From: sungbyeongchan <tjdqudcks0424@naver.com>
To: German Maglione <gmaglione@redhat.com>,
Vivek Goyal <vgoyal@redhat.com>,
Stefan Hajnoczi <stefanha@redhat.com>,
Miklos Szeredi <miklos@szeredi.hu>
Cc: "Eugenio Pérez" <eperezma@redhat.com>,
"Michael S . Tsirkin" <mst@redhat.com>,
virtualization@lists.linux.dev, fuse-devel@lists.linux.dev,
linux-fsdevel@vger.kernel.org, linux-kernel@vger.kernel.org,
stable@vger.kernel.org,
"Greg Kroah-Hartman" <gregkh@linuxfoundation.org>
Subject: [PATCH v2] virtiofs: validate fixed-output response length
Date: Wed, 7 Oct 2026 03:24:08 +0900 [thread overview]
Message-ID: <20261006182408.1301152-1-tjdqudcks0424@naver.com> (raw)
In-Reply-To: <20261004123405.586168-1-tjdqudcks0424@naver.com>
A short successful virtiofs response can leave the fixed-output
portion of the request argument buffer unwritten. The completion path
nevertheless copies the full declared output to the request destination,
allowing stale allocator contents to reach callers such as
fuse_statfs().
Require successful fixed-output responses to contain their complete
declared output. Continue to permit a shorter final argument only for
out_argvar requests. Reject positive and internal restart error values,
require valid error replies to be header-only, and do not copy output
arguments from error replies.
A header-only FUSE_STATFS success returned stale fields in nine of
nine calls across three boots. The fixed kernel rejected the short
response and preserved complete replies, valid error replies, and
variable-output controls.
Fixes: a62a8ef9d97d ("virtio-fs: add virtiofs filesystem")
Cc: stable@vger.kernel.org
Assisted-by: LLM
Signed-off-by: sungbyeongchan <tjdqudcks0424@naver.com>
---
Changes in v2:
- Reject positive and internal restart error values.
- Require error replies to be header-only.
- Rate-limit malformed-response warnings.
- Rely on the existing FUSE pr_fmt prefix.
- Add Cc: stable@vger.kernel.org.
- Use the reporter identity consistently.
fs/fuse/virtio_fs.c | 43 ++++++++++++++++++++++++++++++++++++++-----
1 file changed, 38 insertions(+), 5 deletions(-)
diff --git a/fs/fuse/virtio_fs.c b/fs/fuse/virtio_fs.c
index f15e516ebcb5c..fffbe08d9114a 100644
--- a/fs/fuse/virtio_fs.c
+++ b/fs/fuse/virtio_fs.c
@@ -4,6 +4,8 @@
* Copyright (C) 2018 Red Hat, Inc.
*/
+#include "fuse_i.h"
+
#include <linux/fs.h>
#include <linux/dax.h>
#include <linux/pci.h>
@@ -20,7 +22,6 @@
#include <linux/cleanup.h>
#include <linux/uio.h>
#include "dev.h"
-#include "fuse_i.h"
#include "fuse_dev_i.h"
/* Used to help calculate the FUSE connection's max_pages limit for a request's
@@ -730,6 +731,10 @@ static void copy_args_from_argbuf(struct fuse_args *args, struct fuse_req *req)
unsigned int num_out;
unsigned int i;
+ /* Error replies contain only the output header. */
+ if (req->out.h.error)
+ goto out;
+
remaining = req->out.h.len - sizeof(req->out.h);
num_in = args->in_numargs - args->in_pages;
num_out = args->out_numargs - args->out_pages;
@@ -755,6 +760,7 @@ static void copy_args_from_argbuf(struct fuse_args *args, struct fuse_req *req)
if (args->out_argvar)
args->out_args[args->out_numargs - 1].size = remaining;
+out:
kfree(req->argbuf);
req->argbuf = NULL;
}
@@ -762,19 +768,46 @@ static void copy_args_from_argbuf(struct fuse_args *args, struct fuse_req *req)
/* Verify that the server properly follows the FUSE protocol */
static bool virtio_fs_verify_response(struct fuse_req *req, unsigned int len)
{
+ struct fuse_args *args = req->args;
struct fuse_out_header *oh = &req->out.h;
+ unsigned int expected;
if (len < sizeof(*oh)) {
- pr_warn("virtio-fs: response too short (%u)\n", len);
+ pr_warn_ratelimited("response too short (%u)\n", len);
return false;
}
if (oh->len != len) {
- pr_warn("virtio-fs: oh.len mismatch (%u != %u)\n", oh->len, len);
+ pr_warn_ratelimited("oh.len mismatch (%u != %u)\n",
+ oh->len, len);
return false;
}
if (oh->unique != req->in.h.unique) {
- pr_warn("virtio-fs: oh.unique mismatch (%llu != %llu)\n",
- oh->unique, req->in.h.unique);
+ pr_warn_ratelimited("oh.unique mismatch (%llu != %llu)\n",
+ oh->unique, req->in.h.unique);
+ return false;
+ }
+ if (oh->error <= -ERESTARTSYS || oh->error > 0) {
+ pr_warn_ratelimited("invalid error value (%d)\n", oh->error);
+ return false;
+ }
+
+ if (oh->error) {
+ if (len != sizeof(*oh)) {
+ pr_warn_ratelimited("error response too long (%u)\n",
+ len);
+ return false;
+ }
+ return true;
+ }
+
+ expected = sizeof(*oh) +
+ fuse_len_args(args->out_numargs, args->out_args);
+ if (len > expected ||
+ (len < expected &&
+ (!args->out_argvar ||
+ expected - len > args->out_args[args->out_numargs - 1].size))) {
+ pr_warn_ratelimited("invalid response length (%u, expected %u)\n",
+ len, expected);
return false;
}
return true;
--
2.43.0
next prev parent reply other threads:[~2026-10-06 18:24 UTC|newest]
Thread overview: 11+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-10-04 12:34 [PATCH] virtiofs: validate fixed-output response length sungbyeongchan
2026-10-04 12:46 ` sashiko-bot
2026-10-04 12:55 ` Greg Kroah-Hartman
2026-10-04 12:56 ` Greg Kroah-Hartman
2026-10-04 13:04 ` Michael S. Tsirkin
2026-10-04 14:48 ` [PATCH v2] " Byeongchan Sung
2026-10-04 14:59 ` sashiko-bot
2026-10-06 18:24 ` sungbyeongchan [this message]
2026-10-06 18:36 ` sashiko-bot
2026-10-06 21:11 ` Greg Kroah-Hartman
2026-10-06 21:27 ` Michael S. Tsirkin
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20261006182408.1301152-1-tjdqudcks0424@naver.com \
--to=tjdqudcks0424@naver.com \
--cc=eperezma@redhat.com \
--cc=fuse-devel@lists.linux.dev \
--cc=gmaglione@redhat.com \
--cc=gregkh@linuxfoundation.org \
--cc=linux-fsdevel@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=miklos@szeredi.hu \
--cc=mst@redhat.com \
--cc=stable@vger.kernel.org \
--cc=stefanha@redhat.com \
--cc=vgoyal@redhat.com \
--cc=virtualization@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox