From: "Darrick J. Wong" <djwong@kernel.org>
To: Aldo Ariel Panzardo <qwe.aldo@gmail.com>
Cc: linux-xfs@vger.kernel.org, Carlos Maiolino <cem@kernel.org>,
Dave Chinner <dchinner@redhat.com>,
linux-kernel@vger.kernel.org
Subject: Re: [PATCH] xfs: bound da-node entry count against the correct geometry
Date: Tue, 7 Jul 2026 09:29:38 -0700 [thread overview]
Message-ID: <20260707162938.GZ9392@frogsfrogsfrogs> (raw)
In-Reply-To: <20260707135930.3214701-1-qwe.aldo@gmail.com>
On Tue, Jul 07, 2026 at 10:59:30AM -0300, Aldo Ariel Panzardo wrote:
> xfs_da3_node_verify() bounds the node entry count against the larger of
> the directory and attribute geometries because it does not know which
> tree the block belongs to. When the directory block size exceeds the fs
> block size (e.g. mkfs.xfs -n size=64k -b size=4k), the attribute node
> buffer is a single fs block holding only m_attr_geo->node_ents entries,
> but a crafted attr node may claim a count up to m_dir_geo->node_ents.
> xfs_da3_node_lookup_int() then reads btree[] entries past the buffer
> during its binary search -- an out-of-bounds read via getxattr/listxattr
> on a mounted crafted image.
>
> The node buffer size identifies its geometry, so bound the count against
> that geometry's node_ents rather than the maximum of the two.
>
> Fixes: 7ab610f9e0f1 ("xfs: move node entry counts to xfs_da_geometry")
> Signed-off-by: Aldo Ariel Panzardo <qwe.aldo@gmail.com>
> ---
> fs/xfs/libxfs/xfs_da_btree.c | 14 ++++++++++----
> 1 file changed, 10 insertions(+), 4 deletions(-)
>
> diff --git a/fs/xfs/libxfs/xfs_da_btree.c b/fs/xfs/libxfs/xfs_da_btree.c
> index 9debb95d86fa..897c31147a46 100644
> --- a/fs/xfs/libxfs/xfs_da_btree.c
> +++ b/fs/xfs/libxfs/xfs_da_btree.c
> @@ -240,12 +240,18 @@ xfs_da3_node_verify(
> return __this_address;
>
> /*
> - * we don't know if the node is for and attribute or directory tree,
> - * so only fail if the count is outside both bounds
> + * The block was read using either the attribute or the directory
> + * geometry; its buffer size tells us which one, so bound the entry
> + * count against that geometry's node_ents. Only failing when the
> + * count exceeds max(dir, attr) let a crafted attr node claim a
> + * dir-sized count and overrun the smaller attr buffer.
> */
> - if (ichdr.count > mp->m_dir_geo->node_ents &&
> - ichdr.count > mp->m_attr_geo->node_ents)
> + if (BBTOB(bp->b_length) == mp->m_attr_geo->blksize) {
No. That's not how we determine if the caller is trying to read a
directory or an xattr block.
--D
> + if (ichdr.count > mp->m_attr_geo->node_ents)
> + return __this_address;
> + } else if (ichdr.count > mp->m_dir_geo->node_ents) {
> return __this_address;
> + }
>
> /* XXX: hash order check? */
>
> --
> 2.43.0
>
>
next prev parent reply other threads:[~2026-07-07 16:29 UTC|newest]
Thread overview: 4+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-07-07 13:59 [PATCH] xfs: bound da-node entry count against the correct geometry Aldo Ariel Panzardo
2026-07-07 16:29 ` Darrick J. Wong [this message]
2026-07-07 19:02 ` [PATCH v2] " Aldo Ariel Panzardo
2026-07-08 15:16 ` Carlos Maiolino
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260707162938.GZ9392@frogsfrogsfrogs \
--to=djwong@kernel.org \
--cc=cem@kernel.org \
--cc=dchinner@redhat.com \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-xfs@vger.kernel.org \
--cc=qwe.aldo@gmail.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox