Re: [PATCH 2/2] ocfs2: validate DIO orphan slot during inode read

Joseph Qi <[email protected]>
Newsgroups dev.linux.lists.ocfs2-devel,org.kernel.vger.linux-kernel
Message-ID <[email protected]>

On 8/3/26 11:00 AM, ZhengYuan Huang wrote:
> [BUG]
> A corrupted append-DIO dinode (high byte at offset 0xa1 
> corrupted from 0 to 1) can carry an i_dio_orphaned_slot
> outside the mounted filesystem slot range and trigger a 
> use-after-free error:
> 
> BUG: KASAN: slab-use-after-free in ocfs2_get_system_file_inode+0x780/0x820 fs/ocfs2/sysfile.c:102
> Read of size 8 at addr ffff88800b767c00 by task kworker/u8:3/85
> Call Trace:
>  ...
>  ocfs2_get_system_file_inode+0x780/0x820 fs/ocfs2/sysfile.c:102
>  ocfs2_wipe_inode+0x292/0xf70 fs/ocfs2/inode.c:840
>  ocfs2_delete_inode fs/ocfs2/inode.c:1155 [inline]
>  ocfs2_evict_inode+0x6c9/0x1170 fs/ocfs2/inode.c:1295
>  evict+0x38e/0x8f0 fs/inode.c:810
>  iput_final fs/inode.c:1914 [inline]
>  iput fs/inode.c:1966 [inline]
>  iput+0x55b/0x8b0 fs/inode.c:1926
>  ocfs2_recover_orphans+0x610/0xe40 fs/ocfs2/journal.c:2374
>  ocfs2_complete_recovery+0x5af/0xd00 fs/ocfs2/journal.c:1373
>  ...
> 
> [CAUSE]
> ocfs2_del_inode_from_orphan() uses i_dio_orphaned_slot to index the
> slot-local system inode cache. The dinode validator does not check
> this active slot, so an out-of-range value produces an invalid cache
> entry pointer that is dereferenced as an inode pointer.
> 
> [FIX]
> Reject an active i_dio_orphaned_slot outside the slot range during
> dinode validation, before DIO orphan recovery can consume it.
> 
> Fixes: 06ee5c75b575 ("ocfs2: add functions to add and remove inode in orphan dir")
> Signed-off-by: ZhengYuan Huang <[email protected]>

Reviewed-by: Joseph Qi <[email protected]>
> ---
>  fs/ocfs2/inode.c | 8 ++++++++
>  1 file changed, 8 insertions(+)
> 
> diff --git a/fs/ocfs2/inode.c b/fs/ocfs2/inode.c
> index 358ab3535366..180107a11046 100644
> --- a/fs/ocfs2/inode.c
> +++ b/fs/ocfs2/inode.c
> @@ -1536,6 +1536,14 @@ int ocfs2_validate_inode_block(struct super_block *sb,
>  		goto bail;
>  	}
>  
> +	if ((le32_to_cpu(di->i_flags) & OCFS2_DIO_ORPHANED_FL) &&
> +	    le16_to_cpu(di->i_dio_orphaned_slot) >= OCFS2_SB(sb)->max_slots) {
> +		rc = ocfs2_error(sb, "Invalid dinode %llu: DIO orphaned slot %u\n",
> +				 (unsigned long long)bh->b_blocknr,
> +				 le16_to_cpu(di->i_dio_orphaned_slot));
> +		goto bail;
> +	}
> +
>  	/*
>  	 * Reject dinodes whose i_mode does not name one of the seven
>  	 * canonical POSIX file types.  ocfs2_populate_inode() copies
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.