From: "Darrick J. Wong" <djwong@kernel.org>
To: tytso@mit.edu
Cc: linux-ext4@vger.kernel.org, linux-ext4@vger.kernel.org
Subject: [PATCH 17/19] fuse2fs: fix link count overflows on dir_nlink filesystems
Date: Thu, 06 Nov 2025 14:35:35 -0800 [thread overview]
Message-ID: <176246793936.2862242.4057006934868513614.stgit@frogsfrogsfrogs> (raw)
In-Reply-To: <176246793541.2862242.16879509838698966689.stgit@frogsfrogsfrogs>
From: Darrick J. Wong <djwong@kernel.org>
On a dir_nlink filesystem, a dir with more than 65000 subdirs ends up
with i_links_count (aka nlink) of 1. libext2fs wraps around and does
the wrong thing, which may have caused a lot of havoc over the years.
The kernel actually knows how to do this properly (it freezes the link
count at 1 when it would overflow) so use the helpers we added in the
previous patch to make fuse2fs behave the same as the kernel.
This is a convenient time to fix the annoying behavior that one has to
call remove_inode twice to rmdir a directory, and actually check for
link count overflows when renaming or hardlinking files.
Found via ext4/045.
Cc: <linux-ext4@vger.kernel.org> # v1.43
Fixes: 81cbf1ef4f5dab ("misc: add fuse2fs, a FUSE server for e2fsprogs")
Signed-off-by: "Darrick J. Wong" <djwong@kernel.org>
---
misc/fuse2fs.c | 85 +++++++++++++++++++++++++++++++++++++++++++++-----------
1 file changed, 69 insertions(+), 16 deletions(-)
diff --git a/misc/fuse2fs.c b/misc/fuse2fs.c
index fd21f546db7fb1..b1cac46ddce567 100644
--- a/misc/fuse2fs.c
+++ b/misc/fuse2fs.c
@@ -1798,21 +1798,34 @@ static int remove_inode(struct fuse2fs *ff, ext2_ino_t ino)
dbg_printf(ff, "%s: put ino=%d links=%d\n", __func__, ino,
inode.i_links_count);
- switch (inode.i_links_count) {
- case 0:
- return 0; /* XXX: already done? */
- case 1:
- inode.i_links_count--;
+ if (S_ISDIR(inode.i_mode)) {
+ /*
+ * Caller should have checked that this is an empty directory
+ * before starting the unlink process. nlink is usually 2, but
+ * it could be 1 if this dir ever had more than 65000 subdirs.
+ * Zero the link count.
+ */
+ if (!ext2fs_dir_link_empty(EXT2_INODE(&inode)))
+ return translate_error(fs, ino, EXT2_ET_INODE_CORRUPTED);
+ inode.i_links_count = 0;
ext2fs_set_dtime(fs, EXT2_INODE(&inode));
- break;
- default:
+ } else {
+ /*
+ * Any other file type can be hardlinked, so all we need to do
+ * is decrement the nlink.
+ */
+ if (inode.i_links_count == 0)
+ return translate_error(fs, ino, EXT2_ET_INODE_CORRUPTED);
inode.i_links_count--;
+ if (!inode.i_links_count)
+ ext2fs_set_dtime(fs, EXT2_INODE(&inode));
}
ret = update_ctime(fs, ino, &inode);
if (ret)
return ret;
+ /* Still linked? Leave it be. */
if (inode.i_links_count)
goto write_out;
@@ -1964,10 +1977,6 @@ static int __op_rmdir(struct fuse2fs *ff, const char *path)
}
ret = fuse2fs_unlink(ff, path, &parent);
- if (ret)
- goto out;
- /* Directories have to be "removed" twice. */
- ret = remove_inode(ff, child);
if (ret)
goto out;
ret = remove_inode(ff, child);
@@ -1982,8 +1991,7 @@ static int __op_rmdir(struct fuse2fs *ff, const char *path)
ret = translate_error(fs, rds.parent, err);
goto out;
}
- if (inode.i_links_count > 1)
- inode.i_links_count--;
+ ext2fs_dec_nlink(EXT2_INODE(&inode));
ret = update_mtime(fs, rds.parent, &inode);
if (ret)
goto out;
@@ -2149,6 +2157,41 @@ static int update_dotdot_helper(ext2_ino_t dir EXT2FS_ATTR((unused)),
return 0;
}
+/*
+ * If we're moving a directory, make sure that the new parent of that directory
+ * can handle the nlink bump.
+ */
+static int fuse2fs_check_from_dir_nlink(struct fuse2fs *ff, ext2_ino_t from_ino,
+ ext2_ino_t to_ino,
+ ext2_ino_t from_dir_ino,
+ ext2_ino_t to_dir_ino)
+{
+ struct ext2_inode_large inode;
+ errcode_t err;
+
+ err = fuse2fs_read_inode(ff->fs, from_ino, &inode);
+ if (err)
+ return translate_error(ff->fs, from_ino, err);
+
+ if (!S_ISDIR(inode.i_mode))
+ return 0;
+
+ if (to_ino != 0)
+ return 0;
+
+ if (to_dir_ino == from_dir_ino)
+ return 0;
+
+ err = fuse2fs_read_inode(ff->fs, to_dir_ino, &inode);
+ if (err)
+ return translate_error(ff->fs, from_ino, err);
+
+ if (ext2fs_dir_link_max(ff->fs, &inode))
+ return -EMLINK;
+
+ return 0;
+}
+
static int op_rename(const char *from, const char *to
#if FUSE_VERSION >= FUSE_MAKE_VERSION(3, 0)
, unsigned int flags EXT2FS_ATTR((unused))
@@ -2275,6 +2318,11 @@ static int op_rename(const char *from, const char *to
if (ret)
goto out2;
+ ret = fuse2fs_check_from_dir_nlink(ff, from_ino, to_ino, from_dir_ino,
+ to_dir_ino);
+ if (ret)
+ goto out2;
+
/* If the target exists, unlink it first */
if (to_ino != 0) {
err = ext2fs_read_inode(fs, to_ino, &inode);
@@ -2337,7 +2385,7 @@ static int op_rename(const char *from, const char *to
ret = translate_error(fs, from_dir_ino, err);
goto out2;
}
- inode.i_links_count--;
+ ext2fs_dec_nlink(&inode);
err = ext2fs_write_inode(fs, from_dir_ino, &inode);
if (err) {
ret = translate_error(fs, from_dir_ino, err);
@@ -2350,7 +2398,7 @@ static int op_rename(const char *from, const char *to
ret = translate_error(fs, to_dir_ino, err);
goto out2;
}
- inode.i_links_count++;
+ ext2fs_inc_nlink(fs, &inode);
err = ext2fs_write_inode(fs, to_dir_ino, &inode);
if (err) {
ret = translate_error(fs, to_dir_ino, err);
@@ -2453,7 +2501,12 @@ static int op_link(const char *src, const char *dest)
if (ret)
goto out2;
- inode.i_links_count++;
+ if (ext2fs_dir_link_max(ff->fs, &inode)) {
+ ret = -EMLINK;
+ goto out2;
+ }
+
+ ext2fs_inc_nlink(fs, EXT2_INODE(&inode));
ret = update_ctime(fs, ino, &inode);
if (ret)
goto out2;
next prev parent reply other threads:[~2025-11-06 22:35 UTC|newest]
Thread overview: 84+ messages / expand[flat|nested] mbox.gz Atom feed top
2025-11-06 22:14 [PATCHBOMB 1.48] fuse2fs: new features, new server Darrick J. Wong
2025-11-06 22:27 ` [PATCHSET 1/9] fuse2fs: fix locking problems Darrick J. Wong
2025-11-06 22:30 ` [PATCH 1/4] libext2fs: add POSIX advisory locking to the unix IO manager Darrick J. Wong
2025-11-06 22:30 ` [PATCH 2/4] fuse2fs: try to lock filesystem image files before using them Darrick J. Wong
2025-11-06 22:30 ` [PATCH 3/4] fuse2fs: quiet down write-protect warning Darrick J. Wong
2025-11-06 22:31 ` [PATCH 4/4] fuse2fs: try to grab block device O_EXCL repeatedly Darrick J. Wong
2025-11-06 22:28 ` [PATCHSET 2/9] fuse2fs: add some easy new features Darrick J. Wong
2025-11-06 22:31 ` [PATCH 01/19] libext2fs: initialize htree when expanding directory Darrick J. Wong
2025-11-06 22:31 ` [PATCH 02/19] libext2fs: create link count adjustment helpers for dir_nlink Darrick J. Wong
2025-11-06 22:31 ` [PATCH 03/19] libext2fs: fix ext2fs_mmp_update Darrick J. Wong
2025-11-06 22:32 ` [PATCH 04/19] libext2fs: refactor aligned MMP buffer allocation Darrick J. Wong
2025-11-06 22:32 ` [PATCH 05/19] libext2fs: always use ext2fs_mmp_get_mem to allocate fs->mmp_buf Darrick J. Wong
2025-11-06 22:32 ` [PATCH 06/19] fuse2fs: check root directory while mounting Darrick J. Wong
2025-11-06 22:32 ` [PATCH 07/19] fuse2fs: read bitmaps asynchronously during initialization Darrick J. Wong
2025-11-06 22:33 ` [PATCH 08/19] fuse2fs: use file handles when possible Darrick J. Wong
2025-11-06 22:33 ` [PATCH 09/19] fuse2fs: implement dir seeking Darrick J. Wong
2025-11-06 22:33 ` [PATCH 10/19] fuse2fs: implement readdirplus Darrick J. Wong
2025-11-06 22:34 ` [PATCH 11/19] fuse2fs: implement dirsync mode Darrick J. Wong
2025-11-06 22:34 ` [PATCH 12/19] fuse2fs: only flush O_SYNC files on close Darrick J. Wong
2025-11-06 22:34 ` [PATCH 13/19] fuse2fs: improve want_extra_isize handling Darrick J. Wong
2025-11-06 22:34 ` [PATCH 14/19] fuse2fs: cache symlink targets in the kernel Darrick J. Wong
2025-11-06 22:35 ` [PATCH 15/19] fuse2fs: constrain worker thread count Darrick J. Wong
2025-11-06 22:35 ` [PATCH 16/19] fuse2fs: improve error handling behaviors Darrick J. Wong
2025-11-06 22:35 ` Darrick J. Wong [this message]
2025-11-06 22:35 ` [PATCH 18/19] libsupport: add background thread manager Darrick J. Wong
2025-11-06 22:36 ` [PATCH 19/19] fuse2fs: implement MMP updates Darrick J. Wong
2025-11-06 22:28 ` [PATCHSET 3/9] fuse2fs: clean up operation startup Darrick J. Wong
2025-11-06 22:36 ` [PATCH 1/9] fuse2fs: rework FUSE2FS_CHECK_CONTEXT not to rely on global_fs Darrick J. Wong
2025-11-06 22:36 ` [PATCH 2/9] fuse2fs: rework checking file handles Darrick J. Wong
2025-11-06 22:36 ` [PATCH 3/9] fuse2fs: rework fallocate file handle extraction Darrick J. Wong
2025-11-06 22:37 ` [PATCH 4/9] fuse2fs: consolidate file handle checking in op_ioctl Darrick J. Wong
2025-11-06 22:37 ` [PATCH 5/9] fuse2fs: move fs assignment closer to locking the bfl Darrick J. Wong
2025-11-06 22:37 ` [PATCH 6/9] fuse2fs: clean up operation startup Darrick J. Wong
2025-11-06 22:37 ` [PATCH 7/9] fuse2fs: clean up operation completion Darrick J. Wong
2025-11-06 22:38 ` [PATCH 8/9] fuse2fs: clean up more boilerplate Darrick J. Wong
2025-11-06 22:38 ` [PATCH 9/9] fuse2fs: collect runtime of various operations Darrick J. Wong
2025-11-06 22:28 ` [PATCHSET 4/9] fuse2fs: refactor unmount code Darrick J. Wong
2025-11-06 22:38 ` [PATCH 1/3] fuse2fs: get rid of the global_fs variable Darrick J. Wong
2025-11-06 22:39 ` [PATCH 2/3] fuse2fs: hoist lockfile code Darrick J. Wong
2025-11-06 22:39 ` [PATCH 3/3] fuse2fs: hoist unmount code from main Darrick J. Wong
2025-11-06 22:28 ` [PATCHSET 5/9] fuse2fs: refactor mount code Darrick J. Wong
2025-11-06 22:39 ` [PATCH 1/3] fuse2fs: split filesystem mounting into helper functions Darrick J. Wong
2025-11-06 22:39 ` [PATCH 2/3] fuse2fs: register as an IO flusher thread Darrick J. Wong
2025-11-06 22:40 ` [PATCH 3/3] fuse2fs: adjust OOM killer score if possible Darrick J. Wong
2025-11-06 22:29 ` [PATCHSET 6/9] fuse2fs: improve operation tracing Darrick J. Wong
2025-11-06 22:40 ` [PATCH 1/4] fuse2fs: hook library error message printing Darrick J. Wong
2025-11-06 22:40 ` [PATCH 2/4] fuse2fs: print the function name in error messages, not the file name Darrick J. Wong
2025-11-06 22:40 ` [PATCH 3/4] fuse2fs: improve tracing for file range operations Darrick J. Wong
2025-11-06 22:41 ` [PATCH 4/4] fuse2fs: record thread id in debug trace data Darrick J. Wong
2025-11-06 22:29 ` [PATCHSET 7/9] fuse2fs: better tracking of writable state Darrick J. Wong
2025-11-06 22:41 ` [PATCH 1/3] fuse2fs: pass a struct fuse2fs to fs_writeable Darrick J. Wong
2025-11-06 22:41 ` [PATCH 2/3] fuse2fs: track our own writable state Darrick J. Wong
2025-11-06 22:41 ` [PATCH 3/3] fuse2fs: enable the shutdown ioctl Darrick J. Wong
2025-11-06 22:29 ` [PATCHSET 8/9] fuse2fs: upgrade to libfuse 3.17 Darrick J. Wong
2025-11-06 22:42 ` [PATCH 1/4] fuse2fs: bump library version Darrick J. Wong
2025-11-06 22:42 ` [PATCH 2/4] fuse2fs: wrap the fuse_set_feature_flag helper for older libfuse Darrick J. Wong
2025-11-06 22:42 ` [PATCH 3/4] fuse2fs: disable nfs exports Darrick J. Wong
2025-11-06 22:43 ` [PATCH 4/4] fuse2fs: drop fuse 2.x support code Darrick J. Wong
2025-11-06 22:30 ` [PATCHSET 9/9] fuse4fs: fork a low level fuse server Darrick J. Wong
2025-11-06 22:43 ` [PATCH 01/23] fuse2fs: separate libfuse3 and fuse2fs detection in configure Darrick J. Wong
2025-11-06 22:43 ` [PATCH 02/23] fuse2fs: start porting fuse2fs to lowlevel libfuse API Darrick J. Wong
2025-11-06 22:43 ` [PATCH 03/23] debian: create new package for fuse4fs Darrick J. Wong
2025-11-06 22:44 ` [PATCH 04/23] fuse4fs: namespace some helpers Darrick J. Wong
2025-11-07 8:09 ` Amir Goldstein
2025-11-08 0:25 ` Darrick J. Wong
2025-11-06 22:44 ` [PATCH 05/23] fuse4fs: convert to low level API Darrick J. Wong
2025-11-06 22:44 ` [PATCH 06/23] libsupport: port the kernel list.h to libsupport Darrick J. Wong
2025-11-06 22:44 ` [PATCH 07/23] libsupport: add a cache Darrick J. Wong
2025-11-06 22:45 ` [PATCH 08/23] cache: disable debugging Darrick J. Wong
2025-11-06 22:45 ` [PATCH 09/23] cache: use modern list iterator macros Darrick J. Wong
2025-11-06 22:45 ` [PATCH 10/23] cache: embed struct cache in the owner Darrick J. Wong
2025-11-06 22:45 ` [PATCH 11/23] cache: pass cache pointer to callbacks Darrick J. Wong
2025-11-06 22:46 ` [PATCH 12/23] cache: pass a private data pointer through cache_walk Darrick J. Wong
2025-11-06 22:46 ` [PATCH 13/23] cache: add a helper to grab a new refcount for a cache_node Darrick J. Wong
2025-11-06 22:46 ` [PATCH 14/23] cache: return results of a cache flush Darrick J. Wong
2025-11-06 22:47 ` [PATCH 15/23] cache: add a "get only if incore" flag to cache_node_get Darrick J. Wong
2025-11-06 22:47 ` [PATCH 16/23] cache: support gradual expansion Darrick J. Wong
2025-11-06 22:47 ` [PATCH 17/23] cache: support updating maxcount and flags Darrick J. Wong
2025-11-06 22:47 ` [PATCH 18/23] cache: support channging flags Darrick J. Wong
2025-11-06 22:48 ` [PATCH 19/23] cache: implement automatic shrinking Darrick J. Wong
2025-11-06 22:48 ` [PATCH 20/23] fuse4fs: add cache to track open files Darrick J. Wong
2025-11-06 22:48 ` [PATCH 21/23] fuse4fs: use the orphaned inode list Darrick J. Wong
2025-11-06 22:48 ` [PATCH 22/23] fuse4fs: implement FUSE_TMPFILE Darrick J. Wong
2025-11-06 22:49 ` [PATCH 23/23] fuse4fs: create incore reverse orphan list Darrick J. Wong
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=176246793936.2862242.4057006934868513614.stgit@frogsfrogsfrogs \
--to=djwong@kernel.org \
--cc=linux-ext4@vger.kernel.org \
--cc=tytso@mit.edu \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox