[PATCH v2] xfs: fix off-by-one in rtrefcount btree root level validation

Xiang Mei posted 1 patch 1 week, 3 days ago
fs/xfs/libxfs/xfs_rtrefcount_btree.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
[PATCH v2] xfs: fix off-by-one in rtrefcount btree root level validation
Posted by Xiang Mei 1 week, 3 days ago
xfs_rtrefcountbt_compute_maxlevels() sets

	mp->m_rtrefc_maxlevels = min(d_maxlevels, r_maxlevels) + 1;

where the trailing "+ 1" already accounts for the inode-root level, so the
deepest valid on-disk root level is m_rtrefc_maxlevels - 1 and a cursor must
satisfy bc_nlevels <= bc_maxlevels (= m_rtrefc_maxlevels).

The two on-disk validation paths, xfs_rtrefcountbt_verify() and
xfs_iformat_rtrefcount(), check the root level with ">" instead of ">=", so a
crafted rtreflink (metadir + realtime + reflink) image whose
/rtgroups/N.refcount inode has bb_level == m_rtrefc_maxlevels is accepted on
mount. xfs_rtrefcountbt_init_cursor() then sets bc_nlevels = bb_level + 1,
exceeding bc_maxlevels by one. Since the xfs_rtrefcountbt_cur slab object is
sized for exactly bc_maxlevels entries, the first btree op on such a cursor
indexes bc_levels[m_rtrefc_maxlevels] past the end of the object. This is
reached by the first rtrefcount cursor built after mount, via log/CoW
recovery (xfs_reflink_recover_cow() during xfs_mountfs()) or an
FS_IOC_GETFSMAP over the realtime device.

Reject a root level equal to m_rtrefc_maxlevels, matching the ">=" form
already used by the sibling data-device refcount/rmap verifiers and the
in-memory rtrmap verifier.

  BUG: KASAN: slab-out-of-bounds in xfs_btree_lookup (fs/xfs/libxfs/xfs_btree.c:2101)
  Write of size 2 at addr ffff888018391658 by task exploit/144
   xfs_btree_lookup (fs/xfs/libxfs/xfs_btree.c:2101)
   xfs_btree_query_range (fs/xfs/libxfs/xfs_btree.c:5308)
   xfs_refcount_recover_cow_leftovers (fs/xfs/libxfs/xfs_refcount.c:2113)
   xfs_reflink_recover_cow (fs/xfs/xfs_reflink.c:1085)
   xlog_recover_finish (fs/xfs/xfs_log_recover.c:3551)
   xfs_mountfs (fs/xfs/xfs_mount.c:1158)
   xfs_fs_fill_super (fs/xfs/xfs_super.c:1940)
   get_tree_bdev_flags (fs/super.c:1634)
   vfs_get_tree (fs/super.c:1694)
   path_mount (fs/namespace.c:4161)
   __x64_sys_mount (fs/namespace.c:4367)
   entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:121)
  The buggy address belongs to the cache xfs_rtrefcountbt_cur of size 216
  The buggy address is located 8 bytes to the right of
   allocated 216-byte region [ffff888018391578, ffff888018391650)
  Kernel panic - not syncing: Fatal exception

Cc: <stable@vger.kernel.org> # v6.14
Fixes: 9abe03a0e4f978 ("xfs: introduce realtime refcount btree ondisk definitions")
Reported-by: Weiming Shi <bestswngs@gmail.com>
Assisted-by: Claude:claude-opus-4-8
Signed-off-by: Xiang Mei <xmei5@asu.edu>
Reviewed-by: "Darrick J. Wong" <djwong@kernel.org>
Reviewed-by: Christoph Hellwig <hch@lst.de>
---
 fs/xfs/libxfs/xfs_rtrefcount_btree.c | 4 ++--
 1 file changed, 2 insertions(+), 2 deletions(-)

diff --git a/fs/xfs/libxfs/xfs_rtrefcount_btree.c b/fs/xfs/libxfs/xfs_rtrefcount_btree.c
index f27b80a199ba..22acc1411aac 100644
--- a/fs/xfs/libxfs/xfs_rtrefcount_btree.c
+++ b/fs/xfs/libxfs/xfs_rtrefcount_btree.c
@@ -201,7 +201,7 @@ xfs_rtrefcountbt_verify(
 	if (fa)
 		return fa;
 	level = be16_to_cpu(block->bb_level);
-	if (level > mp->m_rtrefc_maxlevels)
+	if (level >= mp->m_rtrefc_maxlevels)
 		return __this_address;
 
 	return xfs_btree_fsblock_verify(bp, mp->m_rtrefc_mxr[level != 0]);
@@ -651,7 +651,7 @@ xfs_iformat_rtrefcount(
 	numrecs = be16_to_cpu(dfp->bb_numrecs);
 	level = be16_to_cpu(dfp->bb_level);
 
-	if (level > mp->m_rtrefc_maxlevels ||
+	if (level >= mp->m_rtrefc_maxlevels ||
 	    xfs_rtrefcount_droot_space_calc(level, numrecs) > dsize) {
 		xfs_inode_mark_sick(ip, XFS_SICK_INO_CORE);
 		return -EFSCORRUPTED;
-- 
2.43.0
Re: [PATCH v2] xfs: fix off-by-one in rtrefcount btree root level validation
Posted by Carlos Maiolino 4 days, 7 hours ago
On Tue, 14 Jul 2026 14:56:12 -0700, Xiang Mei wrote:
> xfs_rtrefcountbt_compute_maxlevels() sets
> 
> 	mp->m_rtrefc_maxlevels = min(d_maxlevels, r_maxlevels) + 1;
> 
> where the trailing "+ 1" already accounts for the inode-root level, so the
> deepest valid on-disk root level is m_rtrefc_maxlevels - 1 and a cursor must
> satisfy bc_nlevels <= bc_maxlevels (= m_rtrefc_maxlevels).
> 
> [...]

Applied to for-next, thanks!

[1/1] xfs: fix off-by-one in rtrefcount btree root level validation
      commit: fde50b32183f19041b4bab66c8f07b1cc38f8e26

Best regards,
-- 
Carlos Maiolino <cem@kernel.org>
Re: [PATCH v2] xfs: fix off-by-one in rtrefcount btree root level validation
Posted by Xiang Mei 4 days ago
On Tue, Jul 21, 2026 at 3:44 AM Carlos Maiolino <cem@kernel.org> wrote:
>
> On Tue, 14 Jul 2026 14:56:12 -0700, Xiang Mei wrote:
> > xfs_rtrefcountbt_compute_maxlevels() sets
> >
> >       mp->m_rtrefc_maxlevels = min(d_maxlevels, r_maxlevels) + 1;
> >
> > where the trailing "+ 1" already accounts for the inode-root level, so the
> > deepest valid on-disk root level is m_rtrefc_maxlevels - 1 and a cursor must
> > satisfy bc_nlevels <= bc_maxlevels (= m_rtrefc_maxlevels).
> >
> > [...]
>
> Applied to for-next, thanks!
>
> [1/1] xfs: fix off-by-one in rtrefcount btree root level validation
>       commit: fde50b32183f19041b4bab66c8f07b1cc38f8e26
>
> Best regards,
> --
> Carlos Maiolino <cem@kernel.org>
>
Thank you for your review!

Xiang