From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-pj1-f48.google.com (mail-pj1-f48.google.com [209.85.216.48]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id E412141A517 for ; Tue, 4 Aug 2026 06:45:23 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.216.48 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785825925; cv=none; b=jpk3rCohH9CbGn7Y6lJU/oA/ANLUboIAB3IrbvtYpgIX5mGxqeatGHY+ZDZED/rT59mYppS8xdJHgxj6e7bBYZjsAS70MSM6CTaW9pdH/vghB33V2TtO6GWBsiGFF3x6vwDWJyBGLsIVdqySC7pkKUslhNZvjp9wpDjh4KoYeE4= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785825925; c=relaxed/simple; bh=CP/QiDGE1eTcMdAzoQy/MuB8aGnZqOPRGI3EmSy9FvU=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=sbZXjkZoZAKTnypocwBo58S3X8huhMIVbv0xzz5rWiO0kTKDiohHvyuyQhEzzglhr5qJJ090clUFSLPcBAUwb33faRZeELMJ+gzwI3RgmzEA8CNxxtj9L3eVZypFbFKGqYFkk0haRjaWcWChjyrzoMMw865XYwiEXLMIfOmCOrc= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=Nn2Gp03d; arc=none smtp.client-ip=209.85.216.48 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="Nn2Gp03d" Received: by mail-pj1-f48.google.com with SMTP id 98e67ed59e1d1-38dd55ad76cso687407a91.1 for ; Mon, 03 Aug 2026 23:45:23 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1785825923; x=1786430723; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to:content-type; bh=AH3vppyjD/gVbDWLVTc33GyNBGQ7brJNCu8pjSkSL2g=; b=Nn2Gp03dRIdFZYAmGmLNauLDTszvsYrl3RQJsBDF3W00O9AaCdNiUYxX/LAzaKXScb Va5LpK9XQp06nqDXqxpdH8/vKMQW8sKMG7Abm+IZhuqug6Nri6+lOTJCA3RgCSuTB9sM woyUMT1vpq74irnyCUMMsgkU3VO4zhewPnP6AUoidbRY4Y94k7YAKBaVh4uMRvz7hTyH 3xCDkpxcbsGQF59t5qkGw/B9e3iQU60hR5S+4pzHhQ6Pg4MdkSi0pR2pJb8a5eJK6HYP ifepFau/WlHWmkmH/YT2M4NBBiQsfiPMtSbqZKyJCQOj+RfmHbItDsVvVL9aW7hNtJK5 geKA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785825923; x=1786430723; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=AH3vppyjD/gVbDWLVTc33GyNBGQ7brJNCu8pjSkSL2g=; b=G3OfzdZgX+j3tpN9nia9gdA7J+9L98+wn2U2nL2cs/xvUf3U2/RicfEOb0FVJqru/e vDkpBq0AAepmhrJlPKYJo3yIbTeLWHJhfFXWjclvwgkJ1Hb3oE7ijZGZSUyCMMCQDfMD MM3olcQ566t9vlanPA/AaQQR5TQByQ77uWjFlUvWx39m3LV05GeGrXVSEToaMGPBtrFu f6bPl9FHGJOlkSHERxvomFVzoQwvIW0Nu9JYN6CK8HRl2A/Ss00xSOpNG+dEt2wLK8LH OZIKAGfIq95/GTumy3SklNJIpCsxCJMAYrp/xJiE2XFRThyAizOjxgxU3zAC5tp4WpPp z/GQ== X-Forwarded-Encrypted: i=1; AHgh+RpT5tC160cNatxaLOgMF6AHMsG7I3JBQ0h6PuL0IbGSvo0KtMJhDQBZFtYywHrnlkKerJklrg1lv/xnvM4=@vger.kernel.org X-Gm-Message-State: AOJu0YwEyropV9tvih/5hN4INIo2aGtvAOkzecWNqGqs3bY3M4s7FJei KqQyitlaiCUa5TE/rY5BfDxNEW2Bu+jYjNYyOG3FJDAmpMiWTIRavn5S X-Gm-Gg: AR+sD130t0xNB/XLDln+9dX31B2+SvfYN129wCKraAHU9va9Sg0dlTOlBvltYfT0Wxi wbzQZuv4pK2QguEQD/MWlfAFvmdGIXq62votBbAMCpevBp/upd3JgNkfKaC+tp1HXkK6PGbeR3e u0rQrmNBJ2ucz8DWniij4m7RvZLfi8f1k9f1gFfO/1kSKm27bw9OpxrFRmcpAeclxH11M+zfRVR FGL3ZF02J3/wk6ABZyak5fiHBgW9bUJaqAFcsfzDWeKm+VHws2nNQ5BNXKAkKzVJttUJQxzIsdA bXoNxlbvR5gNSSPQ+hfAGfQ/55wmagc1U95jCYnlNpmrSjHP6xyTHwXhIlceza4TDe1jPh6hyTv TemfaiJcNfijHtF03vQr8fDuCMxbhESxU3qUrOOW34xllLIm1GalYCjrKZYVZkCVG0RyY52No8+ MldPlTuZnRKCT40Pr/FR2mWsSCJ1SEJoRgU9ShuWcyXf8sCR7iv+DIcsabf8xTdFA+vcHTYLDep sNWq3e81r7uo05WaGrIfJWOwt0p4A== X-Received: by 2002:a17:90b:3cc5:b0:37f:d265:18d2 with SMTP id 98e67ed59e1d1-38fec00df2emr1699403a91.7.1785825923109; Mon, 03 Aug 2026 23:45:23 -0700 (PDT) Received: from gmail.com ([138.199.21.246]) by smtp.gmail.com with ESMTPSA id 98e67ed59e1d1-38febfdae78sm841640a91.4.2026.08.03.23.45.18 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 03 Aug 2026 23:45:22 -0700 (PDT) From: ZhengYuan Huang To: mark@fasheh.com, jlbec@evilplan.org, joseph.qi@linux.alibaba.com Cc: ocfs2-devel@lists.linux.dev, linux-kernel@vger.kernel.org, baijiaju1990@gmail.com, r33s3n6@gmail.com, zzzccc427@gmail.com, tom442288@tuta.io, ZhengYuan Huang Subject: [PATCH v2] ocfs2: validate global bitmap cl_bpc before resize Date: Tue, 4 Aug 2026 14:44:45 +0800 Message-ID: <20260804064445.766072-1-gality369@gmail.com> X-Mailer: git-send-email 2.43.0 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit [BUG] A corrupted global bitmap inode can make online group extension scan past the end of a group descriptor bitmap: BUG: KASAN: use-after-free in _find_next_bit+0xef/0x120 lib/find_bit.c:157 Read of size 8 at addr ffff888021b52000 by task syz.0.34/409 Call Trace: ... _find_next_bit+0xef/0x120 lib/find_bit.c:157 find_next_bit include/linux/find.h:73 [inline] find_next_bit_le include/linux/find.h:518 [inline] ocfs2_find_max_contig_free_bits+0x53/0xb0 fs/ocfs2/suballoc.c:1292 ocfs2_update_last_group_and_inode fs/ocfs2/resize.c:127 [inline] ocfs2_group_extend+0x83e/0x1ae0 fs/ocfs2/resize.c:350 ocfs2_ioctl+0x175/0x6e0 fs/ocfs2/ioctl.c:869 vfs_ioctl fs/ioctl.c:51 [inline] __do_sys_ioctl fs/ioctl.c:597 [inline] __se_sys_ioctl fs/ioctl.c:583 [inline] __x64_sys_ioctl+0x197/0x1e0 fs/ioctl.c:583 ... [CAUSE] ocfs2_group_extend() consumes the global bitmap dinode's cl_bpc value in resize arithmetic. The existing inode validation checked cl_bpc only for non-global chain allocators, so a corrupted global bitmap value could reach the resize path. With cl_bpc changed from 1 to 51457, extending by seven clusters wraps the u16 bit count and grows a 2048-bit group to 34567 bits, exceeding its 32256-bit bitmap capacity. [FIX] Validate cl_bpc in ocfs2_validate_inode_block() for every chain allocator, including the global bitmap, against the value derived from the filesystem's cluster and block sizes. This rejects the corrupted dinode when it is read and removes the resize-local check that incorrectly assumed cl_bpc is always one. The resize path still uses the validated value for its arithmetic. Fixes: d659072f7368 ("[PATCH 1/2] ocfs2: Add group extend for online resize") Signed-off-by: ZhengYuan Huang --- v2: - Derive the expected cl_bpc from the filesystem block and cluster sizes. - Extend the existing inode-block validation to cover the global bitmap. - Remove the resize-local hardcoded cl_bpc check. --- --- fs/ocfs2/inode.c | 9 ++++----- 1 file changed, 4 insertions(+), 5 deletions(-) diff --git a/fs/ocfs2/inode.c b/fs/ocfs2/inode.c index 41db7dd39ed9..0e1f9ae0eb73 100644 --- a/fs/ocfs2/inode.c +++ b/fs/ocfs2/inode.c @@ -1683,12 +1683,11 @@ int ocfs2_validate_inode_block(struct super_block *sb, le16_to_cpu(cl->cl_next_free_rec)); goto bail; } - if (OCFS2_SB(sb)->bitmap_blkno && - OCFS2_SB(sb)->bitmap_blkno != le64_to_cpu(di->i_blkno) && - le16_to_cpu(cl->cl_bpc) != bpc) { - rc = ocfs2_error(sb, "Invalid dinode %llu: bits per cluster %u\n", + if (le16_to_cpu(cl->cl_bpc) != bpc) { + rc = ocfs2_error(sb, + "Invalid dinode %llu: bits per cluster %u (expected %u)\n", (unsigned long long)bh->b_blocknr, - le16_to_cpu(cl->cl_bpc)); + le16_to_cpu(cl->cl_bpc), bpc); goto bail; } } -- 2.43.0