From: Gao Xiang <xiang@kernel.org>
To: binglei wang <l3b2w1@gmail.com>
Cc: linux-erofs@lists.ozlabs.org, xiang@kernel.org, chao@kernel.org,
shengyong1@xiaomi.com, zbestahu@gmail.com,
jefflexu@linux.alibaba.com, dhavale@google.com,
hongbohbli@tencent.com, guochunhai@vivo.com,
wangshuai12@xiaomi.com, linux-kernel@vger.kernel.org
Subject: Re: [PATCH] erofs: fix unbalanced buf->off handling in erofs_bread()
Date: Fri, 11 Sep 2026 12:18:53 +0800 [thread overview]
Message-ID: <aqOBLWQEkH7_3LSu@XiangdeMacBook-Pro.local> (raw)
In-Reply-To: <CAJ3C4KxqO2--RDZN7jCvYKOjwe-XSUcEj8w74ETeHV2ZUq_1dw@mail.gmail.com>
Hi Binglei,
On Fri, Sep 11, 2026 at 12:01:48PM +0800, binglei wang wrote:
> erofs_bread() locates the target folio with
>
> index = (buf->off + offset) >> PAGE_SHIFT;
>
> but computes the in-folio offset without taking buf->off into account:
>
> return buf->base + (offset & ~PAGE_MASK);
>
> If buf->off is not page-aligned, the returned pointer misses the in-page
> component of buf->off, so callers end up fetching data from a wrong
> offset.
>
> buf->off is set to sbi->dif0.fsoff in erofs_init_metabuf(), and fsoff can
> be specified via the "fsoffset=" mount option, which only requires
> block-size alignment. Therefore, on an image with a sub-page block size
> (e.g. 512 bytes), a non-page-aligned fsoff (e.g. 512) triggers the issue,
> since 512 is a multiple of the block size but not of PAGE_SIZE.
>
> It can be reproduced by mounting an image that is placed at a
> non-page-aligned offset:
>
> mkfs.erofs -b512 -zlz4hc sub.erofs src/
> # prepend 512 bytes of padding to the image
> mount -t erofs -o loop,fsoffset=512 padded.erofs /mnt
>
> which fails with
>
> erofs (device loop0): cannot find valid erofs superblock
>
> because the on-disk superblock (at offset 1024 within the image, i.e.
> 1536 within the padded file) is read from a wrong in-folio offset. With
> this fixed, the very same image mounts successfully and its file contents
> match those read from the unpadded image.
>
> Fix it by including buf->off in the in-folio offset calculation, so that
> it is consistent with the folio index calculation.
>
> Fixes: c36ec00d7f67 ("erofs: add 'fsoffset' mount option to specify
> filesystem offset")
> Cc: <stable@vger.kernel.org> # 6.16+
> Signed-off-by: Binglei Wang <l3b2w1@gmail.com>
The fix looks fine, but the patch format is broken:
Reviewed-by: Gao Xiang <xiang@kernel.org>
I applied the following version manually with an updated
patch subject.
From 135d84c66f85426299db01a09d93a79a87af18ba Mon Sep 17 00:00:00 2001
From: Binglei Wang <l3b2w1@gmail.com>
Date: Fri, 11 Sep 2026 12:11:33 +0800
Subject: [PATCH] erofs: add missing buf->off in erofs_bread()
erofs_bread() locates the target folio with
index = (buf->off + offset) >> PAGE_SHIFT;
but computes the in-folio offset without taking buf->off into account:
return buf->base + (offset & ~PAGE_MASK);
If buf->off is not page-aligned, the returned pointer misses the in-page
component of buf->off, so callers end up fetching data from a wrong
offset.
buf->off is set to sbi->dif0.fsoff in erofs_init_metabuf(), and fsoff can
be specified via the "fsoffset=" mount option, which only requires
block-size alignment. Therefore, on an image with a sub-page block size
(e.g. 512 bytes), a non-page-aligned fsoff (e.g. 512) triggers the issue,
since 512 is a multiple of the block size but not of PAGE_SIZE.
It can be reproduced by mounting an image that is placed at a
non-page-aligned offset:
mkfs.erofs -b512 -zlz4hc sub.erofs src/
# prepend 512 bytes of padding to the image
mount -t erofs -o loop,fsoffset=512 padded.erofs /mnt
which fails with
erofs (device loop0): cannot find valid erofs superblock
because the on-disk superblock (at offset 1024 within the image, i.e.
1536 within the padded file) is read from a wrong in-folio offset. With
this fixed, the very same image mounts successfully and its file contents
match those read from the unpadded image.
Fix it by including buf->off in the in-folio offset calculation, so that
it is consistent with the folio index calculation.
Fixes: c36ec00d7f67 ("erofs: add 'fsoffset' mount option to specify filesystem offset")
Signed-off-by: Binglei Wang <l3b2w1@gmail.com>
Reviewed-by: Gao Xiang <xiang@kernel.org>
Signed-off-by: Gao Xiang <xiang@kernel.org>
---
fs/erofs/data.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/fs/erofs/data.c b/fs/erofs/data.c
index 0885b1f2fc92..be63b89f0862 100644
--- a/fs/erofs/data.c
+++ b/fs/erofs/data.c
@@ -48,7 +48,7 @@ void *erofs_bread(struct erofs_buf *buf, erofs_off_t offset, bool need_kmap)
return NULL;
if (!buf->base)
buf->base = kmap_local_page(buf->page);
- return buf->base + (offset & ~PAGE_MASK);
+ return buf->base + ((buf->off + offset) & ~PAGE_MASK);
}
int erofs_init_metabuf(struct erofs_buf *buf, struct super_block *sb,
--
2.47.3
next prev parent reply other threads:[~2026-09-11 4:19 UTC|newest]
Thread overview: 9+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-11 4:01 [PATCH] erofs: fix unbalanced buf->off handling in erofs_bread() binglei wang
2026-09-11 4:18 ` Gao Xiang [this message]
2026-09-11 4:22 ` binglei wang
-- strict thread matches above, loose matches on Subject: below --
2026-09-11 4:15 binglei wang
2026-09-11 4:16 binglei wang
2026-09-11 4:22 ` Gao Xiang
2026-09-11 4:33 ` binglei wang
2026-09-12 2:57 Binglei Wang
2026-09-12 9:25 ` Gao Xiang
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=aqOBLWQEkH7_3LSu@XiangdeMacBook-Pro.local \
--to=xiang@kernel.org \
--cc=chao@kernel.org \
--cc=dhavale@google.com \
--cc=guochunhai@vivo.com \
--cc=hongbohbli@tencent.com \
--cc=jefflexu@linux.alibaba.com \
--cc=l3b2w1@gmail.com \
--cc=linux-erofs@lists.ozlabs.org \
--cc=linux-kernel@vger.kernel.org \
--cc=shengyong1@xiaomi.com \
--cc=wangshuai12@xiaomi.com \
--cc=zbestahu@gmail.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.