From: sashiko-bot@kernel.org
To: "shuo chen" <1289151713@qq.com>
Cc: linux-ext4@vger.kernel.org, tytso@mit.edu
Subject: Re: [PATCH] ext4:Fix the initial value of not_found in ext4_destroy_inline_data_nolock
Date: Wed, 09 Sep 2026 01:24:42 +0000 [thread overview]
Message-ID: <20260909012443.0E7A01F00A3A@smtp.kernel.org> (raw)
In-Reply-To: <tencent_CD1AF9C3A7875C42F2187B57D74A1C5EE609@qq.com>
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
Pre-existing issues:
- [Critical] The patch initializes `is.s.not_found` to `-ENODATA` but fails to check this value before unconditionally deleting the inline data xattr, leading to a catastrophic size_t underflow and KASAN out-of-bounds write (kernel panic).
--
commit af434a75deba4ee29e45b41767340323974fc530
Author: shuo chen <1289151713@qq.com>
ext4:Fix the initial value of not_found in ext4_destroy_inline_data_nolock
If a file has EXT4_INODE_INLINE_DATA set but lacks the EXT4_STATE_XATTR
flag, ext4_xattr_ibody_find() will exit early without modifying
is.s.not_found. This may cause ext4_xattr_ibody_set() to behave
incorrectly.
> diff --git a/fs/ext4/inline.c b/fs/ext4/inline.c
> index caa51473207d7..4f02e7e9f5a30 100644
> --- a/fs/ext4/inline.c
> +++ b/fs/ext4/inline.c
> @@ -405,7 +405,7 @@ static int ext4_destroy_inline_data_nolock(handle_t *handle,
> {
> struct ext4_inode_info *ei = EXT4_I(inode);
> struct ext4_xattr_ibody_find is = {
> - .s = { .not_found = 0, },
> + .s = { .not_found = -ENODATA, },
[Severity: Critical]
This is a pre-existing issue, but does this patch fully resolve the problem?
While is.s.not_found is now correctly initialized to -ENODATA,
ext4_destroy_inline_data_nolock() still unconditionally calls
ext4_xattr_ibody_inline_set() without checking if is.s.not_found indicates
the attribute is missing.
When ext4_xattr_ibody_find() returns 0 and leaves not_found as -ENODATA,
this leads to a deletion operation (i.value == NULL) in
ext4_xattr_set_entry() on a non-existent entry.
Because the deletion path in ext4_xattr_set_entry() ignores s->not_found:
fs/ext4/xattr.c:ext4_xattr_set_entry() {
...
if (!i->value) {
/* Remove old name. */
size_t size = EXT4_XATTR_LEN(name_len);
last = ENTRY((void *)last - size);
memmove(here, (void *)here + size,
(void *)last - (void *)here + sizeof(__u32));
memset(last, 0, size);
}
...
}
Executing this when the entry doesn't exist causes an integer underflow in the
memmove() length parameter, which leads to an out-of-bounds write and kernel
panic.
Should ext4_destroy_inline_data_nolock() explicitly check is.s.not_found
and skip ext4_xattr_ibody_inline_set() when it is -ENODATA?
> };
> struct ext4_xattr_info i = {
> .name_index = EXT4_XATTR_INDEX_SYSTEM,
--
Sashiko AI review · https://sashiko.dev/#/patchset/tencent_CD1AF9C3A7875C42F2187B57D74A1C5EE609@qq.com?part=1
next prev parent reply other threads:[~2026-09-09 1:24 UTC|newest]
Thread overview: 6+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-09 1:12 [PATCH] ext4:Fix the initial value of not_found in ext4_destroy_inline_data_nolock shuo chen
2026-09-09 1:24 ` sashiko-bot [this message]
2026-09-09 2:56 ` shuo chen
2026-09-09 10:37 ` Jan Kara
2026-09-09 11:30 ` shuo chen
2026-09-09 12:28 ` Jan Kara
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260909012443.0E7A01F00A3A@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=1289151713@qq.com \
--cc=linux-ext4@vger.kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
--cc=tytso@mit.edu \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.