From: Weiming Shi <bestswngs@gmail.com>
To: Carlos Maiolino <cem@kernel.org>
Cc: linux-xfs@vger.kernel.org, linux-kernel@vger.kernel.org,
Chandan Babu R <chandanrlinux@gmail.com>,
"Darrick J . Wong" <darrick.wong@oracle.com>,
Xiang Mei <xmei5@asu.edu>, Weiming Shi <bestswngs@gmail.com>,
co+af981e62f5c7171a@bugs.sh, stable@vger.kernel.org
Subject: [PATCH] xfs: validate buffer log item before reordering
Date: Sun, 13 Sep 2026 19:45:30 +0800 [thread overview]
Message-ID: <20260913114528.842015-3-bestswngs@gmail.com> (raw)
Log recovery reorders transaction items before buffer item pass1 validates
the format of region 0. A corrupt log can therefore supply a four-byte
region containing only blf_type and blf_size. xlog_recover_buf_reorder()
then reads blf_flags immediately past the allocation:
BUG: KASAN: slab-out-of-bounds in xlog_recover_buf_reorder
Read of size 2 at addr ffff88800e40e364 by task poc/133
Call Trace:
kasan_report mm/kasan/report.c:595
xlog_recover_buf_reorder fs/xfs/xfs_buf_item_recover.c:164
xlog_recover_reorder_trans fs/xfs/xfs_log_recover.c:1929
xlog_recover_commit_trans fs/xfs/xfs_log_recover.c:2053
xlog_recovery_process_trans fs/xfs/xfs_log_recover.c:2319
xlog_recover_process_data fs/xfs/xfs_log_recover.c:2510
xlog_do_recovery_pass fs/xfs/xfs_log_recover.c:3253
xlog_do_log_recovery fs/xfs/xfs_log_recover.c:3340
xlog_do_recover fs/xfs/xfs_log_recover.c:3377
xlog_recover fs/xfs/xfs_log_recover.c:3502
xfs_log_mount fs/xfs/xfs_log.c:617
xfs_mountfs fs/xfs/xfs_mount.c:1031
The buggy address is located 0 bytes to the right of
allocated 4-byte region [ffff88800e40e360, ffff88800e40e364)
Validate region 0 before inspecting the flags. Keep a malformed item on
the regular item list so that xlog_recover_buf_commit_pass1() reports the
corrupt log through the existing error path.
Fixes: 86ffa471d9ce ("xfs: refactor log recovery item sorting into a generic dispatch structure")
Reported-by: co+af981e62f5c7171a@bugs.sh
Closes: https://lore.kernel.org/all/aqZALi7GdVprcNOh@cronus.toxiclabs.cc/
Cc: stable@vger.kernel.org
Assisted-by: Codex:gpt-5
Signed-off-by: Weiming Shi <bestswngs@gmail.com>
---
fs/xfs/xfs_buf_item_recover.c | 4 ++++
1 file changed, 4 insertions(+)
diff --git a/fs/xfs/xfs_buf_item_recover.c b/fs/xfs/xfs_buf_item_recover.c
index 57929f115055..70e69ec731ac 100644
--- a/fs/xfs/xfs_buf_item_recover.c
+++ b/fs/xfs/xfs_buf_item_recover.c
@@ -161,6 +161,10 @@ xlog_recover_buf_reorder(
{
struct xfs_buf_log_format *buf_f = item->ri_buf[0].iov_base;
+ /* A short region 0 is rejected by xlog_recover_buf_commit_pass1. */
+ if (!xfs_buf_log_check_iovec(&item->ri_buf[0]))
+ return XLOG_REORDER_ITEM_LIST;
+
if (buf_f->blf_flags & XFS_BLF_CANCEL)
return XLOG_REORDER_CANCEL_LIST;
if (buf_f->blf_flags & XFS_BLF_INODE_BUF)
--
2.55.0
next reply other threads:[~2026-09-13 11:48 UTC|newest]
Thread overview: 3+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-13 11:45 Weiming Shi [this message]
2026-09-13 23:49 ` [PATCH] xfs: validate buffer log item before reordering Dave Chinner
2026-09-14 1:49 ` Weiming Shi
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260913114528.842015-3-bestswngs@gmail.com \
--to=bestswngs@gmail.com \
--cc=cem@kernel.org \
--cc=chandanrlinux@gmail.com \
--cc=co+af981e62f5c7171a@bugs.sh \
--cc=darrick.wong@oracle.com \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-xfs@vger.kernel.org \
--cc=stable@vger.kernel.org \
--cc=xmei5@asu.edu \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.