* [PATCH v3] virtiofs: validate fixed-output response length
@ 2026-10-07 6:19 Sung Byeongchan
2026-10-07 6:32 ` sashiko-bot
0 siblings, 1 reply; 2+ messages in thread
From: Sung Byeongchan @ 2026-10-07 6:19 UTC (permalink / raw)
To: German Maglione, Vivek Goyal, Stefan Hajnoczi, Miklos Szeredi
Cc: Eugenio Pérez, Michael S . Tsirkin, Greg Kroah-Hartman,
virtualization, linux-fsdevel, fuse-devel, linux-kernel
A short successful virtiofs response can leave the fixed-output portion of
the request argument buffer unwritten. The completion path nevertheless
copies the full declared output to the request destination, allowing stale
allocator contents to reach callers such as fuse_statfs().
Require successful fixed-output responses to contain their complete
declared output. Continue to permit a shorter final argument only for
out_argvar requests. Reject positive and internal restart error values
and require valid error replies to be header-only. The error already
stored in the FUSE output header is returned by fuse_request_end(), so do
not copy output arguments from an error reply.
This was found by source review with AI assistance. A header-only
successful FUSE_STATFS reply returned stale fields in nine of nine calls
across three boots. The fixed kernel rejected the short response and
preserved complete replies, valid negative-error replies, and
variable-output replies.
Fixes: a62a8ef9d97d ("virtio-fs: add virtiofs filesystem")
Cc: stable@vger.kernel.org
Assisted-by: LLM
Signed-off-by: Sung Byeongchan <tjdqudcks0424@naver.com>
---
Changes in v3:
- Keep fuse_i.h in its original include position.
- Drop the unrelated warning ratelimiting and prefix changes.
- Explain that req->out.h.error is propagated by fuse_request_end(); the
completion copy only skips nonexistent output arguments for error replies.
- Use the spaced real-name form requested during review.
Changes in v2:
- Validate positive and internal restart error values.
- Require error replies to be header-only.
- Add Cc: stable@vger.kernel.org.
fs/fuse/virtio_fs.c | 30 ++++++++++++++++++++++++++++++
1 file changed, 30 insertions(+)
diff --git a/fs/fuse/virtio_fs.c b/fs/fuse/virtio_fs.c
index 4f334766b8c30..1b585bbbe353d 100644
--- a/fs/fuse/virtio_fs.c
+++ b/fs/fuse/virtio_fs.c
@@ -730,6 +730,10 @@ static void copy_args_from_argbuf(struct fuse_args *args, struct fuse_req *req)
unsigned int num_out;
unsigned int i;
+ /* fuse_request_end() returns this error; there are no args to copy. */
+ if (req->out.h.error)
+ goto out;
+
remaining = req->out.h.len - sizeof(req->out.h);
num_in = args->in_numargs - args->in_pages;
num_out = args->out_numargs - args->out_pages;
@@ -755,6 +759,7 @@ static void copy_args_from_argbuf(struct fuse_args *args, struct fuse_req *req)
if (args->out_argvar)
args->out_args[args->out_numargs - 1].size = remaining;
+out:
kfree(req->argbuf);
req->argbuf = NULL;
}
@@ -762,7 +767,9 @@ static void copy_args_from_argbuf(struct fuse_args *args, struct fuse_req *req)
/* Verify that the server properly follows the FUSE protocol */
static bool virtio_fs_verify_response(struct fuse_req *req, unsigned int len)
{
+ struct fuse_args *args = req->args;
struct fuse_out_header *oh = &req->out.h;
+ unsigned int expected;
if (len < sizeof(*oh)) {
pr_warn("virtio-fs: response too short (%u)\n", len);
@@ -777,6 +784,29 @@ static bool virtio_fs_verify_response(struct fuse_req *req, unsigned int len)
oh->unique, req->in.h.unique);
return false;
}
+ if (oh->error <= -ERESTARTSYS || oh->error > 0) {
+ pr_warn("virtio-fs: invalid error value (%d)\n", oh->error);
+ return false;
+ }
+
+ if (oh->error) {
+ if (len != sizeof(*oh)) {
+ pr_warn("virtio-fs: error response too long (%u)\n", len);
+ return false;
+ }
+ return true;
+ }
+
+ expected = sizeof(*oh) +
+ fuse_len_args(args->out_numargs, args->out_args);
+ if (len > expected ||
+ (len < expected &&
+ (!args->out_argvar ||
+ expected - len > args->out_args[args->out_numargs - 1].size))) {
+ pr_warn("virtio-fs: invalid response length (%u, expected %u)\n",
+ len, expected);
+ return false;
+ }
return true;
}
--
2.43.0
^ permalink raw reply related [flat|nested] 2+ messages in thread
* Re: [PATCH v3] virtiofs: validate fixed-output response length
2026-10-07 6:19 [PATCH v3] virtiofs: validate fixed-output response length Sung Byeongchan
@ 2026-10-07 6:32 ` sashiko-bot
0 siblings, 0 replies; 2+ messages in thread
From: sashiko-bot @ 2026-10-07 6:32 UTC (permalink / raw)
To: Sung Byeongchan; +Cc: Eugenio Perez, virtualization, Michael S. Tsirkin
> A short successful virtiofs response can leave the fixed-output portion of
> the request argument buffer unwritten. The completion path nevertheless
> copies the full declared output to the request destination, allowing stale
> allocator contents to reach callers such as fuse_statfs().
>
> Require successful fixed-output responses to contain their complete
> declared output. Continue to permit a shorter final argument only for
> out_argvar requests. Reject positive and internal restart error values
> and require valid error replies to be header-only. The error already
> stored in the FUSE output header is returned by fuse_request_end(), so do
> not copy output arguments from an error reply.
>
> This was found by source review with AI assistance. A header-only
> successful FUSE_STATFS reply returned stale fields in nine of nine calls
> across three boots. The fixed kernel rejected the short response and
> preserved complete replies, valid negative-error replies, and
> variable-output replies.
>
> Fixes: a62a8ef9d97d ("virtio-fs: add virtiofs filesystem")
> Cc: stable@vger.kernel.org
> Assisted-by: LLM
> Signed-off-by: Sung Byeongchan <tjdqudcks0424@naver.com>
Sashiko has reviewed this patch and found no issues. It looks great!
--
Sashiko AI review · https://sashiko.dev/#/patchset/20261007061949.23008-1-tjdqudcks0424@naver.com?part=1
^ permalink raw reply [flat|nested] 2+ messages in thread
end of thread, other threads:[~2026-10-07 6:32 UTC | newest]
Thread overview: 2+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-10-07 6:19 [PATCH v3] virtiofs: validate fixed-output response length Sung Byeongchan
2026-10-07 6:32 ` sashiko-bot
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox