* [PATCH] bfs: Fix sanity checks for empty files
@ 2014-01-15 17:35 Rakesh Pandit
0 siblings, 0 replies; 3+ messages in thread
From: Rakesh Pandit @ 2014-01-15 17:35 UTC (permalink / raw)
To: tigran; +Cc: linux-kernel, linux-fsdevel
Mount fails if file system image has empty files because of sanity
check while reading superblock. For empty files disk offset to end of
file (i_eoffset) is cpu_to_le32(-1). Sanity check comparison, which
compares disk offset with file system size isn't valid for this value
and hence is ignored with this patch.
Steps to reproduce:
$ dd if=/dev/zero of=bfs-image count=204800
$ mkfs.bfs bfs-image
$ mkdir bfs-mount-point
$ sudo mount -t bfs -o loop bfs-image bfs-mount-point/
$ cd bfs-mount-point/
$ sudo touch a
$ cd ..
$ sudo umount bfs-mount-point/
$ sudo mount -t bfs -o loop bfs-image bfs-mount-point/
mount: /dev/loop0: can't read superblock
$ dmesg
[25526.689580] BFS-fs: bfs_fill_super(): Inode 0x00000003 corrupted
Signed-off-by: Rakesh Pandit <rakesh@tuxera.com>
---
fs/bfs/inode.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/fs/bfs/inode.c b/fs/bfs/inode.c
index 8defc6b..d69c464 100644
--- a/fs/bfs/inode.c
+++ b/fs/bfs/inode.c
@@ -420,7 +420,7 @@ static int bfs_fill_super(struct super_block *s, void *data, int silent)
if (i_sblock > info->si_blocks ||
i_eblock > info->si_blocks ||
i_sblock > i_eblock ||
- i_eoff > s_size ||
+ (i_eoff != le32_to_cpu(-1) && i_eoff > s_size) ||
i_sblock * BFS_BSIZE > i_eoff) {
printf("Inode 0x%08x corrupted\n", i);
--
1.7.11.7
^ permalink raw reply related [flat|nested] 3+ messages in thread* [PATCH] bfs: Fix sanity checks for empty files
@ 2017-05-05 20:16 Rakesh Pandit
2017-05-09 20:29 ` Tigran Aivazian
0 siblings, 1 reply; 3+ messages in thread
From: Rakesh Pandit @ 2017-05-05 20:16 UTC (permalink / raw)
To: Andrew Morton; +Cc: Tigran A. Aivazian, linux-kernel
Mount fails if file system image has empty files because of sanity
check while reading superblock. For empty files disk offset to end of
file (i_eoffset) is cpu_to_le32(-1). Sanity check comparison, which
compares disk offset with file system size isn't valid for this value
and hence is ignored with this patch.
Steps to reproduce:
$ dd if=/dev/zero of=bfs-image count=204800
$ mkfs.bfs bfs-image
$ mkdir bfs-mount-point
$ sudo mount -t bfs -o loop bfs-image bfs-mount-point/
$ cd bfs-mount-point/
$ sudo touch a
$ cd ..
$ sudo umount bfs-mount-point/
$ sudo mount -t bfs -o loop bfs-image bfs-mount-point/
mount: /dev/loop0: can't read superblock
$ dmesg
[25526.689580] BFS-fs: bfs_fill_super(): Inode 0x00000003 corrupted
Signed-off-by: Rakesh Pandit <rakesh@tuxera.com>
---
This was sent three years but maintainer has been unresponsive:
https://marc.info/?l=linux-kernel&m=138980764525250
So sending you Andrew as previous patches to bfs have gone through
your tree. This is tested and reproducible.
fs/bfs/inode.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/fs/bfs/inode.c b/fs/bfs/inode.c
index f2deec0..0d3dc18 100644
--- a/fs/bfs/inode.c
+++ b/fs/bfs/inode.c
@@ -419,7 +419,7 @@ static int bfs_fill_super(struct super_block *s, void *data, int silent)
if (i_sblock > info->si_blocks ||
i_eblock > info->si_blocks ||
i_sblock > i_eblock ||
- i_eoff > s_size ||
+ (i_eoff != le32_to_cpu(-1) && i_eoff > s_size) ||
i_sblock * BFS_BSIZE > i_eoff) {
printf("Inode 0x%08x corrupted\n", i);
--
2.9.3
^ permalink raw reply related [flat|nested] 3+ messages in thread* Re: [PATCH] bfs: Fix sanity checks for empty files
2017-05-05 20:16 Rakesh Pandit
@ 2017-05-09 20:29 ` Tigran Aivazian
0 siblings, 0 replies; 3+ messages in thread
From: Tigran Aivazian @ 2017-05-09 20:29 UTC (permalink / raw)
To: Rakesh Pandit; +Cc: Andrew Morton, LKML
Hi,
If you had created the filesystem with the proper mkfs under SCO
UnixWare 7 you (probably) wouldn't encounter this issue. But since
commercial Unix-es are now part of history and the only proper way is
the Linux mkfs.bfs utility, your patch is fine.
Kind regards,
Tigran
On 5 May 2017 at 21:16, Rakesh Pandit <rakesh@tuxera.com> wrote:
> Mount fails if file system image has empty files because of sanity
> check while reading superblock. For empty files disk offset to end of
> file (i_eoffset) is cpu_to_le32(-1). Sanity check comparison, which
> compares disk offset with file system size isn't valid for this value
> and hence is ignored with this patch.
>
> Steps to reproduce:
>
> $ dd if=/dev/zero of=bfs-image count=204800
> $ mkfs.bfs bfs-image
> $ mkdir bfs-mount-point
> $ sudo mount -t bfs -o loop bfs-image bfs-mount-point/
> $ cd bfs-mount-point/
> $ sudo touch a
> $ cd ..
> $ sudo umount bfs-mount-point/
> $ sudo mount -t bfs -o loop bfs-image bfs-mount-point/
> mount: /dev/loop0: can't read superblock
>
> $ dmesg
> [25526.689580] BFS-fs: bfs_fill_super(): Inode 0x00000003 corrupted
>
> Signed-off-by: Rakesh Pandit <rakesh@tuxera.com>
> ---
>
> This was sent three years but maintainer has been unresponsive:
> https://marc.info/?l=linux-kernel&m=138980764525250
>
> So sending you Andrew as previous patches to bfs have gone through
> your tree. This is tested and reproducible.
>
> fs/bfs/inode.c | 2 +-
> 1 file changed, 1 insertion(+), 1 deletion(-)
>
> diff --git a/fs/bfs/inode.c b/fs/bfs/inode.c
> index f2deec0..0d3dc18 100644
> --- a/fs/bfs/inode.c
> +++ b/fs/bfs/inode.c
> @@ -419,7 +419,7 @@ static int bfs_fill_super(struct super_block *s, void *data, int silent)
> if (i_sblock > info->si_blocks ||
> i_eblock > info->si_blocks ||
> i_sblock > i_eblock ||
> - i_eoff > s_size ||
> + (i_eoff != le32_to_cpu(-1) && i_eoff > s_size) ||
> i_sblock * BFS_BSIZE > i_eoff) {
>
> printf("Inode 0x%08x corrupted\n", i);
> --
> 2.9.3
>
^ permalink raw reply [flat|nested] 3+ messages in thread
end of thread, other threads:[~2017-05-09 20:29 UTC | newest]
Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2014-01-15 17:35 [PATCH] bfs: Fix sanity checks for empty files Rakesh Pandit
-- strict thread matches above, loose matches on Subject: below --
2017-05-05 20:16 Rakesh Pandit
2017-05-09 20:29 ` Tigran Aivazian
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox