* [PATCH v4 0/2] ext4: Convert group-count barrier protocol to acquire/release
@ 2026-09-04 7:32 Jinjie Ruan
2026-09-04 7:32 ` [PATCH v4 1/2] ext4: Fix out-of-bounds read in ext4_get_group_info() Jinjie Ruan
2026-09-04 7:32 ` [PATCH v4 2/2] ext4: Convert group-count barrier protocol to acquire/release Jinjie Ruan
0 siblings, 2 replies; 5+ messages in thread
From: Jinjie Ruan @ 2026-09-04 7:32 UTC (permalink / raw)
To: tytso, adilger.kernel, libaokun, jack, ojaswin, ritesh.list,
yi.zhang, linux-ext4, linux-kernel
Cc: ruanjinjie
Hi all,
This series fix out-of-bounds read in ext4_get_group_info() and
convert the ext4 group-count barrier protocol to acquire/release.
Changes in v4:
- Split ext4 patches out as Theodore suggested.
- Link to v3: https://lore.kernel.org/all/20260902074805.398540-1-ruanjinjie@huawei.com/
Jinjie Ruan (2):
ext4: Fix out-of-bounds read in ext4_get_group_info()
ext4: Convert group-count barrier protocol to acquire/release
fs/ext4/balloc.c | 2 +-
fs/ext4/ext4.h | 10 +++-------
fs/ext4/mballoc.c | 6 ++----
fs/ext4/resize.c | 19 +++++++++++--------
4 files changed, 17 insertions(+), 20 deletions(-)
--
2.34.1
^ permalink raw reply [flat|nested] 5+ messages in thread
* [PATCH v4 1/2] ext4: Fix out-of-bounds read in ext4_get_group_info()
2026-09-04 7:32 [PATCH v4 0/2] ext4: Convert group-count barrier protocol to acquire/release Jinjie Ruan
@ 2026-09-04 7:32 ` Jinjie Ruan
2026-09-04 7:47 ` sashiko-bot
2026-09-04 7:32 ` [PATCH v4 2/2] ext4: Convert group-count barrier protocol to acquire/release Jinjie Ruan
1 sibling, 1 reply; 5+ messages in thread
From: Jinjie Ruan @ 2026-09-04 7:32 UTC (permalink / raw)
To: tytso, adilger.kernel, libaokun, jack, ojaswin, ritesh.list,
yi.zhang, linux-ext4, linux-kernel
Cc: ruanjinjie
A plain read of s_groups_count in ext4_get_group_info() allows CPU
load-load reordering. On weak memory models, speculative prefetch of
s_group_info prior to the boundary check could lead to an out-of-bounds
read if a concurrent online resize expands the array and increments
s_groups_count.
The data race occurs between the ioctl configuration path (holding the
resize lock via ext4_resize_begin) and the lockless metadata lookup path:
CPU 0 (Writer, Resize Lock) CPU 1 (Reader, Lockless)
--------------------------- ------------------------
ext4_ioctl()
[EXT4_IOC_GROUP_ADD]
ext4_ioctl_group_add()
ext4_resize_begin() // Takes lock
ext4_group_add()
ext4_mb_alloc_groupinfo()
// Publishes expanded array via RCU
rcu_assign_pointer(s_group_info, ...)
ext4_flex_group_add()
ext4_update_super()
ext4_get_group_info()
// Speculative / out-of-order read
[Loads old/smaller s_group_info pointer]
[Plain C store / smp_wmb()]
sbi->s_groups_count += ...;
// Reads new s_groups_count,
// boundary check passes
if (group >= s_groups_count)
// Out-of-bounds array access!
sbi_array_rcu_deref(..., s_group_info)
Fix this by using ext4_get_groups_count() to enforce acquire semantics.
Cc: stable@vger.kernel.org
Fixes: 5354b2af3406 ("ext4: allow ext4_get_group_info() to fail")
Link: https://sashiko.dev/#/patchset/20260825095422.3166067-1-ruanjinjie%40huawei.com
Reviewed-by: Zhang Yi <yi.zhang@huawei.com>
Reviewed-by: Jan Kara <jack@suse.cz>
Signed-off-by: Jinjie Ruan <ruanjinjie@huawei.com>
---
Cc: Theodore Ts'o <tytso@mit.edu>
Cc: Andreas Dilger <adilger.kernel@dilger.ca>
Cc: Baokun Li <libaokun@linux.alibaba.com>
Cc: Jan Kara <jack@suse.cz>
Cc: Ojaswin Mujoo <ojaswin@linux.ibm.com>
Cc: Ritesh Harjani (IBM) <ritesh.list@gmail.com>
Cc: Zhang Yi <yi.zhang@huawei.com>
---
fs/ext4/balloc.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/fs/ext4/balloc.c b/fs/ext4/balloc.c
index 52f4c5169f91..778fe8788f06 100644
--- a/fs/ext4/balloc.c
+++ b/fs/ext4/balloc.c
@@ -329,7 +329,7 @@ struct ext4_group_info *ext4_get_group_info(struct super_block *sb,
struct ext4_group_info **grp_info;
long indexv, indexh;
- if (unlikely(group >= EXT4_SB(sb)->s_groups_count))
+ if (unlikely(group >= ext4_get_groups_count(sb)))
return NULL;
if (unlikely(!EXT4_SB(sb)->s_group_info))
return NULL;
--
2.34.1
^ permalink raw reply related [flat|nested] 5+ messages in thread
* [PATCH v4 2/2] ext4: Convert group-count barrier protocol to acquire/release
2026-09-04 7:32 [PATCH v4 0/2] ext4: Convert group-count barrier protocol to acquire/release Jinjie Ruan
2026-09-04 7:32 ` [PATCH v4 1/2] ext4: Fix out-of-bounds read in ext4_get_group_info() Jinjie Ruan
@ 2026-09-04 7:32 ` Jinjie Ruan
2026-09-04 7:40 ` sashiko-bot
1 sibling, 1 reply; 5+ messages in thread
From: Jinjie Ruan @ 2026-09-04 7:32 UTC (permalink / raw)
To: tytso, adilger.kernel, libaokun, jack, ojaswin, ritesh.list,
yi.zhang, linux-ext4, linux-kernel
Cc: ruanjinjie
During an online resize, reading s_groups_count and s_blockfile_groups
requires strict ordering against subsequent initialized block group
metadata.
Replace the historical smp_wmb()/smp_rmb() pairs with smp_store_release()
and smp_load_acquire(). This formalizes the publish-subscribe pattern
and allows weakly-ordered architectures (e.g., arm64) to utilize native
STLR/LDAR instructions instead of full DMB fences.
Update the documentation in resize.c and ext4.h accordingly.
Assisted-by: Gemini:Gemini-3.1
Assisted-by: DeepSeek:DeepSeek-V3
Reviewed-by: Zhang Yi <yi.zhang@huawei.com>
Reviewed-by: Jan Kara <jack@suse.cz>
Signed-off-by: Jinjie Ruan <ruanjinjie@huawei.com>
---
Cc: Theodore Ts'o <tytso@mit.edu>
Cc: Andreas Dilger <adilger.kernel@dilger.ca>
Cc: Baokun Li <libaokun@linux.alibaba.com>
Cc: Jan Kara <jack@suse.cz>
Cc: Ojaswin Mujoo <ojaswin@linux.ibm.com>
Cc: Ritesh Harjani (IBM) <ritesh.list@gmail.com>
Cc: Zhang Yi <yi.zhang@huawei.com>
---
fs/ext4/ext4.h | 10 +++-------
fs/ext4/mballoc.c | 6 ++----
fs/ext4/resize.c | 19 +++++++++++--------
3 files changed, 16 insertions(+), 19 deletions(-)
diff --git a/fs/ext4/ext4.h b/fs/ext4/ext4.h
index 724a27e8be61..d70b9cb09155 100644
--- a/fs/ext4/ext4.h
+++ b/fs/ext4/ext4.h
@@ -3542,16 +3542,12 @@ static inline void ext4_isize_set(struct ext4_inode *raw_inode, loff_t i_size)
}
/*
- * Reading s_groups_count requires using smp_rmb() afterwards. See
- * the locking protocol documented in the comments of ext4_group_add()
- * in resize.c
+ * Reading s_groups_count uses acquire semantics.
*/
static inline ext4_group_t ext4_get_groups_count(struct super_block *sb)
{
- ext4_group_t ngroups = EXT4_SB(sb)->s_groups_count;
-
- smp_rmb();
- return ngroups;
+ /* Pairs with smp_store_release() in ext4_update_super() */
+ return smp_load_acquire(&EXT4_SB(sb)->s_groups_count);
}
static inline ext4_group_t ext4_flex_group(struct ext4_sb_info *sbi,
diff --git a/fs/ext4/mballoc.c b/fs/ext4/mballoc.c
index 06171a11db12..a15285224cdf 100644
--- a/fs/ext4/mballoc.c
+++ b/fs/ext4/mballoc.c
@@ -899,10 +899,8 @@ static ext4_group_t ext4_get_allocation_groups_count(
/* non-extent files are limited to low blocks/groups */
if (!(ext4_test_inode_flag(ac->ac_inode, EXT4_INODE_EXTENTS)))
- ngroups = EXT4_SB(ac->ac_sb)->s_blockfile_groups;
-
- /* Pairs with smp_wmb() in ext4_update_super() */
- smp_rmb();
+ /* Pairs with smp_store_release() in ext4_update_super() */
+ ngroups = smp_load_acquire(&EXT4_SB(ac->ac_sb)->s_blockfile_groups);
return ngroups;
}
diff --git a/fs/ext4/resize.c b/fs/ext4/resize.c
index 2c5b851c552a..5e3ad8393cf8 100644
--- a/fs/ext4/resize.c
+++ b/fs/ext4/resize.c
@@ -1462,11 +1462,11 @@ static void ext4_update_super(struct super_block *sb,
*
* The precise rules we use are:
*
- * * Writers must perform a smp_wmb() after updating all
- * dependent data and before modifying the groups count
+ * * Writers must use a release store when updating the groups count
+ * after all dependent data has been updated
*
- * * Readers must perform an smp_rmb() after reading the groups
- * count and before reading any dependent data.
+ * * Readers must use an acquire load when reading the groups
+ * count before reading any dependent data.
*
* NB. These rules can be relaxed when checking the group count
* while freeing data, as we can only allocate from a block
@@ -1474,12 +1474,15 @@ static void ext4_update_super(struct super_block *sb,
* only then free after serialising in turn against that
* allocation.
*/
- smp_wmb();
/* Update the global fs size fields */
- sbi->s_groups_count += flex_gd->count;
- sbi->s_blockfile_groups = min(sbi->s_groups_count,
- (EXT4_MAX_BLOCK_FILE_PHYS / EXT4_BLOCKS_PER_GROUP(sb)));
+ /* Pairs with smp_load_acquire() in ext4_get_groups_count() */
+ smp_store_release(&sbi->s_groups_count,
+ sbi->s_groups_count + flex_gd->count);
+ /* Pairs with smp_load_acquire() in ext4_get_allocation_groups_count() */
+ smp_store_release(&sbi->s_blockfile_groups,
+ min(sbi->s_groups_count,
+ (EXT4_MAX_BLOCK_FILE_PHYS / EXT4_BLOCKS_PER_GROUP(sb))));
/* Update the reserved block counts only once the new group is
* active. */
--
2.34.1
^ permalink raw reply related [flat|nested] 5+ messages in thread
* Re: [PATCH v4 2/2] ext4: Convert group-count barrier protocol to acquire/release
2026-09-04 7:32 ` [PATCH v4 2/2] ext4: Convert group-count barrier protocol to acquire/release Jinjie Ruan
@ 2026-09-04 7:40 ` sashiko-bot
0 siblings, 0 replies; 5+ messages in thread
From: sashiko-bot @ 2026-09-04 7:40 UTC (permalink / raw)
To: Jinjie Ruan; +Cc: tytso, linux-ext4
> During an online resize, reading s_groups_count and s_blockfile_groups
> requires strict ordering against subsequent initialized block group
> metadata.
>
> Replace the historical smp_wmb()/smp_rmb() pairs with smp_store_release()
> and smp_load_acquire(). This formalizes the publish-subscribe pattern
> and allows weakly-ordered architectures (e.g., arm64) to utilize native
> STLR/LDAR instructions instead of full DMB fences.
>
> Update the documentation in resize.c and ext4.h accordingly.
>
> Assisted-by: Gemini:Gemini-3.1
> Assisted-by: DeepSeek:DeepSeek-V3
> Reviewed-by: Zhang Yi <yi.zhang@huawei.com>
> Reviewed-by: Jan Kara <jack@suse.cz>
> Signed-off-by: Jinjie Ruan <ruanjinjie@huawei.com>
Sashiko has reviewed this patch and found no issues. It looks great!
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260904073253.663243-1-ruanjinjie@huawei.com?part=2
^ permalink raw reply [flat|nested] 5+ messages in thread
* Re: [PATCH v4 1/2] ext4: Fix out-of-bounds read in ext4_get_group_info()
2026-09-04 7:32 ` [PATCH v4 1/2] ext4: Fix out-of-bounds read in ext4_get_group_info() Jinjie Ruan
@ 2026-09-04 7:47 ` sashiko-bot
0 siblings, 0 replies; 5+ messages in thread
From: sashiko-bot @ 2026-09-04 7:47 UTC (permalink / raw)
To: Jinjie Ruan; +Cc: tytso, linux-ext4
> A plain read of s_groups_count in ext4_get_group_info() allows CPU
> load-load reordering. On weak memory models, speculative prefetch of
> s_group_info prior to the boundary check could lead to an out-of-bounds
> read if a concurrent online resize expands the array and increments
> s_groups_count.
>
> The data race occurs between the ioctl configuration path (holding the
> resize lock via ext4_resize_begin) and the lockless metadata lookup path:
>
> CPU 0 (Writer, Resize Lock) CPU 1 (Reader, Lockless)
> --------------------------- ------------------------
> ext4_ioctl()
> [EXT4_IOC_GROUP_ADD]
> ext4_ioctl_group_add()
> ext4_resize_begin() // Takes lock
> [ ... ]
> Fixes: 5354b2af3406 ("ext4: allow ext4_get_group_info() to fail")
> Link: https://sashiko.dev/#/patchset/20260825095422.3166067-1-ruanjinjie%40huawei.com
> Reviewed-by: Zhang Yi <yi.zhang@huawei.com>
> Reviewed-by: Jan Kara <jack@suse.cz>
> Signed-off-by: Jinjie Ruan <ruanjinjie@huawei.com>
Sashiko has reviewed this patch and found no issues. It looks great!
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260904073253.663243-1-ruanjinjie@huawei.com?part=1
^ permalink raw reply [flat|nested] 5+ messages in thread
end of thread, other threads:[~2026-09-04 7:48 UTC | newest]
Thread overview: 5+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-04 7:32 [PATCH v4 0/2] ext4: Convert group-count barrier protocol to acquire/release Jinjie Ruan
2026-09-04 7:32 ` [PATCH v4 1/2] ext4: Fix out-of-bounds read in ext4_get_group_info() Jinjie Ruan
2026-09-04 7:47 ` sashiko-bot
2026-09-04 7:32 ` [PATCH v4 2/2] ext4: Convert group-count barrier protocol to acquire/release Jinjie Ruan
2026-09-04 7:40 ` sashiko-bot
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox