From: Viacheslav Dubeyko <Slava.Dubeyko@ibm.com>
To: "contact@gvernon.com" <contact@gvernon.com>
Cc: "syzbot+97e301b4b82ae803d21b@syzkaller.appspotmail.com"
<syzbot+97e301b4b82ae803d21b@syzkaller.appspotmail.com>,
"glaubitz@physik.fu-berlin.de" <glaubitz@physik.fu-berlin.de>,
"frank.li@vivo.com" <frank.li@vivo.com>,
"penguin-kernel@i-love.sakura.ne.jp"
<penguin-kernel@i-love.sakura.ne.jp>,
"slava@dubeyko.com" <slava@dubeyko.com>,
"linux-kernel@vger.kernel.org" <linux-kernel@vger.kernel.org>,
"linux-fsdevel@vger.kernel.org" <linux-fsdevel@vger.kernel.org>
Subject: RE: [PATCH v4] hfs: Validate CNIDs in hfs_read_inode
Date: Wed, 18 Mar 2026 02:02:10 +0000 [thread overview]
Message-ID: <dbacbf1c48ac5aa24f37c58bff995d7b03268db4.camel@ibm.com> (raw)
In-Reply-To: <abnzsVk9JNN3alKq@Bertha>
On Wed, 2026-03-18 at 00:37 +0000, George Anthony Vernon wrote:
> Sorry I struggled to understand you here Slava, there's a little bit lost in
> translation I think.
>
> On Mon, Mar 16, 2026 at 09:50:14PM +0000, Viacheslav Dubeyko wrote:
> > by hfs_cat_find_brec(). But I cannot imagine that this logic can extract the
> > record with incorrect CNID. Because, it is the main goal of hfs_cat_find_brec()
> > logic to extract the record that contains requested CNID. And if we requested
>
> Do you mean that you do not think hfs_cat_find_brec *can* return a
> record with incorrect CNID, or that you do not think it *should*?
>
> I think Tetsuo is right that hfs_cat_find_brec() will return a catalog
> record with different CNID in case of a malformed thread record.
>
> On Mon, Mar 16, 2026 at 09:50:14PM +0000, Viacheslav Dubeyko wrote:
> > logic to extract the record that contains requested CNID. And if we requested
> > the HFS_ROOT_CNID, then this logic should return the record with exactly
> > requested CNID or return the error code if such record has not been found.
>
> Do you mean that hfs_cat_find_brec() should validate the CNID of the
> catalog record found by hfs_brec_find()? I'm worried that validating
> every B-tree lookup is going to be expensive. We could do it, however.
>
>
If you need to initialize the inode, then you need to find a file or a folder
record in Catalog File (b-tree). It means that there are two possible ways: (1)
find it by name, (2) find it by CNID.
If you know the name only, then you need to find a thread record by name. The
thread record contains associated CNID that can be used to find the final
file/folder record. It means that the second step is the searching the record by
using the CNID. If CNID is OK, then we can find the record. If it is not OK,
then we can find nothing or wrong record.
If we know CNID, then we can try to find the record by CNID directly. We will
fail to find the record if there is no record with such CNID. But you don't need
in thread record in the case of having CNID for the search.
Thanks,
Slava.
next prev parent reply other threads:[~2026-03-18 2:02 UTC|newest]
Thread overview: 21+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-03-11 21:13 George Anthony Vernon
2026-03-12 10:45 ` Tetsuo Handa
2026-03-12 23:13 ` Viacheslav Dubeyko
2026-03-13 11:03 ` Tetsuo Handa
2026-03-13 18:40 ` Viacheslav Dubeyko
2026-03-14 6:35 ` Tetsuo Handa
2026-03-16 21:50 ` Viacheslav Dubeyko
2026-03-18 0:37 ` George Anthony Vernon
2026-03-18 2:02 ` Viacheslav Dubeyko [this message]
2026-03-18 22:49 ` George Anthony Vernon
2026-03-19 9:57 ` Tetsuo Handa
2026-03-19 12:26 ` George Vernon
2026-03-20 0:32 ` Tetsuo Handa
2026-05-14 7:34 ` [PATCH v7] hfs: validate record ID against requested CNID in hfs_cat_find_brec() Tetsuo Handa
2026-05-15 21:10 ` Viacheslav Dubeyko
2026-05-16 6:17 ` Tetsuo Handa
2026-05-19 21:09 ` Viacheslav Dubeyko
2026-03-18 10:42 ` [PATCH v4] hfs: Validate CNIDs in hfs_read_inode Tetsuo Handa
2026-03-18 0:10 ` George Anthony Vernon
2026-03-18 8:16 ` Tetsuo Handa
2026-03-12 23:07 ` Viacheslav Dubeyko
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=dbacbf1c48ac5aa24f37c58bff995d7b03268db4.camel@ibm.com \
--to=slava.dubeyko@ibm.com \
--cc=contact@gvernon.com \
--cc=frank.li@vivo.com \
--cc=glaubitz@physik.fu-berlin.de \
--cc=linux-fsdevel@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=penguin-kernel@i-love.sakura.ne.jp \
--cc=slava@dubeyko.com \
--cc=syzbot+97e301b4b82ae803d21b@syzkaller.appspotmail.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®