGnx0lmOjT0+zAsK4Vaws q9KkTjJH6Q7CMyz4tFvjPPAPYDTiCl/mvKwrS6vfDySjScrQ1a300MsEcJSCZ2vFjbIZ /5EA== X-Forwarded-Encrypted: i=1; AHgh+Rrhm5wHAPtrd4GwIddIuZZ83QUvtj2XogzrslLLFU/fVJlXVSjNgZCb3oaFaYt72YmdJcKIz8Uphk2iuEE=@vger.kernel.org X-Gm-Message-State: AOJu0YwPTmQfTW8BACxEewt5zrGUDLuJBHsLtHq42cAmPmHzHADpNzJF /0IWYqB78jb47/icI4nf/3S37F1yifdEKVOBoqW4+u1T2+ab29JzR3FFAOXlOorImv4= X-Gm-Gg: AR+sD10i+Zzj7/SbkqJYJsSXjPT+RR1kYeBznhz2J82Ffl+bjj5VjCkLO/Ghwf4tqbX +77cgdBaNpHVY2jPp0Ur/HaDTLTGe5Cg8T/r9wBaIty/s9sEqOkCtuBOgG2EGZeoUjBeynoTPi5 lJUUcLREdMhzUoipoFIGzHsgaV6XjM0Nw2H9lZktcY4utlEjhS0IOB8wnwKUt5n5iIt9rhSDYvJ szNmzjrZUbE6qFiz9LXoKmG9OoSR01ObC8y2fUD32ffA+GT0JmBjis3CXIaKyUAkTXqHefesrPC ZgZCSSInKwgegf2pQ18DcokGLEJmXSHI4TzjGP7jiBYzPltfYOjQ8YwLtHhucBloJ+oPPKupsSj nhq0ymKPtUe81aVsctfwxueMBKxl3iOKHnXAsmLzJf82dfLF6gjPfM/0fuH2TQTy7Auwavs1uBD HSJT1LF4ZJykFd7+aSQyk5y28vhZcqw0ROZVfsPJCn0K8QM+9trFmmzbH51x8= X-Received: by 2002:a05:6402:5c1:b0:6a0:d411:930d with SMTP id 4fb4d7f45d1cf-6a0d41194b8mr1290830a12.2.1785739056731; Sun, 02 Aug 2026 23:37:36 -0700 (PDT) Received: from localhost ([202.127.77.110]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-84edbe593basm3155356b3a.21.2026.08.02.23.37.34 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 02 Aug 2026 23:37:35 -0700 (PDT) Date: Mon, 3 Aug 2026 14:37:31 +0800 From: Heming Zhao To: ZhengYuan Huang Cc: mark@fasheh.com, jlbec@evilplan.org, joseph.qi@linux.alibaba.com, tao.ma@oracle.com, ocfs2-devel@lists.linux.dev, linux-kernel@vger.kernel.org, baijiaju1990@gmail.com, r33s3n6@gmail.com, zzzccc427@gmail.com, tom442288@tuta.io Subject: Re: [PATCH] ocfs2: validate global bitmap cl_bpc before resize Message-ID: References: <20260803031116.3994362-1-gality369@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <20260803031116.3994362-1-gality369@gmail.com> On Mon, Aug 03, 2026 at 11:11:16AM +0800, ZhengYuan Huang wrote: > [BUG] > A corrupted global bitmap inode can make online group extension scan past > the end of a group descriptor bitmap: > > BUG: KASAN: use-after-free in _find_next_bit+0xef/0x120 lib/find_bit.c:157 > Read of size 8 at addr ffff888021b52000 by task syz.0.34/409 > Call Trace: > > ... > _find_next_bit+0xef/0x120 lib/find_bit.c:157 > find_next_bit include/linux/find.h:73 [inline] > find_next_bit_le include/linux/find.h:518 [inline] > ocfs2_find_max_contig_free_bits+0x53/0xb0 fs/ocfs2/suballoc.c:1292 > ocfs2_update_last_group_and_inode fs/ocfs2/resize.c:127 [inline] > ocfs2_group_extend+0x83e/0x1ae0 fs/ocfs2/resize.c:350 > ocfs2_ioctl+0x175/0x6e0 fs/ocfs2/ioctl.c:869 > vfs_ioctl fs/ioctl.c:51 [inline] > __do_sys_ioctl fs/ioctl.c:597 [inline] > __se_sys_ioctl fs/ioctl.c:583 [inline] > __x64_sys_ioctl+0x197/0x1e0 fs/ioctl.c:583 > ... > > [CAUSE] > ocfs2_group_extend() trusts the global bitmap dinode's cl_bpc value. > If its high byte corrupted from zero to 0xc9 makes cl_bpc 51457. > Extending by seven clusters narrows their product to a u16 value of > 32519 and raises a 2048-bit group to 34567 bits, beyond its 32256-bit > bitmap. The subsequent maximum-free-run scan then reads into the next > page. > > [FIX] > Reject a global bitmap whose cl_bpc is not one before using it in any > resize arithmetic. The global allocator has exactly one bitmap bit per > cluster, so this validates the invariant at the cold online-resize > boundary and reports metadata corruption instead of enlarging bg_bits > past the descriptor. > > Fixes: d659072f7368 ("[PATCH 1/2] ocfs2: Add group extend for online resize") > Signed-off-by: ZhengYuan Huang > --- > fs/ocfs2/resize.c | 9 ++++++++- > 1 file changed, 8 insertions(+), 1 deletion(-) > > diff --git a/fs/ocfs2/resize.c b/fs/ocfs2/resize.c > index 6375d5035972..556aaa319621 100644 > --- a/fs/ocfs2/resize.c > +++ b/fs/ocfs2/resize.c > @@ -311,6 +311,14 @@ int ocfs2_group_extend(struct inode * inode, int new_clusters) > goto out_unlock; > } > > + cl_bpc = le16_to_cpu(fe->id2.i_chain.cl_bpc); > + if (cl_bpc != 1) { cl_bpc is not a fixed value. Refer from mkfs.ocfs2(8), only both block size and cluster size are 4K, cl_bpc is 1. Otherwise, cl_bpc is 2, 4, .... Btw, is it any possible to put the check in ocfs2_validate_inode_block()? Thanks, Heming > + ret = ocfs2_error(main_bm_inode->i_sb, > + "Invalid global bitmap bits per cluster %u\n", > + cl_bpc); > + goto out_unlock; > + } > + > if (le16_to_cpu(fe->id2.i_chain.cl_cpg) != > ocfs2_group_bitmap_size(osb->sb, 0, > osb->s_feature_incompat) * 8) { > @@ -332,7 +340,6 @@ int ocfs2_group_extend(struct inode * inode, int new_clusters) > } > group = (struct ocfs2_group_desc *)group_bh->b_data; > > - cl_bpc = le16_to_cpu(fe->id2.i_chain.cl_bpc); > if (le16_to_cpu(group->bg_bits) / cl_bpc + new_clusters > > le16_to_cpu(fe->id2.i_chain.cl_cpg)) { > ret = -EINVAL; > -- > 2.43.0 > >