All of lore.kernel.org
 help / color / mirror / Atom feed
* [PATCH] ext4: save converted extent before merging
@ 2026-09-30 13:45 Jérémy Jean
  2026-09-30 13:53 ` sashiko-bot
  2026-10-01  6:06 ` Ojaswin Mujoo
  0 siblings, 2 replies; 3+ messages in thread
From: Jérémy Jean @ 2026-09-30 13:45 UTC (permalink / raw)
  To: tytso
  Cc: Andreas Dilger, Baokun Li, Jan Kara, Ojaswin Mujoo, ritesh.list,
	Zhang Yi, linux-ext4, linux-kernel, Jérémy Jean, stable

In ext4_split_convert_extents(), merging can release the leaf holding
the extent pointed to by ex. The later extent status cache update can
then dereference freed memory, causing a use-after-free. KASAN reports:

  BUG: KASAN: use-after-free in ext4_split_convert_extents.constprop.0+0xb98/0xc80
  Read of size 2 at addr ff11000002547034 by task fixture/65

Save the converted extent before merging and use the copy for the cache
update. This also avoids using the old extent slot after a merge with
the left neighbour.

Fixes: 716b9c23b862 ("ext4: refactor split and convert extents")
Cc: stable@kernel.org
Assisted-by: LLM
Signed-off-by: Jérémy Jean <Jeremy.Jean@oss.cyber.gouv.fr>
---
 fs/ext4/extents.c | 5 +++++
 1 file changed, 5 insertions(+)

diff --git a/fs/ext4/extents.c b/fs/ext4/extents.c
index 76038b6..f5a3880 100644
--- a/fs/ext4/extents.c
+++ b/fs/ext4/extents.c
@@ -3830,6 +3830,7 @@ static struct ext4_ext_path *ext4_split_convert_extents(handle_t *handle,
 	ext4_lblk_t eof_block;
 	ext4_lblk_t ee_block;
 	struct ext4_extent *ex;
+	struct ext4_extent converted_ex;
 	unsigned int ee_len;
 	int split_flag = 0, depth, err = 0;
 	bool did_zeroout = false;
@@ -3887,6 +3888,9 @@ convert:
 		else if (flags & EXT4_GET_BLOCKS_CONVERT_UNWRITTEN)
 			ext4_ext_mark_unwritten(ex);
 
+		/* Merging can move ex or release the leaf containing it. */
+		converted_ex = *ex;
+
 		if (!(flags & EXT4_GET_BLOCKS_SPLIT_NOMERGE))
 		       /*
 			* note: ext4_ext_correct_indexes() isn't needed here because
@@ -3897,6 +3901,7 @@ convert:
 		err = ext4_ext_dirty(handle, inode, path + depth);
 		if (err)
 			goto err;
+		ex = &converted_ex;
 	}
 
 	/* Lets update the extent status tree after conversion */
-- 
2.47.3


^ permalink raw reply related	[flat|nested] 3+ messages in thread

* Re: [PATCH] ext4: save converted extent before merging
  2026-09-30 13:45 [PATCH] ext4: save converted extent before merging Jérémy Jean
@ 2026-09-30 13:53 ` sashiko-bot
  2026-10-01  6:06 ` Ojaswin Mujoo
  1 sibling, 0 replies; 3+ messages in thread
From: sashiko-bot @ 2026-09-30 13:53 UTC (permalink / raw)
  To: Jérémy Jean; +Cc: tytso, linux-ext4

> In ext4_split_convert_extents(), merging can release the leaf holding
> the extent pointed to by ex. The later extent status cache update can
> then dereference freed memory, causing a use-after-free. KASAN reports:
> 
>   BUG: KASAN: use-after-free in ext4_split_convert_extents.constprop.0+0xb98/0xc80
>   Read of size 2 at addr ff11000002547034 by task fixture/65
> 
> Save the converted extent before merging and use the copy for the cache
> update. This also avoids using the old extent slot after a merge with
> the left neighbour.
> 
> Fixes: 716b9c23b862 ("ext4: refactor split and convert extents")
> Cc: stable@kernel.org
> Assisted-by: LLM
> Signed-off-by: Jérémy Jean <Jeremy.Jean@oss.cyber.gouv.fr>

Sashiko has reviewed this patch and found no issues. It looks great!

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260930134516.397754-2-Jeremy.Jean@oss.cyber.gouv.fr?part=1


^ permalink raw reply	[flat|nested] 3+ messages in thread

* Re: [PATCH] ext4: save converted extent before merging
  2026-09-30 13:45 [PATCH] ext4: save converted extent before merging Jérémy Jean
  2026-09-30 13:53 ` sashiko-bot
@ 2026-10-01  6:06 ` Ojaswin Mujoo
  1 sibling, 0 replies; 3+ messages in thread
From: Ojaswin Mujoo @ 2026-10-01  6:06 UTC (permalink / raw)
  To: Jérémy Jean
  Cc: tytso, Andreas Dilger, Baokun Li, Jan Kara, ritesh.list, Zhang Yi,
	linux-ext4, linux-kernel, stable

On Wed, Sep 30, 2026 at 01:45:17PM +0000, Jérémy Jean wrote:
> In ext4_split_convert_extents(), merging can release the leaf holding
> the extent pointed to by ex. The later extent status cache update can
> then dereference freed memory, causing a use-after-free. KASAN reports:
> 
>   BUG: KASAN: use-after-free in ext4_split_convert_extents.constprop.0+0xb98/0xc80
>   Read of size 2 at addr ff11000002547034 by task fixture/65
> 
> Save the converted extent before merging and use the copy for the cache
> update. This also avoids using the old extent slot after a merge with
> the left neighbour.
> 
> Fixes: 716b9c23b862 ("ext4: refactor split and convert extents")
> Cc: stable@kernel.org
> Assisted-by: LLM
> Signed-off-by: Jérémy Jean <Jeremy.Jean@oss.cyber.gouv.fr>
> ---

Hey Jeremy,

thanks for the fix. I'm working on a patch that has some more fixes in
this area but your fix looks good standalone.

Feel free to add:

Reviewed-by: Ojaswin Mujoo <ojaswin@linux.ibm.com>

Regards,
ojaswin

>  fs/ext4/extents.c | 5 +++++
>  1 file changed, 5 insertions(+)
> 
> diff --git a/fs/ext4/extents.c b/fs/ext4/extents.c
> index 76038b6..f5a3880 100644
> --- a/fs/ext4/extents.c
> +++ b/fs/ext4/extents.c
> @@ -3830,6 +3830,7 @@ static struct ext4_ext_path *ext4_split_convert_extents(handle_t *handle,
>  	ext4_lblk_t eof_block;
>  	ext4_lblk_t ee_block;
>  	struct ext4_extent *ex;
> +	struct ext4_extent converted_ex;
>  	unsigned int ee_len;
>  	int split_flag = 0, depth, err = 0;
>  	bool did_zeroout = false;
> @@ -3887,6 +3888,9 @@ convert:
>  		else if (flags & EXT4_GET_BLOCKS_CONVERT_UNWRITTEN)
>  			ext4_ext_mark_unwritten(ex);
>  
> +		/* Merging can move ex or release the leaf containing it. */
> +		converted_ex = *ex;
> +
>  		if (!(flags & EXT4_GET_BLOCKS_SPLIT_NOMERGE))
>  		       /*
>  			* note: ext4_ext_correct_indexes() isn't needed here because
> @@ -3897,6 +3901,7 @@ convert:
>  		err = ext4_ext_dirty(handle, inode, path + depth);
>  		if (err)
>  			goto err;
> +		ex = &converted_ex;
>  	}
>  
>  	/* Lets update the extent status tree after conversion */
> -- 
> 2.47.3
> 

^ permalink raw reply	[flat|nested] 3+ messages in thread

end of thread, other threads:[~2026-10-01  6:06 UTC | newest]

Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-30 13:45 [PATCH] ext4: save converted extent before merging Jérémy Jean
2026-09-30 13:53 ` sashiko-bot
2026-10-01  6:06 ` Ojaswin Mujoo

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.