From nobody Sat Jul 25 04:54:08 2026 Received: from mail-pg1-f173.google.com (mail-pg1-f173.google.com [209.85.215.173]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 784F937AA6A for ; Fri, 17 Jul 2026 19:24:28 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.215.173 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784316269; cv=none; b=RG2ZZGJ4s04AMuc9B9scs343q293YSVayrd6RZj/VWi9y90vLo+4g1QGGHjV+omn7cq1qd3KfLwoBLPO8QnK2Lu/XE+x7/rB4LWpB7ySILImaHaiurKQe6/VbpF3w7hbAvTKu2C97ebPzNwazYeJmK+TT3J4wYrBvg9WzT7WP0k= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784316269; c=relaxed/simple; bh=KeKC7n/oTJyTV63b3Kr+tQ3oG2a+u/DbbZq9QhNw8gw=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=frMl7NNfWxDC7jFohExgO0EPtdUuv7ohEpSJp7513AgQcF7/FBchpKwEnz6D6yevedWlgH8JvR9vnqQ//m2d5FcCT+v9EP/QTWTuOOBxsO9iZghjsb+TeIZFdUiZZhj9/hH77qmGRJ6+C8sOS0PkdCLgHxhRTHA6DGEVd37oEKA= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=tE6YSNYf; arc=none smtp.client-ip=209.85.215.173 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="tE6YSNYf" Received: by mail-pg1-f173.google.com with SMTP id 41be03b00d2f7-cb5a6aa8760so321005a12.1 for ; Fri, 17 Jul 2026 12:24:28 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1784316268; x=1784921068; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=UidqxNP5YgqeCULD9zL1DJ+TVbEY7ph+loZhp7Vlg48=; b=tE6YSNYfWKI6rzcWfv3HKWfx0kWoOi1SpLlxtEDg6BJIOC1zHMw8K7BTgoYJmJY7DU iZVpWdLLU706WKxzqYdnb7EyLnyZp33v6gbxIEG2DzPOgLcnCNBv7lrDxlRcTnnwof/w pgznmIc8UPf8WlB1TcUEBGatTYMnsqlY7T74iVZFOLiZ5v/x97c+VgLDgKy7hLR/YKkW 2lkJPKQvOpq+Ldh6Id4FDVpLOkbHhse29m+gNb66dnIUyVnUh9trRg9jgN3fANNcQaGY 3Vxy7UUT2RX9BCBkNwzN/7MJaUqr724xnkymD0sPYMlcwTGR3hydLohm9kFaeMNWxx/E WvNg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784316268; x=1784921068; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=UidqxNP5YgqeCULD9zL1DJ+TVbEY7ph+loZhp7Vlg48=; b=gkn/10Szr7Xk3ALknGiavyZ/5+Kv4KSELsnGK5fMusTz6tfpWe90NhwvYLSy9EtbkD 77aaP5cqLviQj13ZZTCl56XZi1RVS3/0X7ME/91RsUSUMbaPx4jb+OCQQM4xwEUm/NKg Irz++SVgXuP7YxiajtSDtmdIWtzWWi25RqrqTzbMXqDUPM9+iage6yEdnGCx+Qqrz7S3 YHtg5f8DfHTrxfPGmK0UA9P3GLTMWus+APbMKp+snmRtDrGLlFqVXzollBTdbypk7xNQ SbUXNE4CTGkCUHrCo4Yt1Ftj7Qkhga0XVWOgSUBqDkEyk6VX+n+YuR0RMxBDeyqZzMlH NE0Q== X-Forwarded-Encrypted: i=1; AHgh+Rr87IL3clS2kJKizEI/qg0OmhOLKbZWaId076iDF/HoqLl25INCZ0KIZ7/NY6oG3Prhz3vPLADYXKcvLqo=@vger.kernel.org X-Gm-Message-State: AOJu0YykBTwLMP3IzTVm8kMGMFmbSvg7g5lrWKWF3L6LOPqEr4I7wtdW Y10X8xXVxUY3p/bbk0JeB/wP14R/w+zwZNZcZOEsoRseoqSQlYuuumee X-Gm-Gg: AfdE7cnY5uJJlnGN9bmQuZ1gknKUf33PsvfqC0kA+1oHrQ4/CcJZllvlqAqXH9Br+YP qUjQqRUrx8DbzgQuMP8c5XQmoOsHTTMySJ31+if619lbRdv3a6e8EIJqWdsnUYGRktcdVqZKBT+ Xdm+gzA8OdP6k1oAO96EpYTz4JIkUg4VunYZLx7iCP2rfU/i01vvcYKph0hyCN3XQu9vNf1dRnA ct09zUL4J6TXWgzv312vLoYcdNIoNx8bjgi6Pqs5YdxJaNUt0geV3exq+MLsCH35HPKp2zzo/Jo j6H0ohzwyURi5GMwF//HpJZXlhMc900ExNidMlk1CG9P0iWf6Q575cFMVtwlORklio6iuQHTbUR qRhH/PbyJju0IiODGoEaIz8bilcEDejdiQR53z7ZxoGlbOSUfY6ytL2asPdq6b1UxwX1P1GM/Gn 58z5TtV0FgszVl8g+M82bEreQjkd99nt2BZcWuQDqFYBlXAIg= X-Received: by 2002:a17:90b:264b:b0:387:e0db:bc24 with SMTP id 98e67ed59e1d1-38e4b555d20mr3795621a91.36.1784316267848; Fri, 17 Jul 2026 12:24:27 -0700 (PDT) Received: from fx.tailc0aff1.ts.net ([206.206.192.132]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-3142a1dde81sm18648783eec.21.2026.07.17.12.24.26 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Fri, 17 Jul 2026 12:24:27 -0700 (PDT) From: Weiming Shi To: Carlos Maiolino , "Darrick J . Wong" Cc: linux-xfs@vger.kernel.org, linux-kernel@vger.kernel.org, xmei5@asu.edu, Weiming Shi , Dave Chinner Subject: [PATCH v2 1/2] xfs: reject log items with missing regions during recovery Date: Fri, 17 Jul 2026 12:24:07 -0700 Message-ID: <20260717192408.109168-2-bestswngs@gmail.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260717192408.109168-1-bestswngs@gmail.com> References: <20260717192408.109168-1-bestswngs@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" Each recovered log item is assembled in xlog_recover_add_to_trans() into an ri_buf[] of ri_total (=3D the format's declared region count) slots, and the regions actually logged are counted in ri_cnt. Nothing checks that ri_cnt reached ri_total once the transaction is complete, so a crafted or truncated log can present an item whose format declares more regions than were logged. The trailing ri_buf[] slots are then NULL, and the reorder, readahead and replay code dereference them. For example, an XFS_LI_INODE item declaring two regions but logging only the format region leaves ri_buf[1] NULL, and mount-time recovery faults dereferencing it as the log dinode: KASAN: null-ptr-deref in range [0x0000000000000000-0x0000000000000007] RIP: xlog_recover_inode_commit_pass2 (fs/xfs/xfs_inode_item_recover.c:370) Call Trace: xlog_recover_items_pass2 (fs/xfs/xfs_log_recover.c:2011) xlog_recover_commit_trans (fs/xfs/xfs_log_recover.c:2078) xlog_recovery_process_trans (fs/xfs/xfs_log_recover.c:2328) xlog_recover_process_data (fs/xfs/xfs_log_recover.c:2502) xlog_recover (fs/xfs/xfs_log_recover.c:3486) xfs_log_mount (fs/xfs/xfs_log.c:667) xfs_mountfs (fs/xfs/xfs_mount.c:1039) xfs_fs_fill_super (fs/xfs/xfs_super.c:1965) get_tree_bdev_flags (fs/super.c:1680) __x64_sys_mount (fs/namespace.c:4433) Whether an item logged all its declared regions is a generic log format property, not a per-item-type concern, so reject any item with a missing region in xlog_recover_commit_trans() before the item ops run. Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2") Reported-by: Xiang Mei Suggested-by: Dave Chinner Assisted-by: Claude:claude-opus-4-8 Signed-off-by: Weiming Shi --- fs/xfs/xfs_log_recover.c | 11 +++++++++++ 1 file changed, 11 insertions(+) diff --git a/fs/xfs/xfs_log_recover.c b/fs/xfs/xfs_log_recover.c index 09e6678ca487..5250d512a392 100644 --- a/fs/xfs/xfs_log_recover.c +++ b/fs/xfs/xfs_log_recover.c @@ -2039,6 +2039,17 @@ xlog_recover_commit_trans( =20 hlist_del_init(&trans->r_list); =20 + /* + * Reject an item missing a region its format declared; the NULL slot + * would be dereferenced by the reorder and replay code. + */ + list_for_each_entry(item, &trans->r_itemq, ri_list) { + if (XFS_IS_CORRUPT(log->l_mp, + item->ri_total =3D=3D 0 || + item->ri_cnt !=3D item->ri_total)) + return -EFSCORRUPTED; + } + error =3D xlog_recover_reorder_trans(log, trans, pass); if (error) return error; --=20 2.43.0 From nobody Sat Jul 25 04:54:08 2026 Received: from mail-pj1-f46.google.com (mail-pj1-f46.google.com [209.85.216.46]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 00BC1378D71 for ; Fri, 17 Jul 2026 19:24:29 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.216.46 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784316273; cv=none; b=ebgCDoarGry1uNw+7sN55pnRRsyk0hZ4LCpjsAM5cgN15vSsxMTldXfy36xxfJyGbYK+uojlsNfjReVwg7CV2seX7xwEdE7CiI2vhmT0IJOuQea8snIJOBXoFJsyxwUpvJssClYp6K4bZZFEG+6oRgbewokjS1saJHNnZTTPwp8= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784316273; c=relaxed/simple; bh=EG69EPkO7N62BjoL+8oQ9HiwnjhLDWKjuYf3qchcwVM=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=NB7XWqTw7fqIGC2K229juHjq9P9HczIoD1q3nu4aoSx6f2njEL3jCYWR924JIIq4nZxoywyU1CyMaLwB63xb5YgiJjZG55jLMPrDlYUiACsIuG+sUwQpJaGf13s+XPMoyLwkmlVgGJu2zgLzpHwo7WrtVfu9S6Kv6BIhsbcoMeg= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=G0jR1IdH; arc=none smtp.client-ip=209.85.216.46 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="G0jR1IdH" Received: by mail-pj1-f46.google.com with SMTP id 98e67ed59e1d1-38e041ea211so5861019a91.0 for ; Fri, 17 Jul 2026 12:24:29 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1784316269; x=1784921069; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=DuWe98bSxDVP2YNkxgoDo5czOZmzPaVlyD3OHz/X3MY=; b=G0jR1IdHWs8zsjNPNtmZJj2davz4nQv3DKJgMTU/wr7jrspIaJvNtia2pcejcmGW25 6P+vEAuOdT94pks/ooVzmxZIaTTXQ42M7lHqJZeB486mz8VfugwuriUqO84AIbzAh51O v6W4tYx9CaZf9DdUQDGklr1FMZoWsq9d+9zvyFtT5DzWw29/eLLU7hMUt4YEnsuSFZDf Ou18qDY6fh296z5bdUwD7hbBzcbDl8lNzvj5BRTHFYf9YQDRBZ9j7OxBUqjFd01NC35a ip5P6MTmn4wYwZrUTb0GDsSBdh9zW7W3zLqwPP8fFAZ9LI/jW5gofN77rHAn05y243PV 8lgA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784316269; x=1784921069; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=DuWe98bSxDVP2YNkxgoDo5czOZmzPaVlyD3OHz/X3MY=; b=W3PjvhRQn+NGGCiTkMB1KQ4SiOi/9nzoVTRuilOSxfcTZ+alAaByPqqp5thS48i5wc 2E7EgjSng1xLWaeqwwb5Ywf31rqMjRpgn2EnX/Ztn8MtezCcCFGAeIxisuSSqon/CBfS YTt6XmO8ga1jxAN0Yc+mmZqqALS0PGGDx3PBhmv/ohuRGgFEOM8We831T0HxpOh5+eUG wQfzfK7UklS4lU4AEuGnhXmU6miRZ3vbsY3XX+zIRDGj1JRNbvOsLt6T94fBLOYezcP3 8QXKCMfFl8FK86/UJgGxFOSm6H73KoNNN1Dw73nRIkTFSzh016GeehghyTZNq/yeH2hb /slw== X-Forwarded-Encrypted: i=1; AHgh+RoGsF8B2Qqw0FBVbPynXA4KTcS9C/hl3HrEWa0os08iTdu1c/vLgc1siJRYKY3FRSx4B8IxlslrE9Dkvmw=@vger.kernel.org X-Gm-Message-State: AOJu0YwEqH6qcgz1EVrM4aj82d51duNXad3bITGyMQLQzGm4Nc5VFIEi vT2/Maarw8F418kv/6Cp1PwgrIhkFkjVSdrTcjXf398Glfak1ABvKPwQ X-Gm-Gg: AfdE7clJ9wp2pEJ6KI4Y3nrtZWJZR/C8TF4PYPfXjalDJR0csbe4UtV+lf9Ucg3vryo HpHGhntJJ/eSJhbI72TmpNe+9y5gJI3gsEPcmJnzasVPyJhyFaNgoaHWeaMTywLNUn3I4WF0qV8 h2bTRTm7kioVJJivN6t7+7MP6y5NvWpLWkLqgX/m3VlRvn2GFNHk2Wf348Gk+nUv5ODzQ0LEy1H kDKgA3p620ZjEcUFMpRyp5Yna1iGClX7p6IaQttfQFyn1m+DAzW3C5/LLH/v+K99F5ayV1/WAOZ bkylUxe8+F48gqlh4GVYbHGoqsy93Pmedy+qFcLOdT/SNzZ5kvXmQaPkGU5zkNsr5ec6zn4GFlx Wx+HlPaOY9idTewxLOeQ8nwaar9ZkGICGIT+lmTdCIrGMix8Ibw1QWp7m7Rv1kjV/ytluSgjS8r 4lDZI3RwimUmaFURfRFWC72vgigSVU5yME6WjyjVg1SkkwlLs= X-Received: by 2002:a17:90a:dfcc:b0:366:3517:1aa2 with SMTP id 98e67ed59e1d1-38e4b24d8ddmr4182562a91.0.1784316269321; Fri, 17 Jul 2026 12:24:29 -0700 (PDT) Received: from fx.tailc0aff1.ts.net ([206.206.192.132]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-3142a1dde81sm18648783eec.21.2026.07.17.12.24.27 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Fri, 17 Jul 2026 12:24:28 -0700 (PDT) From: Weiming Shi To: Carlos Maiolino , "Darrick J . Wong" Cc: linux-xfs@vger.kernel.org, linux-kernel@vger.kernel.org, xmei5@asu.edu, Weiming Shi , Dave Chinner Subject: [PATCH v2 2/2] xfs: verify recovered inode log items in pass1 Date: Fri, 17 Jul 2026 12:24:08 -0700 Message-ID: <20260717192408.109168-3-bestswngs@gmail.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260717192408.109168-1-bestswngs@gmail.com> References: <20260717192408.109168-1-bestswngs@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" Log recovery mixes validation of a recovered inode item's formatted structures into the pass2 decode and replay code, one open-coded check at a time. That is hard to read and audit for what is still unchecked, and it runs after the item has already been sorted and read ahead in earlier passes. Add a verifier layer to journal recovery: a new xlog_recover_item_ops->verify() method that validates an item's formatted log structures, called in pass1 for every item after the generic region checks. Add the first verifier, for inode items: xlog_recover_inode_verify() checks in one place that the core and each fork region implied by ilf_fields is declared, that the log dinode is present and large enough, that its version matches the mount, that di_forkoff is within the literal area, and that the verbatim-copied fork regions fit their destination fork. Because those log dinode checks now run in pass1, drop the equivalent open-coded checks (the log dinode magic and the dead di_forkoff bound) from xlog_recover_inode_commit_pass2(). The checks that need the on-disk inode buffer (its magic, the LSN and di_flushiter replay-ordering decisions, the di_mode/di_format consistency, and the final xfs_dinode_verify()) cannot be hoisted and stay in pass2. This only covers the self-contained log dinode structure. The btree-root fork formats are converted from a larger in-core form on replay and their record count is not yet bounded here; clamping xfs_bmbt_to_bmdr() and the rt btree converters against the destination fork is left as follow-up. Further item types can grow their own verify() method the same way. Suggested-by: Dave Chinner Assisted-by: Claude:claude-opus-4-8 Signed-off-by: Weiming Shi --- fs/xfs/libxfs/xfs_log_recover.h | 3 ++ fs/xfs/xfs_inode_item_recover.c | 87 +++++++++++++++++++++++++++------ fs/xfs/xfs_log_recover.c | 5 ++ 3 files changed, 79 insertions(+), 16 deletions(-) diff --git a/fs/xfs/libxfs/xfs_log_recover.h b/fs/xfs/libxfs/xfs_log_recove= r.h index 9e712e62369c..327a4a9c5fbe 100644 --- a/fs/xfs/libxfs/xfs_log_recover.h +++ b/fs/xfs/libxfs/xfs_log_recover.h @@ -33,6 +33,9 @@ struct xlog_recover_item_ops { */ enum xlog_recover_reorder (*reorder)(struct xlog_recover_item *item); =20 + /* Validate the item's log structures in pass1, if provided. */ + int (*verify)(struct xlog *log, struct xlog_recover_item *item); + /* Start readahead for pass2, if provided. */ void (*ra_pass2)(struct xlog *log, struct xlog_recover_item *item); =20 diff --git a/fs/xfs/xfs_inode_item_recover.c b/fs/xfs/xfs_inode_item_recove= r.c index 169a8fe3bf0a..277267f722aa 100644 --- a/fs/xfs/xfs_inode_item_recover.c +++ b/fs/xfs/xfs_inode_item_recover.c @@ -367,13 +367,6 @@ xlog_recover_inode_commit_pass2( goto out_release; } ldip =3D item->ri_buf[1].iov_base; - if (XFS_IS_CORRUPT(mp, ldip->di_magic !=3D XFS_DINODE_MAGIC)) { - xfs_alert(mp, - "%s: Bad inode log record, rec ptr "PTR_FMT", ino %lld", - __func__, item, in_f->ilf_ino); - error =3D -EFSCORRUPTED; - goto out_release; - } =20 /* * If the inode has an LSN in it, recover the inode only if the on-disk @@ -462,15 +455,6 @@ xlog_recover_inode_commit_pass2( if (error) goto out_release; =20 - if (unlikely(ldip->di_forkoff > mp->m_sb.sb_inodesize)) { - XFS_CORRUPTION_ERROR("Bad log dinode fork offset", - XFS_ERRLEVEL_LOW, mp, ldip, sizeof(*ldip)); - xfs_alert(mp, - "Bad inode 0x%llx, di_forkoff 0x%x", - in_f->ilf_ino, ldip->di_forkoff); - error =3D -EFSCORRUPTED; - goto out_release; - } isize =3D xfs_log_dinode_size(mp); if (unlikely(item->ri_buf[1].iov_len > isize)) { XFS_CORRUPTION_ERROR("Bad log dinode size", XFS_ERRLEVEL_LOW, @@ -597,8 +581,79 @@ xlog_recover_inode_commit_pass2( return error; } =20 +/* + * Validate an inode log item's log dinode structure in pass1 so pass2 need + * not re-check it; buffer-dependent checks stay in pass2. + */ +STATIC int +xlog_recover_inode_verify( + struct xlog *log, + struct xlog_recover_item *item) +{ + struct xfs_mount *mp =3D log->l_mp; + struct xfs_inode_log_format *in_f; + struct xfs_inode_log_format in_f_buf; + struct xfs_log_dinode *ldip; + unsigned int litino =3D XFS_LITINO(mp); + unsigned int dsize, asize; + int attr_index; + int error; + + if (item->ri_buf[0].iov_len =3D=3D sizeof(struct xfs_inode_log_format)) { + in_f =3D item->ri_buf[0].iov_base; + } else { + in_f =3D &in_f_buf; + error =3D xfs_inode_item_format_convert(&item->ri_buf[0], in_f); + if (error) + return error; + } + + /* The inode core is always logged as the log dinode in ri_buf[1]. */ + if (XFS_IS_CORRUPT(mp, in_f->ilf_size < 2) || + XFS_IS_CORRUPT(mp, + item->ri_buf[1].iov_len < xfs_log_dinode_size(mp))) + return -EFSCORRUPTED; + + ldip =3D item->ri_buf[1].iov_base; + if (XFS_IS_CORRUPT(mp, ldip->di_magic !=3D XFS_DINODE_MAGIC) || + XFS_IS_CORRUPT(mp, !xfs_dinode_good_version(mp, ldip->di_version)) || + XFS_IS_CORRUPT(mp, ldip->di_forkoff >=3D (litino >> 3))) + return -EFSCORRUPTED; + + if (ldip->di_forkoff) { + dsize =3D ldip->di_forkoff << 3; + asize =3D litino - (ldip->di_forkoff << 3); + } else { + dsize =3D litino; + asize =3D 0; + } + + /* + * Btree-root forks are logged in a larger in-core form and converted on + * replay, so their region is not bounded by the on-disk fork size here. + */ + if (in_f->ilf_fields & XFS_ILOG_DFORK) { + if (XFS_IS_CORRUPT(mp, in_f->ilf_size < 3)) + return -EFSCORRUPTED; + if ((in_f->ilf_fields & XFS_ILOG_DFORK) !=3D XFS_ILOG_DBROOT && + XFS_IS_CORRUPT(mp, item->ri_buf[2].iov_len > dsize)) + return -EFSCORRUPTED; + } + if (in_f->ilf_fields & XFS_ILOG_AFORK) { + attr_index =3D (in_f->ilf_fields & XFS_ILOG_DFORK) ? 3 : 2; + if (XFS_IS_CORRUPT(mp, in_f->ilf_size < attr_index + 1)) + return -EFSCORRUPTED; + if ((in_f->ilf_fields & XFS_ILOG_AFORK) !=3D XFS_ILOG_ABROOT && + XFS_IS_CORRUPT(mp, item->ri_buf[attr_index].iov_len > asize)) + return -EFSCORRUPTED; + } + + return 0; +} + const struct xlog_recover_item_ops xlog_inode_item_ops =3D { .item_type =3D XFS_LI_INODE, + .verify =3D xlog_recover_inode_verify, .ra_pass2 =3D xlog_recover_inode_ra_pass2, .commit_pass2 =3D xlog_recover_inode_commit_pass2, }; diff --git a/fs/xfs/xfs_log_recover.c b/fs/xfs/xfs_log_recover.c index 5250d512a392..252e7f5cbd47 100644 --- a/fs/xfs/xfs_log_recover.c +++ b/fs/xfs/xfs_log_recover.c @@ -2059,6 +2059,11 @@ xlog_recover_commit_trans( =20 switch (pass) { case XLOG_RECOVER_PASS1: + if (item->ri_ops->verify) { + error =3D item->ri_ops->verify(log, item); + if (error) + break; + } if (item->ri_ops->commit_pass1) error =3D item->ri_ops->commit_pass1(log, item); break; --=20 2.43.0