From: "Darrick J. Wong" <darrick.wong@oracle.com>
To: "Theodore Ts'o" <tytso@mit.edu>
Cc: linux-ext4@vger.kernel.org
Subject: Re: [PATCH 05/25] libext2fs: don't overflow when punching indirect blocks with large blocks
Date: Tue, 3 Dec 2013 20:40:27 -0800 [thread overview]
Message-ID: <20131204044027.GN9535@birch.djwong.org> (raw)
In-Reply-To: <20131024000834.GE31400@thunk.org>
On Wed, Oct 23, 2013 at 08:08:34PM -0400, Theodore Ts'o wrote:
> On Thu, Oct 17, 2013 at 09:49:28PM -0700, Darrick J. Wong wrote:
> > On a FS with a rather large blockize (> 4K), the old block map
> > structure can construct a fat enough "tree" (or whatever we call that
> > lopsided thing) that (at least in theory) one could create mappings
> > for logical blocks higher than 32 bits. In practice this doesn't
> > happen, but the 'max' and 'iter' variables that the punch helpers use
> > will overflow because the BLOCK_SIZE_BITS shifts are too large to fit
> > a 32-bit variable. This causes punch to fail on TIND-mapped blocks
> > even if the file is < 16T. So enlarge the fields to fit.
>
> Hmm.... this brings up the question of whether we should support
> inodes that have indirect block maps that result in mappings for
> logical blocks > 32-bits. There is probably a lot of code that
> assumes that the logical block number is 32-bits that will break
> horribly.
I'm not sure. The way I noticed this brokeness was by creating a FS with 64k
blocks, sparse-writing a range of blocks at lblk 268451854 (to force it to
create a tind map) and then try to punch it. The file itself had a size of
just under 16T. e2fsck seemed fine with the file, and as you can see the lblk
number was nowhere close to 2^32.
I think the problem is that the punch code is using two variables max and incr
as upper limits on how many blocks it should try to punch for a given level.
Since the variables aren't wide enough, they overflow (effectively becoming
zero) and then things like (offset + incr(0) <= start) become true and so it
quits early.
---
If I use fuse2fs to create a non-extent file that exceeds 2^32 blocks (and
blocksize > 4k), fsck doesn't complain.
If the blocksize is 4k or less, the kernel refuses to write the file, but
fuse2fs creates a garbled filesystem (with enormous i_size but no blocks
mapped) and fsck complains. Hmm, I'll look into that.
--D
>
> So things brings up a couple of different questions.
>
> #1) Does e2fsck notice, and does it complain if it trips against one
> of these.
>
> #2) What should e2fsprogs do when it comes across one of these inodes.
> It may be that simply returning an error is enough, once we notice
> that it hsa blocks larger than this. Would it be cleaner and more
> efficient for the punch code to simply make sure that it stops before
> the logical block number overflows? 64-bit variables have a cost,
> especially on 32-bit machines.
>
> - Ted
> --
> To unsubscribe from this list: send the line "unsubscribe linux-ext4" in
> the body of a message to majordomo@vger.kernel.org
> More majordomo info at http://vger.kernel.org/majordomo-info.html
next prev parent reply other threads:[~2013-12-04 4:40 UTC|newest]
Thread overview: 73+ messages / expand[flat|nested] mbox.gz Atom feed top
2013-10-18 4:48 [PATCH v2 00/25] e2fsprogs patchbomb 10/2013 Darrick J. Wong
2013-10-18 4:49 ` [PATCH 01/25] libext2fs: stop iterating dirents when done linking Darrick J. Wong
2013-10-23 23:39 ` Theodore Ts'o
2013-10-18 4:49 ` [PATCH 02/25] libext2fs: fix ext2fs_open2() truncation of the superblock parameter Darrick J. Wong
2013-10-18 18:32 ` Darrick J. Wong
2013-10-23 14:49 ` Lukáš Czerner
2013-10-18 4:49 ` [PATCH 03/25] mke2fs: don't let resize= turn on resize_inode when meta_bg is set Darrick J. Wong
2013-10-23 15:08 ` Lukáš Czerner
2013-10-23 23:40 ` Theodore Ts'o
2013-10-18 4:49 ` [PATCH 04/25] libext2fs: reject 64bit badblocks numbers Darrick J. Wong
2013-10-23 15:24 ` Lukáš Czerner
2013-10-23 23:58 ` Theodore Ts'o
2013-10-24 11:40 ` Lukáš Czerner
2013-10-18 4:49 ` [PATCH 05/25] libext2fs: don't overflow when punching indirect blocks with large blocks Darrick J. Wong
2013-10-24 0:08 ` Theodore Ts'o
2013-12-04 4:40 ` Darrick J. Wong [this message]
2013-10-18 4:49 ` [PATCH 06/25] libext2fs: fix tests that set LARGE_FILE Darrick J. Wong
2013-11-25 7:09 ` Zheng Liu
2013-11-25 17:57 ` Darrick J. Wong
2013-10-18 4:49 ` [PATCH 07/25] mke2fs: load configfile blocksize setting before 64bit checks Darrick J. Wong
2013-11-25 8:01 ` Zheng Liu
2013-10-18 4:49 ` [PATCH 08/25] debugfs: fix various minor bogosity Darrick J. Wong
2013-11-25 8:08 ` Zheng Liu
2013-11-25 18:05 ` Darrick J. Wong
2013-10-18 4:49 ` [PATCH 09/25] e2fsck: teach EA refcounting code to handle 64bit block addresses Darrick J. Wong
2013-10-18 18:37 ` Darrick J. Wong
2013-11-25 8:18 ` Zheng Liu
2013-10-18 4:50 ` [PATCH 10/25] debugfs: handle 64bit block numbers Darrick J. Wong
2013-10-18 18:47 ` Darrick J. Wong
2013-11-25 8:33 ` Zheng Liu
2013-11-25 17:49 ` Darrick J. Wong
2013-10-18 4:50 ` [PATCH 11/25] libext2fs: only punch complete clusters Darrick J. Wong
2013-10-18 18:55 ` Darrick J. Wong
2013-11-25 8:51 ` Zheng Liu
2013-10-18 4:50 ` [PATCH 12/25] libext2fs: don't update the summary counts when doing implied cluster allocation Darrick J. Wong
2013-11-25 9:03 ` Zheng Liu
2013-10-18 4:50 ` [PATCH 13/25] libext2fs: use ext2fs_punch() to truncate quota file Darrick J. Wong
2013-11-25 9:08 ` Zheng Liu
2013-10-18 4:50 ` [PATCH 14/25] e2fsck: only release clusters when shortening a directory during a rehash Darrick J. Wong
2013-11-25 11:09 ` Zheng Liu
2013-10-18 4:50 ` [PATCH 15/25] e2fsck: print cluster ranges when encountering bitmap errors Darrick J. Wong
2013-11-25 11:56 ` Zheng Liu
2013-10-18 4:50 ` [PATCH 16/25] resize2fs: convert fs to and from 64bit mode Darrick J. Wong
2013-10-18 18:59 ` Darrick J. Wong
2013-11-26 6:44 ` Zheng Liu
2013-11-26 18:39 ` Darrick J. Wong
2013-11-27 2:21 ` Zheng Liu
2013-10-18 4:50 ` [PATCH 17/25] resize2fs: when toggling 64bit, don't free in-use bg data clusters Darrick J. Wong
2013-10-18 4:50 ` [PATCH 18/25] resize2fs: adjust reserved_gdt_blocks when changing group descriptor size Darrick J. Wong
2013-10-18 4:51 ` [PATCH 19/25] resize2fs: during shrink, don't free in-use bg data clusters Darrick J. Wong
2013-10-18 4:51 ` [PATCH 20/25] resize2fs: don't free in-use clusters when moving blocks Darrick J. Wong
2013-10-18 4:51 ` [PATCH 21/25] misc: use the checksum predicate function, not raw flag tests Darrick J. Wong
2013-10-18 4:51 ` [PATCH 22/25] resize2fs: rewrite extent/dir/ea block checksums when migrating Darrick J. Wong
2013-10-18 4:51 ` [PATCH 23/25] libext2fs: support modifying arbitrary extended attributes Darrick J. Wong
2013-10-18 19:25 ` Darrick J. Wong
2013-10-22 1:13 ` Darrick J. Wong
2013-11-26 7:21 ` Zheng Liu
2013-11-26 19:55 ` Darrick J. Wong
2013-11-27 2:52 ` Zheng Liu
2013-11-27 3:13 ` Darrick J. Wong
2013-11-27 11:36 ` Zheng Liu
2013-11-27 1:56 ` Darrick J. Wong
2013-11-29 5:30 ` Zheng Liu
2013-11-29 8:17 ` Jan Kara
2013-11-30 20:24 ` Darrick J. Wong
2013-12-02 8:38 ` Jan Kara
2013-10-18 4:51 ` [PATCH 24/25] misc: add fuse2fs, a FUSE server for e2fsprogs Darrick J. Wong
2013-10-18 19:36 ` Darrick J. Wong
2013-10-22 1:20 ` Darrick J. Wong
2013-10-18 13:13 ` [PATCH v2 00/25] e2fsprogs patchbomb 10/2013 Lukáš Czerner
2013-10-18 18:13 ` Darrick J. Wong
2013-10-18 20:37 ` Darrick J. Wong
2013-10-18 18:39 ` Theodore Ts'o
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20131204044027.GN9535@birch.djwong.org \
--to=darrick.wong@oracle.com \
--cc=linux-ext4@vger.kernel.org \
--cc=tytso@mit.edu \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).