Linux Btrfs filesystem development
 help / color / mirror / Atom feed
From: Eric Biggers <ebiggers@kernel.org>
To: Qu Wenruo <wqu@suse.com>
Cc: linux-btrfs@vger.kernel.org, "Roger Alasà" <vonbloom@gmail.com>
Subject: Re: [PATCH v2] btrfs: fix the fsverity callback where unexpected range is verified
Date: Sat, 10 Oct 2026 09:50:23 +0200	[thread overview]
Message-ID: <20261010075023.GA1946@quark> (raw)
In-Reply-To: <15f4ef9f50e1f4af375e45cf976717041f1a96d4.1791613764.git.wqu@suse.com>

On Sat, Oct 10, 2026 at 04:59:49PM +1030, Qu Wenruo wrote:
> [BUG]
> There is a bug report that on v7.2 kernel, compressed extents with
> fsverity enabled can lead to warnings like the following:
> 
>  fs-verity (dm-3, inode 257): FILE CORRUPTED! pos=7471104, level=-1, want_hash=sha256:bedf0e7bc93b48694db719001a8d3e79229cc58ee638b41d4149193505090774, real_hash=sha256:ad7facb2586fc6e966c004d7d1d16b024f5805ff7cb47c7a85dabd8b48892ca7
> 
> The read itself eventually succeeds, and no read error is returned to
> user space.
> 
> [CAUSE]
> Since v7.2 btrfs has enabled large data folio support, now a folio can
> contain multiple blocks even if the page size matches the fs block size.
> And even before that, btrfs already has block size < page size support,
> thus all involved code should assume a folio can contain multiple
> blocks.
> 
> However the function btrfs_verify_folio() calls fsverity_verify_folio(),
> which verifies the whole folio, even if the read range only covers part
> of the folio.
> 
> This forces fsverity to verify garbage data that is not yet read from
> disk, and causes verification failure.
> 
> This is a long-standing bug, but previously it only affected bs < ps
> cases which is not that common.
> Now with the large folio support, it's much easier to trigger with bs ==
> ps cases.
> 
> [FIX]
> Instead of calling fsverity_verify_folio(), call
> fsverity_verify_blocks() to verify only the read range.
> 
> Reported-by: Roger Alasà <vonbloom@gmail.com>
> Link: https://lore.kernel.org/linux-btrfs/CAELqY9==Ter2XQPRp=gjW5T75T+7kcZCXpn5roF2L6tY6mQNxw@mail.gmail.com/
> Fixes: 146054090b08 ("btrfs: initial fsverity support")
> Tested-by: Roger Alasà <vonbloom@gmail.com>
> Signed-off-by: Qu Wenruo <wqu@suse.com>

Please add 'Cc: stable@vger.kernel.org'

Reviewed-by: Eric Biggers <ebiggers@kernel.org>

- Eric

  reply	other threads:[~2026-10-10  7:50 UTC|newest]

Thread overview: 3+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-10-10  6:29 [PATCH v2] btrfs: fix the fsverity callback where unexpected range is verified Qu Wenruo
2026-10-10  7:50 ` Eric Biggers [this message]
2026-10-10  9:10 ` Tito Duarte

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20261010075023.GA1946@quark \
    --to=ebiggers@kernel.org \
    --cc=linux-btrfs@vger.kernel.org \
    --cc=vonbloom@gmail.com \
    --cc=wqu@suse.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox