From: Gao Xiang <xiang@kernel.org>
To: ChengyuZhu6 <hudson@cyzhu.com>
Cc: linux-erofs@lists.ozlabs.org, xiang@kernel.org,
Chengyu Zhu <hudsonzhu@tencent.com>
Subject: Re: [PATCH] erofs: delimit inode_share cache key components
Date: Mon, 7 Sep 2026 16:18:29 +0800 [thread overview]
Message-ID: <ap5zVT1PJQnMW6i3@XiangdeMacBook-Pro.local> (raw)
In-Reply-To: <20260907072440.76001-1-hudson@cyzhu.com>
Hi Chengyu,
On Mon, Sep 07, 2026 at 03:24:40PM +0800, ChengyuZhu6 wrote:
> From: Chengyu Zhu <hudsonzhu@tencent.com>
>
> The selected fingerprint xattr is treated as opaque and accepts any
> positive length up to the filesystem block size. Appending the domain ID
> directly to such a value leaves no boundary between the two key components
> if a different fingerprint length is used.
>
> Change the key encoding as follows:
>
> fingerprint || domain_id -> domain_id || '\0' || fingerprint
>
> Since a mount option string cannot contain NUL, this makes the in-memory
> tuple unambiguous without constraining fingerprint contents or changing
> the on-disk format.
>
> Signed-off-by: Chengyu Zhu <hudsonzhu@tencent.com>
Subject: erofs: delimit inode_share key components
Previously, inode_share keys are encoded as follows:
fingerprint || domain_id
It would be better to have a separator between fingerprint and domain_id
so that fingerprint won't be parsed as part of a domain_id.
Change the key encoding as follows:
domain_id || '\0' || fingerprint
Since domain_id is a NIL-terminated string, this makes the in-memory
key indices unambiguous.
> ---
> fs/erofs/xattr.c | 9 ++++++---
> 1 file changed, 6 insertions(+), 3 deletions(-)
>
> diff --git a/fs/erofs/xattr.c b/fs/erofs/xattr.c
> index df7ea019526d..17c640aca5f7 100644
> --- a/fs/erofs/xattr.c
> +++ b/fs/erofs/xattr.c
> @@ -621,6 +621,7 @@ int erofs_xattr_fill_inode_fingerprint(struct erofs_inode_fingerprint *fp,
> struct erofs_sb_info *sbi = EROFS_SB(inode->i_sb);
> struct erofs_xattr_prefix_item *prefix;
> const char *infix;
> + size_t domainlen;
> int valuelen, base_index;
>
> if (!test_opt(&sbi->opt, INODE_SHARE))
> @@ -633,17 +634,19 @@ int erofs_xattr_fill_inode_fingerprint(struct erofs_inode_fingerprint *fp,
> valuelen = erofs_getxattr(inode, base_index, infix, NULL, 0);
> if (valuelen <= 0 || valuelen > (1 << sbi->blkszbits))
> return -EFSCORRUPTED;
> - fp->size = valuelen + (domain_id ? strlen(domain_id) : 0);
> + domain_id = domain_id ?: "";
> + domainlen = strlen(domain_id);
> + fp->size = domainlen + 1 + valuelen;
> fp->opaque = kmalloc(fp->size, GFP_KERNEL);
> if (!fp->opaque)
> return -ENOMEM;
> + memcpy(fp->opaque, domain_id, domainlen + 1);
> if (valuelen != erofs_getxattr(inode, base_index, infix,
> - fp->opaque, valuelen)) {
> + fp->opaque + domainlen + 1, valuelen)) {
> kfree(fp->opaque);
> fp->opaque = NULL;
> return -EFSCORRUPTED;
> }
> - memcpy(fp->opaque + valuelen, domain_id, fp->size - valuelen);
> return 0;
Can you apply the following diff? domain_id cannot be NULL so it was a
redundant check:
diff --git a/fs/erofs/xattr.c b/fs/erofs/xattr.c
index 17c640aca5f7..57cfb7520782 100644
--- a/fs/erofs/xattr.c
+++ b/fs/erofs/xattr.c
@@ -620,9 +620,8 @@ int erofs_xattr_fill_inode_fingerprint(struct erofs_inode_fingerprint *fp,
{
struct erofs_sb_info *sbi = EROFS_SB(inode->i_sb);
struct erofs_xattr_prefix_item *prefix;
+ int domainlen, valuelen, base_index;
const char *infix;
- size_t domainlen;
- int valuelen, base_index;
if (!test_opt(&sbi->opt, INODE_SHARE))
return -EOPNOTSUPP;
@@ -634,7 +633,6 @@ int erofs_xattr_fill_inode_fingerprint(struct erofs_inode_fingerprint *fp,
valuelen = erofs_getxattr(inode, base_index, infix, NULL, 0);
if (valuelen <= 0 || valuelen > (1 << sbi->blkszbits))
return -EFSCORRUPTED;
- domain_id = domain_id ?: "";
domainlen = strlen(domain_id);
fp->size = domainlen + 1 + valuelen;
fp->opaque = kmalloc(fp->size, GFP_KERNEL);
> }
> #endif
> --
> 2.51.0
next prev parent reply other threads:[~2026-09-07 8:18 UTC|newest]
Thread overview: 4+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-07 7:24 [PATCH] erofs: delimit inode_share cache key components ChengyuZhu6
2026-09-07 8:18 ` Gao Xiang [this message]
2026-09-07 8:33 ` [PATCH v2] " ChengyuZhu6
2026-09-07 9:10 ` Gao Xiang
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=ap5zVT1PJQnMW6i3@XiangdeMacBook-Pro.local \
--to=xiang@kernel.org \
--cc=hudson@cyzhu.com \
--cc=hudsonzhu@tencent.com \
--cc=linux-erofs@lists.ozlabs.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.