Re: [PATCH v3 0/2] ocfs2: validate xattr metadata bounds
Joseph Qi <[email protected]> Mon, 22 Jun 2026 15:10:34 +0800
| Newsgroups | dev.linux.lists.ocfs2-devel |
|---|---|
| Message-ID | <[email protected]> |
Hi, I couldn't apply your patches cleanly upon the lastest master. Could you please do a update? Thanks, Joseph On 6/16/26 5:11 PM, Zhang Cen wrote: > From: Cen Zhang <[email protected]> > > Hi, > > This v3 moves the corrupted xattr metadata checks into the metadata > validation paths Joseph pointed at. > > Patch 1 validates inline xattr metadata from > ocfs2_validate_inode_block() and keeps the get/list consumers using the > same helper before they derive pointers from i_xattr_inline_size. > > Patch 2 validates non-indexed external xattr blocks from > ocfs2_validate_xattr_block(). Indexed xattr buckets do not pass through > that validator, so their header and per-entry bounds are checked after > bucket ECC verification in ocfs2_read_xattr_bucket(). > > Both issues were reproduced with crafted OCFS2 images under KASAN. > > Changes since v2: > - Move inline xattr validation into ocfs2_validate_inode_block(). > - Move non-indexed external xattr validation into > ocfs2_validate_xattr_block(). > - Validate indexed xattr bucket entries at bucket read time, after ECC > verification. > - Keep get/list path checks as helper reuse instead of a separate > consumer-only policy. > > Cen Zhang (2): > ocfs2: validate inline xattrs during inode block validation > ocfs2: validate external xattr entries when reading metadata > > fs/ocfs2/inode.c | 4 ++ > fs/ocfs2/xattr.c | 211 +++++++++++++++++++++++++++++++++++++++-------- > fs/ocfs2/xattr.h | 2 + > 3 files changed, 183 insertions(+), 34 deletions(-) >