From: Leo Stone <leocstone@gmail.com>
To: syzbot+b01a36acd7007e273a83@syzkaller.appspotmail.com,
jaegeuk@kernel.org, chao@kernel.org
Cc: Leo Stone <leocstone@gmail.com>,
linux-f2fs-devel@lists.sourceforge.net,
linux-kernel@vger.kernel.org, shuah@kernel.org,
anupnewsmail@gmail.com,
linux-kernel-mentees@lists.linuxfoundation.org
Subject: [PATCH] f2fs: Add check for deleted inode
Date: Sat, 23 Nov 2024 17:04:56 -0800 [thread overview]
Message-ID: <20241124010459.23283-1-leocstone@gmail.com> (raw)
In-Reply-To: 6740a00c.050a0220.363a1b.0143.GAE@google.com
The syzbot reproducer mounts a f2fs image, then tries to unlink an
existing file. However, the unlinked file already has a link count of 0
when it is read for the first time in do_read_inode().
Add a check to sanity_check_inode() for i_nlink == 0.
#syz test
Reported-by: syzbot+b01a36acd7007e273a83@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=b01a36acd7007e273a83
Fixes: 4c8ff7095bef ("f2fs: support data compression")
Signed-off-by: Leo Stone <leocstone@gmail.com>
---
fs/f2fs/inode.c | 6 ++++++
1 file changed, 6 insertions(+)
diff --git a/fs/f2fs/inode.c b/fs/f2fs/inode.c
index 1ed86df343a5..65f1dc32f173 100644
--- a/fs/f2fs/inode.c
+++ b/fs/f2fs/inode.c
@@ -372,6 +372,12 @@ static bool sanity_check_inode(struct inode *inode, struct page *node_page)
return false;
}
+ if (inode->i_nlink == 0) {
+ f2fs_warn(sbi, "%s: inode (ino=%lx) has a link count of 0",
+ __func__, inode->i_ino);
+ return false;
+ }
+
return true;
}
--
2.43.0
next reply other threads:[~2024-11-24 1:05 UTC|newest]
Thread overview: 5+ messages / expand[flat|nested] mbox.gz Atom feed top
2024-11-24 1:04 Leo Stone [this message]
2024-11-24 1:40 ` [syzbot] [f2fs?] WARNING in f2fs_unlink syzbot
2024-11-25 11:16 ` [PATCH] f2fs: Add check for deleted inode Chao Yu
2024-11-25 17:56 ` Leo Stone
2024-11-29 2:01 ` Chao Yu
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20241124010459.23283-1-leocstone@gmail.com \
--to=leocstone@gmail.com \
--cc=anupnewsmail@gmail.com \
--cc=chao@kernel.org \
--cc=jaegeuk@kernel.org \
--cc=linux-f2fs-devel@lists.sourceforge.net \
--cc=linux-kernel-mentees@lists.linuxfoundation.org \
--cc=linux-kernel@vger.kernel.org \
--cc=shuah@kernel.org \
--cc=syzbot+b01a36acd7007e273a83@syzkaller.appspotmail.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox