Re: [PATCH] ocfs2: validate global bitmap cl_bpc before resize
ZhengYuan Huang <[email protected]>
| Newsgroups | dev.linux.lists.ocfs2-devel,org.kernel.vger.linux-kernel |
|---|---|
| Message-ID | <CAOmEq9W_8iOtV4SZPpODbwqwO8kQsEyktGjgXu0nVM+tpW+w1Q@mail.gmail.com> |
On Mon, Aug 3, 2026 at 2:37 PM Heming Zhao <[email protected]> wrote: > > On Mon, Aug 03, 2026 at 11:11:16AM +0800, ZhengYuan Huang wrote: > > [BUG] > > A corrupted global bitmap inode can make online group extension scan past > > the end of a group descriptor bitmap: > > > > BUG: KASAN: use-after-free in _find_next_bit+0xef/0x120 lib/find_bit.c:157 > > Read of size 8 at addr ffff888021b52000 by task syz.0.34/409 > > Call Trace: > > <TASK> > > ... > > _find_next_bit+0xef/0x120 lib/find_bit.c:157 > > find_next_bit include/linux/find.h:73 [inline] > > find_next_bit_le include/linux/find.h:518 [inline] > > ocfs2_find_max_contig_free_bits+0x53/0xb0 fs/ocfs2/suballoc.c:1292 > > ocfs2_update_last_group_and_inode fs/ocfs2/resize.c:127 [inline] > > ocfs2_group_extend+0x83e/0x1ae0 fs/ocfs2/resize.c:350 > > ocfs2_ioctl+0x175/0x6e0 fs/ocfs2/ioctl.c:869 > > vfs_ioctl fs/ioctl.c:51 [inline] > > __do_sys_ioctl fs/ioctl.c:597 [inline] > > __se_sys_ioctl fs/ioctl.c:583 [inline] > > __x64_sys_ioctl+0x197/0x1e0 fs/ioctl.c:583 > > ... > > > > [CAUSE] > > ocfs2_group_extend() trusts the global bitmap dinode's cl_bpc value. > > If its high byte corrupted from zero to 0xc9 makes cl_bpc 51457. > > Extending by seven clusters narrows their product to a u16 value of > > 32519 and raises a 2048-bit group to 34567 bits, beyond its 32256-bit > > bitmap. The subsequent maximum-free-run scan then reads into the next > > page. > > > > [FIX] > > Reject a global bitmap whose cl_bpc is not one before using it in any > > resize arithmetic. The global allocator has exactly one bitmap bit per > > cluster, so this validates the invariant at the cold online-resize > > boundary and reports metadata corruption instead of enlarging bg_bits > > past the descriptor. > > > > Fixes: d659072f7368 ("[PATCH 1/2] ocfs2: Add group extend for online resize") > > Signed-off-by: ZhengYuan Huang <[email protected]> > > --- > > fs/ocfs2/resize.c | 9 ++++++++- > > 1 file changed, 8 insertions(+), 1 deletion(-) > > > > diff --git a/fs/ocfs2/resize.c b/fs/ocfs2/resize.c > > index 6375d5035972..556aaa319621 100644 > > --- a/fs/ocfs2/resize.c > > +++ b/fs/ocfs2/resize.c > > @@ -311,6 +311,14 @@ int ocfs2_group_extend(struct inode * inode, int new_clusters) > > goto out_unlock; > > } > > > > + cl_bpc = le16_to_cpu(fe->id2.i_chain.cl_bpc); > > + if (cl_bpc != 1) { > > cl_bpc is not a fixed value. Refer from mkfs.ocfs2(8), only both block size > and cluster size are 4K, cl_bpc is 1. Otherwise, cl_bpc is 2, 4, .... > > Btw, is it any possible to put the check in ocfs2_validate_inode_block()? > > Thanks, > Heming You're right. Thank you for the guidance. In the v2 patch, I moved the check into ocfs2_validate_inode_block(). The updated patch has been sent. Thanks, ZhengYuan Huang