From: sashiko-bot@kernel.org
To: "Fan Wu" <fanwu01@zju.edu.cn>
Cc: tytso@mit.edu, linux-ext4@vger.kernel.org
Subject: Re: [PATCH v3] ext4: fix discard work use-after-free on failed mount
Date: Wed, 09 Sep 2026 11:52:42 +0000 [thread overview]
Message-ID: <20260909115243.0BE8D1F00A3D@smtp.kernel.org> (raw)
In-Reply-To: <20260909113703.698544-1-fanwu01@zju.edu.cn>
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
Pre-existing issues:
- [High] Use-after-free of mballoc s_group_info during mount failure unwinding via deferred EA inode eviction.
--
commit 08ee0a465324ade857a129840a9cb84d583a4d78
Author: Fan Wu <fanwu01@zju.edu.cn>
ext4: fix discard work use-after-free on failed mount
ext4_put_super() shuts the journal down before it releases the mballoc
structures, but the failure unwind of __ext4_fill_super() runs the two
steps in the opposite order: failed_mount6 calls ext4_mb_release(),
which flushes sbi->s_discard_work, and the journal is destroyed only
later, just above failed_mount3a.
> diff --git a/fs/ext4/super.c b/fs/ext4/super.c
> index bca0dc87d0b7c..459f69bf1c3a3 100644
> --- a/fs/ext4/super.c
> +++ b/fs/ext4/super.c
> @@ -5776,6 +5776,12 @@ failed_mount8: __maybe_unused
> failed_mount7:
> ext4_unregister_li_request(sb);
> failed_mount6:
> + /*
> + * We can have a running transaction from orphan replay or quota
> + * setup. Commit it so that discard work after commit runs before
> + * we shutdown mballoc.
> + */
> + ext4_force_commit(sb);
> ext4_mb_release(sb);
[Severity: High]
This is a pre-existing issue, but does this lead to a use-after-free
of mballoc's s_group_info during deferred EA inode eviction?
If journal replay queues a deferred EA inode put (e.g., dropping the last
reference to an EA inode), it is placed on sbi->s_ea_inode_work. If a
subsequent initialization step fails before failed_mount9, the error
unwinding path calls ext4_mb_release() here, which frees sbi->s_group_info.
Later in the unwinding process at failed_mount_wq:
fs/ext4/super.c:__ext4_fill_super() {
...
failed_mount_wq:
/* Drain deferred EA inode iputs before freeing structures */
flush_delayed_work(&sbi->s_ea_inode_work);
...
}
This executes the deferred iput, resulting in:
ext4_evict_inode() -> ext4_free_blocks() -> ext4_mb_free_blocks()
Which dereferences the dangling s_group_info pointer:
fs/ext4/balloc.c:ext4_get_group_info() {
...
grp_info = sbi_array_rcu_deref(EXT4_SB(sb), s_group_info, indexv);
...
}
Can this sequence occur with a crafted or corrupted filesystem image that
triggers both an EA inode eviction during journal replay and a subsequent
initialization failure?
> ext4_flex_groups_free(sbi);
> failed_mount5:
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260909113703.698544-1-fanwu01@zju.edu.cn?part=1
prev parent reply other threads:[~2026-09-09 11:52 UTC|newest]
Thread overview: 2+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-09 11:37 [PATCH v3] ext4: fix discard work use-after-free on failed mount Fan Wu
2026-09-09 11:52 ` sashiko-bot [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260909115243.0BE8D1F00A3D@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=fanwu01@zju.edu.cn \
--cc=linux-ext4@vger.kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
--cc=tytso@mit.edu \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.