From: Binglei Wang <l3b2w1@gmail.com>
To: linux-erofs@lists.ozlabs.org
Cc: xiang@kernel.org, chao@kernel.org, shengyong1@xiaomi.com,
linux-kernel@vger.kernel.org, Binglei Wang <l3b2w1@gmail.com>,
stable@vger.kernel.org
Subject: [PATCH] erofs: fix unbalanced buf->off handling in erofs_bread()
Date: Sat, 12 Sep 2026 10:57:09 +0800 [thread overview]
Message-ID: <20260912025709.25604-1-l3b2w1@gmail.com> (raw)
From: Binglei Wang <l3b2w1@gmail.com>
erofs_bread() locates the target folio with
index = (buf->off + offset) >> PAGE_SHIFT;
but computes the in-folio offset without taking buf->off into account:
return buf->base + (offset & ~PAGE_MASK);
If buf->off is not page-aligned, the returned pointer misses the in-page
component of buf->off, so callers end up fetching data from a wrong
offset.
buf->off is set to sbi->dif0.fsoff in erofs_init_metabuf(), and fsoff can
be specified via the "fsoffset=" mount option, which only requires
block-size alignment. Therefore, on an image with a sub-page block size
(e.g. 512 bytes), a non-page-aligned fsoff (e.g. 512) triggers the issue,
since 512 is a multiple of the block size but not of PAGE_SIZE.
It can be reproduced by mounting an image that is placed at a
non-page-aligned offset:
mkfs.erofs -b512 -zlz4hc sub.erofs src/
# prepend 512 bytes of padding to the image
mount -t erofs -o loop,fsoffset=512 padded.erofs /mnt
which fails with
erofs (device loop0): cannot find valid erofs superblock
because the on-disk superblock (at offset 1024 within the image, i.e.
1536 within the padded file) is read from a wrong in-folio offset. With
this fixed, the very same image mounts successfully and its file contents
match those read from the unpadded image.
Fix it by including buf->off in the in-folio offset calculation, so that
it is consistent with the folio index calculation.
Fixes: c36ec00d7f67 ("erofs: add 'fsoffset' mount option to specify filesystem offset")
Cc: <stable@vger.kernel.org> # 6.16+
Signed-off-by: Binglei Wang <l3b2w1@gmail.com>
---
fs/erofs/data.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/fs/erofs/data.c b/fs/erofs/data.c
index 0885b1f2fc92..be63b89f0862 100644
--- a/fs/erofs/data.c
+++ b/fs/erofs/data.c
@@ -48,7 +48,7 @@ void *erofs_bread(struct erofs_buf *buf, erofs_off_t offset, bool need_kmap)
return NULL;
if (!buf->base)
buf->base = kmap_local_page(buf->page);
- return buf->base + (offset & ~PAGE_MASK);
+ return buf->base + ((buf->off + offset) & ~PAGE_MASK);
}
int erofs_init_metabuf(struct erofs_buf *buf, struct super_block *sb,
--
2.33.0
next reply other threads:[~2026-09-12 2:57 UTC|newest]
Thread overview: 9+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-12 2:57 Binglei Wang [this message]
2026-09-12 9:25 ` [PATCH] erofs: fix unbalanced buf->off handling in erofs_bread() Gao Xiang
-- strict thread matches above, loose matches on Subject: below --
2026-09-11 4:16 binglei wang
2026-09-11 4:22 ` Gao Xiang
2026-09-11 4:33 ` binglei wang
2026-09-11 4:15 binglei wang
2026-09-11 4:01 binglei wang
2026-09-11 4:18 ` Gao Xiang
2026-09-11 4:22 ` binglei wang
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260912025709.25604-1-l3b2w1@gmail.com \
--to=l3b2w1@gmail.com \
--cc=chao@kernel.org \
--cc=linux-erofs@lists.ozlabs.org \
--cc=linux-kernel@vger.kernel.org \
--cc=shengyong1@xiaomi.com \
--cc=stable@vger.kernel.org \
--cc=xiang@kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.