From: syzbot <syzbot+e4876215632c2d23b481@syzkaller.appspotmail.com>
To: linux-kernel@vger.kernel.org, syzkaller-bugs@googlegroups.com
Subject: Re: [syzbot] Re: UBSAN: array-index-out-of-bounds in inline_xattr_addr()
Date: Fri, 20 Dec 2024 03:28:55 -0800 [thread overview]
Message-ID: <676554f7.050a0220.1333dc.00cf.GAE@google.com> (raw)
In-Reply-To: <6764cecc.050a0220.1bfc9e.0001.GAE@google.com>
For archival purposes, forwarding an incoming command email to
linux-kernel@vger.kernel.org, syzkaller-bugs@googlegroups.com.
***
Subject: Re: UBSAN: array-index-out-of-bounds in inline_xattr_addr()
Author: dmantipov@yandex.ru
#syz test https://git.kernel.org/pub/scm/linux/kernel/git/arm64/linux d6ab634f1b323db6639b8b776f5d95ae747b342a
diff --git a/fs/f2fs/inode.c b/fs/f2fs/inode.c
index 282fd320bdb3..3061cf69a7fb 100644
--- a/fs/f2fs/inode.c
+++ b/fs/f2fs/inode.c
@@ -302,15 +302,7 @@ static bool sanity_check_inode(struct inode *inode, struct page *node_page)
F2FS_TOTAL_EXTRA_ATTR_SIZE);
return false;
}
- if (f2fs_sb_has_flexible_inline_xattr(sbi) &&
- f2fs_has_inline_xattr(inode) &&
- (!fi->i_inline_xattr_size ||
- fi->i_inline_xattr_size > MAX_INLINE_XATTR_SIZE)) {
- f2fs_warn(sbi, "%s: inode (ino=%lx) has corrupted i_inline_xattr_size: %d, max: %lu",
- __func__, inode->i_ino, fi->i_inline_xattr_size,
- MAX_INLINE_XATTR_SIZE);
- return false;
- }
+
if (f2fs_sb_has_compression(sbi) &&
fi->i_flags & F2FS_COMPR_FL &&
F2FS_FITS_IN_INODE(ri, fi->i_extra_isize,
@@ -320,6 +312,16 @@ static bool sanity_check_inode(struct inode *inode, struct page *node_page)
}
}
+ if (f2fs_sb_has_flexible_inline_xattr(sbi) &&
+ f2fs_has_inline_xattr(inode) &&
+ (!fi->i_inline_xattr_size ||
+ fi->i_inline_xattr_size > MAX_INLINE_XATTR_SIZE)) {
+ f2fs_warn(sbi, "%s: inode (ino=%lx) has corrupted i_inline_xattr_size: %d, max: %lu",
+ __func__, inode->i_ino, fi->i_inline_xattr_size,
+ MAX_INLINE_XATTR_SIZE);
+ return false;
+ }
+
if (!f2fs_sb_has_extra_attr(sbi)) {
if (f2fs_sb_has_project_quota(sbi)) {
f2fs_warn(sbi, "%s: corrupted inode ino=%lx, wrong feature flag: %u, run fsck to fix.",
next prev parent reply other threads:[~2024-12-20 11:28 UTC|newest]
Thread overview: 13+ messages / expand[flat|nested] mbox.gz Atom feed top
2024-12-20 1:56 [f2fs-dev] [syzbot] [f2fs?] UBSAN: array-index-out-of-bounds in inline_xattr_addr syzbot
2024-12-20 1:56 ` syzbot
2024-12-20 11:28 ` syzbot [this message]
2024-12-22 13:38 ` [f2fs-dev] " Chao Yu via Linux-f2fs-devel
2024-12-22 13:38 ` Chao Yu
2024-12-22 13:38 ` [f2fs-dev] " syzbot
2024-12-22 13:38 ` syzbot
2024-12-22 13:57 ` [f2fs-dev] " Chao Yu via Linux-f2fs-devel
2024-12-22 13:57 ` Chao Yu
2024-12-22 20:55 ` [f2fs-dev] " syzbot
2024-12-22 20:55 ` syzbot
2025-02-11 6:46 ` [f2fs-dev] " Chao Yu via Linux-f2fs-devel
2025-02-11 6:46 ` Chao Yu
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=676554f7.050a0220.1333dc.00cf.GAE@google.com \
--to=syzbot+e4876215632c2d23b481@syzkaller.appspotmail.com \
--cc=linux-kernel@vger.kernel.org \
--cc=syzkaller-bugs@googlegroups.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.