Commit 1e1c2b8
ext4: block range must be validated before use in ext4_mb_clear_bb()
Block range to free is validated in ext4_free_blocks() using
ext4_inode_block_valid() and then it's passed to ext4_mb_clear_bb().
However in some situations on bigalloc file system the range might be
adjusted after the validation in ext4_free_blocks() which can lead to
troubles on corrupted file systems such as one found by syzkaller that
resulted in the following BUG
kernel BUG at fs/ext4/ext4.h:3319!
PREEMPT SMP NOPTI
CPU: 28 PID: 4243 Comm: repro Kdump: loaded Not tainted 5.19.0-rc6+ #1
Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.15.0-1.fc35 04/01/2014
RIP: 0010:ext4_free_blocks+0x95e/0xa90
Call Trace:
<TASK>
? lock_timer_base+0x61/0x80
? __es_remove_extent+0x5a/0x760
? __mod_timer+0x256/0x380
? ext4_ind_truncate_ensure_credits+0x90/0x220
ext4_clear_blocks+0x107/0x1b0
ext4_free_data+0x15b/0x170
ext4_ind_truncate+0x214/0x2c0
? _raw_spin_unlock+0x15/0x30
? ext4_discard_preallocations+0x15a/0x410
? ext4_journal_check_start+0xe/0x90
? __ext4_journal_start_sb+0x2f/0x110
ext4_truncate+0x1b5/0x460
? __ext4_journal_start_sb+0x2f/0x110
ext4_evict_inode+0x2b4/0x6f0
evict+0xd0/0x1d0
ext4_enable_quotas+0x11f/0x1f0
ext4_orphan_cleanup+0x3de/0x430
? proc_create_seq_private+0x43/0x50
ext4_fill_super+0x295f/0x3ae0
? snprintf+0x39/0x40
? sget_fc+0x19c/0x330
? ext4_reconfigure+0x850/0x850
get_tree_bdev+0x16d/0x260
vfs_get_tree+0x25/0xb0
path_mount+0x431/0xa70
__x64_sys_mount+0xe2/0x120
do_syscall_64+0x5b/0x80
? do_user_addr_fault+0x1e2/0x670
? exc_page_fault+0x70/0x170
entry_SYSCALL_64_after_hwframe+0x46/0xb0
RIP: 0033:0x7fdf4e512ace
Fix it by making sure that the block range is properly validated before
used every time it changes in ext4_free_blocks() or ext4_mb_clear_bb().
Link: https://syzkaller.appspot.com/bug?id=5266d464285a03cee9dbfda7d2452a72c3c2ae7c
Reported-by: syzbot+15cd994e273307bf5cfa@syzkaller.appspotmail.com
Signed-off-by: Lukas Czerner <lczerner@redhat.com>
Cc: Tadeusz Struk <tadeusz.struk@linaro.org>
Tested-by: Tadeusz Struk <tadeusz.struk@linaro.org>
Link: https://lore.kernel.org/r/20220714165903.58260-1-lczerner@redhat.com
Signed-off-by: Theodore Ts'o <tytso@mit.edu>1 parent 307af6c commit 1e1c2b8
1 file changed
Lines changed: 20 additions & 1 deletion
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
5934 | 5934 | | |
5935 | 5935 | | |
5936 | 5936 | | |
| 5937 | + | |
| 5938 | + | |
| 5939 | + | |
| 5940 | + | |
| 5941 | + | |
| 5942 | + | |
| 5943 | + | |
| 5944 | + | |
| 5945 | + | |
5937 | 5946 | | |
5938 | 5947 | | |
5939 | 5948 | | |
| |||
5950 | 5959 | | |
5951 | 5960 | | |
5952 | 5961 | | |
| 5962 | + | |
| 5963 | + | |
5953 | 5964 | | |
5954 | 5965 | | |
5955 | 5966 | | |
| |||
5964 | 5975 | | |
5965 | 5976 | | |
5966 | 5977 | | |
5967 | | - | |
| 5978 | + | |
| 5979 | + | |
5968 | 5980 | | |
5969 | 5981 | | |
5970 | 5982 | | |
| |||
6087 | 6099 | | |
6088 | 6100 | | |
6089 | 6101 | | |
| 6102 | + | |
| 6103 | + | |
6090 | 6104 | | |
6091 | 6105 | | |
6092 | 6106 | | |
| |||
6133 | 6147 | | |
6134 | 6148 | | |
6135 | 6149 | | |
| 6150 | + | |
6136 | 6151 | | |
6137 | 6152 | | |
6138 | 6153 | | |
| |||
6164 | 6179 | | |
6165 | 6180 | | |
6166 | 6181 | | |
| 6182 | + | |
| 6183 | + | |
6167 | 6184 | | |
6168 | 6185 | | |
6169 | 6186 | | |
| |||
6174 | 6191 | | |
6175 | 6192 | | |
6176 | 6193 | | |
| 6194 | + | |
| 6195 | + | |
6177 | 6196 | | |
6178 | 6197 | | |
6179 | 6198 | | |
| |||
0 commit comments