* [PATCH v2] btrfs: fix the fsverity callback where unexpected range is verified
@ 2026-10-10 6:29 Qu Wenruo
2026-10-10 7:50 ` Eric Biggers
2026-10-10 9:10 ` Tito Duarte
0 siblings, 2 replies; 3+ messages in thread
From: Qu Wenruo @ 2026-10-10 6:29 UTC (permalink / raw)
To: linux-btrfs; +Cc: Roger Alasà
[BUG]
There is a bug report that on v7.2 kernel, compressed extents with
fsverity enabled can lead to warnings like the following:
fs-verity (dm-3, inode 257): FILE CORRUPTED! pos=7471104, level=-1, want_hash=sha256:bedf0e7bc93b48694db719001a8d3e79229cc58ee638b41d4149193505090774, real_hash=sha256:ad7facb2586fc6e966c004d7d1d16b024f5805ff7cb47c7a85dabd8b48892ca7
The read itself eventually succeeds, and no read error is returned to
user space.
[CAUSE]
Since v7.2 btrfs has enabled large data folio support, now a folio can
contain multiple blocks even if the page size matches the fs block size.
And even before that, btrfs already has block size < page size support,
thus all involved code should assume a folio can contain multiple
blocks.
However the function btrfs_verify_folio() calls fsverity_verify_folio(),
which verifies the whole folio, even if the read range only covers part
of the folio.
This forces fsverity to verify garbage data that is not yet read from
disk, and causes verification failure.
This is a long-standing bug, but previously it only affected bs < ps
cases which is not that common.
Now with the large folio support, it's much easier to trigger with bs ==
ps cases.
[FIX]
Instead of calling fsverity_verify_folio(), call
fsverity_verify_blocks() to verify only the read range.
Reported-by: Roger Alasà <vonbloom@gmail.com>
Link: https://lore.kernel.org/linux-btrfs/CAELqY9==Ter2XQPRp=gjW5T75T+7kcZCXpn5roF2L6tY6mQNxw@mail.gmail.com/
Fixes: 146054090b08 ("btrfs: initial fsverity support")
Tested-by: Roger Alasà <vonbloom@gmail.com>
Signed-off-by: Qu Wenruo <wqu@suse.com>
---
Changelog
v2:
- Refresh the [BUG] section to show the symptom better
---
fs/btrfs/extent_io.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/fs/btrfs/extent_io.c b/fs/btrfs/extent_io.c
index 55e9144d4759..5ff630630490 100644
--- a/fs/btrfs/extent_io.c
+++ b/fs/btrfs/extent_io.c
@@ -504,7 +504,7 @@ static bool btrfs_verify_folio(struct fsverity_info *vi, struct folio *folio,
if (!vi || btrfs_folio_test_uptodate(fs_info, folio, start, len))
return true;
- return fsverity_verify_folio(vi, folio);
+ return fsverity_verify_blocks(vi, folio, len, offset_in_folio(folio, start));
}
static void end_folio_read(struct fsverity_info *vi, struct folio *folio,
--
2.56.0
^ permalink raw reply related [flat|nested] 3+ messages in thread
* Re: [PATCH v2] btrfs: fix the fsverity callback where unexpected range is verified
2026-10-10 6:29 [PATCH v2] btrfs: fix the fsverity callback where unexpected range is verified Qu Wenruo
@ 2026-10-10 7:50 ` Eric Biggers
2026-10-10 9:10 ` Tito Duarte
1 sibling, 0 replies; 3+ messages in thread
From: Eric Biggers @ 2026-10-10 7:50 UTC (permalink / raw)
To: Qu Wenruo; +Cc: linux-btrfs, Roger Alasà
On Sat, Oct 10, 2026 at 04:59:49PM +1030, Qu Wenruo wrote:
> [BUG]
> There is a bug report that on v7.2 kernel, compressed extents with
> fsverity enabled can lead to warnings like the following:
>
> fs-verity (dm-3, inode 257): FILE CORRUPTED! pos=7471104, level=-1, want_hash=sha256:bedf0e7bc93b48694db719001a8d3e79229cc58ee638b41d4149193505090774, real_hash=sha256:ad7facb2586fc6e966c004d7d1d16b024f5805ff7cb47c7a85dabd8b48892ca7
>
> The read itself eventually succeeds, and no read error is returned to
> user space.
>
> [CAUSE]
> Since v7.2 btrfs has enabled large data folio support, now a folio can
> contain multiple blocks even if the page size matches the fs block size.
> And even before that, btrfs already has block size < page size support,
> thus all involved code should assume a folio can contain multiple
> blocks.
>
> However the function btrfs_verify_folio() calls fsverity_verify_folio(),
> which verifies the whole folio, even if the read range only covers part
> of the folio.
>
> This forces fsverity to verify garbage data that is not yet read from
> disk, and causes verification failure.
>
> This is a long-standing bug, but previously it only affected bs < ps
> cases which is not that common.
> Now with the large folio support, it's much easier to trigger with bs ==
> ps cases.
>
> [FIX]
> Instead of calling fsverity_verify_folio(), call
> fsverity_verify_blocks() to verify only the read range.
>
> Reported-by: Roger Alasà <vonbloom@gmail.com>
> Link: https://lore.kernel.org/linux-btrfs/CAELqY9==Ter2XQPRp=gjW5T75T+7kcZCXpn5roF2L6tY6mQNxw@mail.gmail.com/
> Fixes: 146054090b08 ("btrfs: initial fsverity support")
> Tested-by: Roger Alasà <vonbloom@gmail.com>
> Signed-off-by: Qu Wenruo <wqu@suse.com>
Please add 'Cc: stable@vger.kernel.org'
Reviewed-by: Eric Biggers <ebiggers@kernel.org>
- Eric
^ permalink raw reply [flat|nested] 3+ messages in thread
* Re: [PATCH v2] btrfs: fix the fsverity callback where unexpected range is verified
2026-10-10 6:29 [PATCH v2] btrfs: fix the fsverity callback where unexpected range is verified Qu Wenruo
2026-10-10 7:50 ` Eric Biggers
@ 2026-10-10 9:10 ` Tito Duarte
1 sibling, 0 replies; 3+ messages in thread
From: Tito Duarte @ 2026-10-10 9:10 UTC (permalink / raw)
To: wqu; +Cc: linux-btrfs, ebiggers, vonbloom
On Sat, Oct 10, 2026 at 04:59:49PM +1030, Qu Wenruo wrote:
> [FIX]
> Instead of calling fsverity_verify_folio(), call
> fsverity_verify_blocks() to verify only the read range.
Tested on Debian's 7.2.8-1 kernel with this change applied, 4K pages:
- arm64 VM (virtio-blk), the reproducer from my report [1]: from 10
spurious "FILE CORRUPTED" reports per 30 mount/read cycles to 0
(0 in 120 cycles over four runs)
- boots from a composefs root with overlayfs verity=require on btrfs:
arm64 previously 7-10 reports per test run (three boots), now none;
x86_64 with Secure Boot and lockdown also clean
Sorry for the duplicate report, I had missed your patch.
Tested-by: Tito Duarte <duartito@gmail.com>
[1] https://lore.kernel.org/linux-btrfs/20261010083827.27604-1-duartito@gmail.com/
^ permalink raw reply [flat|nested] 3+ messages in thread
end of thread, other threads:[~2026-10-10 9:10 UTC | newest]
Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-10-10 6:29 [PATCH v2] btrfs: fix the fsverity callback where unexpected range is verified Qu Wenruo
2026-10-10 7:50 ` Eric Biggers
2026-10-10 9:10 ` Tito Duarte
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox