From: Chao Yu via Linux-f2fs-devel <linux-f2fs-devel@lists.sourceforge.net>
To: Dmitry Antipov <dmantipov@yandex.ru>, Jaegeuk Kim <jaegeuk@kernel.org>
Cc: linux-fsdevel@vger.kernel.org,
syzbot+5141f6db57a2f7614352@syzkaller.appspotmail.com,
lvc-project@linuxtesting.org,
linux-f2fs-devel@lists.sourceforge.net
Subject: Re: [f2fs-dev] [PATCH] f2fs: ensure that node info flags are always initialized
Date: Thu, 12 Dec 2024 22:59:54 +0800 [thread overview]
Message-ID: <ec2729cc-2846-49c2-b7ca-4c1efe004cd1@kernel.org> (raw)
In-Reply-To: <20241204060934.697070-1-dmantipov@yandex.ru>
On 2024/12/4 14:09, Dmitry Antipov wrote:
> Syzbot has reported the following KMSAN splat:
>
> BUG: KMSAN: uninit-value in f2fs_new_node_page+0x1494/0x1630
> f2fs_new_node_page+0x1494/0x1630
> f2fs_new_inode_page+0xb9/0x100
> f2fs_init_inode_metadata+0x176/0x1e90
> f2fs_add_inline_entry+0x723/0xc90
> f2fs_do_add_link+0x48f/0xa70
> f2fs_symlink+0x6af/0xfc0
> vfs_symlink+0x1f1/0x470
> do_symlinkat+0x471/0xbc0
> __x64_sys_symlink+0xcf/0x140
> x64_sys_call+0x2fcc/0x3d90
> do_syscall_64+0xd9/0x1b0
> entry_SYSCALL_64_after_hwframe+0x77/0x7f
>
> Local variable new_ni created at:
> f2fs_new_node_page+0x9d/0x1630
> f2fs_new_inode_page+0xb9/0x100
>
> So adjust 'f2fs_new_node_page()' to ensure that 'flag' field of on-stack
> 'struct node_info' is always zeroed just like if it was allocated within
> 'struct nat_entry' via 'f2fs_kmem_cache_alloc(..., GFP_F2FS_ZERO, ...)'
> in '__alloc_nat_entry()'.
>
> Reported-by: syzbot+5141f6db57a2f7614352@syzkaller.appspotmail.com
> Closes: https://syzkaller.appspot.com/bug?extid=5141f6db57a2f7614352
> Fixes: e05df3b115e7 ("f2fs: add node operations")
> Signed-off-by: Dmitry Antipov <dmantipov@yandex.ru>
> ---
> fs/f2fs/node.c | 2 +-
> 1 file changed, 1 insertion(+), 1 deletion(-)
>
> diff --git a/fs/f2fs/node.c b/fs/f2fs/node.c
> index 0b900a7a48e5..5103cc0d95c4 100644
> --- a/fs/f2fs/node.c
> +++ b/fs/f2fs/node.c
> @@ -1314,7 +1314,7 @@ struct page *f2fs_new_inode_page(struct inode *inode)
> struct page *f2fs_new_node_page(struct dnode_of_data *dn, unsigned int ofs)
> {
> struct f2fs_sb_info *sbi = F2FS_I_SB(dn->inode);
> - struct node_info new_ni;
> + struct node_info new_ni = { .flag = 0 };
We can initialize new_ni.flag in f2fs_get_node_info() to cover
all similar cases?
Thanks,
> struct page *page;
> int err;
>
_______________________________________________
Linux-f2fs-devel mailing list
Linux-f2fs-devel@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/linux-f2fs-devel
WARNING: multiple messages have this Message-ID (diff)
From: Chao Yu <chao@kernel.org>
To: Dmitry Antipov <dmantipov@yandex.ru>, Jaegeuk Kim <jaegeuk@kernel.org>
Cc: Chao Yu <chao@kernel.org>,
linux-f2fs-devel@lists.sourceforge.net,
linux-fsdevel@vger.kernel.org, lvc-project@linuxtesting.org,
syzbot+5141f6db57a2f7614352@syzkaller.appspotmail.com
Subject: Re: [PATCH] f2fs: ensure that node info flags are always initialized
Date: Thu, 12 Dec 2024 22:59:54 +0800 [thread overview]
Message-ID: <ec2729cc-2846-49c2-b7ca-4c1efe004cd1@kernel.org> (raw)
In-Reply-To: <20241204060934.697070-1-dmantipov@yandex.ru>
On 2024/12/4 14:09, Dmitry Antipov wrote:
> Syzbot has reported the following KMSAN splat:
>
> BUG: KMSAN: uninit-value in f2fs_new_node_page+0x1494/0x1630
> f2fs_new_node_page+0x1494/0x1630
> f2fs_new_inode_page+0xb9/0x100
> f2fs_init_inode_metadata+0x176/0x1e90
> f2fs_add_inline_entry+0x723/0xc90
> f2fs_do_add_link+0x48f/0xa70
> f2fs_symlink+0x6af/0xfc0
> vfs_symlink+0x1f1/0x470
> do_symlinkat+0x471/0xbc0
> __x64_sys_symlink+0xcf/0x140
> x64_sys_call+0x2fcc/0x3d90
> do_syscall_64+0xd9/0x1b0
> entry_SYSCALL_64_after_hwframe+0x77/0x7f
>
> Local variable new_ni created at:
> f2fs_new_node_page+0x9d/0x1630
> f2fs_new_inode_page+0xb9/0x100
>
> So adjust 'f2fs_new_node_page()' to ensure that 'flag' field of on-stack
> 'struct node_info' is always zeroed just like if it was allocated within
> 'struct nat_entry' via 'f2fs_kmem_cache_alloc(..., GFP_F2FS_ZERO, ...)'
> in '__alloc_nat_entry()'.
>
> Reported-by: syzbot+5141f6db57a2f7614352@syzkaller.appspotmail.com
> Closes: https://syzkaller.appspot.com/bug?extid=5141f6db57a2f7614352
> Fixes: e05df3b115e7 ("f2fs: add node operations")
> Signed-off-by: Dmitry Antipov <dmantipov@yandex.ru>
> ---
> fs/f2fs/node.c | 2 +-
> 1 file changed, 1 insertion(+), 1 deletion(-)
>
> diff --git a/fs/f2fs/node.c b/fs/f2fs/node.c
> index 0b900a7a48e5..5103cc0d95c4 100644
> --- a/fs/f2fs/node.c
> +++ b/fs/f2fs/node.c
> @@ -1314,7 +1314,7 @@ struct page *f2fs_new_inode_page(struct inode *inode)
> struct page *f2fs_new_node_page(struct dnode_of_data *dn, unsigned int ofs)
> {
> struct f2fs_sb_info *sbi = F2FS_I_SB(dn->inode);
> - struct node_info new_ni;
> + struct node_info new_ni = { .flag = 0 };
We can initialize new_ni.flag in f2fs_get_node_info() to cover
all similar cases?
Thanks,
> struct page *page;
> int err;
>
next prev parent reply other threads:[~2024-12-12 15:00 UTC|newest]
Thread overview: 10+ messages / expand[flat|nested] mbox.gz Atom feed top
2024-12-04 6:09 [f2fs-dev] [PATCH] f2fs: ensure that node info flags are always initialized Dmitry Antipov
2024-12-04 6:09 ` Dmitry Antipov
2024-12-12 14:59 ` Chao Yu via Linux-f2fs-devel [this message]
2024-12-12 14:59 ` Chao Yu
2024-12-12 17:57 ` [f2fs-dev] [PATCH v2] " Dmitry Antipov
2024-12-12 17:57 ` Dmitry Antipov
2024-12-16 13:47 ` [f2fs-dev] " Chao Yu via Linux-f2fs-devel
2024-12-16 13:47 ` Chao Yu
2024-12-16 16:40 ` [f2fs-dev] " patchwork-bot+f2fs--- via Linux-f2fs-devel
2024-12-16 16:40 ` patchwork-bot+f2fs
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=ec2729cc-2846-49c2-b7ca-4c1efe004cd1@kernel.org \
--to=linux-f2fs-devel@lists.sourceforge.net \
--cc=chao@kernel.org \
--cc=dmantipov@yandex.ru \
--cc=jaegeuk@kernel.org \
--cc=linux-fsdevel@vger.kernel.org \
--cc=lvc-project@linuxtesting.org \
--cc=syzbot+5141f6db57a2f7614352@syzkaller.appspotmail.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.