From nobody Fri Jul 24 23:30:21 2026 Received: from mail-pj1-f54.google.com (mail-pj1-f54.google.com [209.85.216.54]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id C33F4379960 for ; Wed, 22 Jul 2026 09:12:13 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.216.54 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784711535; cv=none; b=CMkPym82xqmCqcVjH/CEnajteFVjVH7+eiSpaBFsFuFILxFOS+yKvws5E6t4QUtUSZQ0JPkHRUG7mNMHTNuySSipu+u1rjCDlwwRVB+aC7tUjBYQ+e+8pN4lI4upfZAwCDelh2jYgcaHIDjlsIRRebBDOH51aq+xY15D6xf5P5Q= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784711535; c=relaxed/simple; bh=xyRey8pJutA6bz3H1QdoAYJt24UmHPBc7BSHwZnKDi0=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=J0r+uVe6ICE4tEbJe4mfnVxG61+JqrAMEE8nLr/50ESCIlaGP0IFK+VinvEO3yASNf7ZOsFJNNQ4mBztz4cGMuDmMnMPzVnyHBYFRvqB/BnivdF5k95h+IT+CXNhte9yAnuo7NNpZxvStUEcP03ZhAQVgY7Y/W/TdeTalRXjjd4= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=pvBTUVSG; arc=none smtp.client-ip=209.85.216.54 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="pvBTUVSG" Received: by mail-pj1-f54.google.com with SMTP id 98e67ed59e1d1-38dfe7eb825so7021367a91.0 for ; Wed, 22 Jul 2026 02:12:13 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1784711533; x=1785316333; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to:content-type; bh=e1BMRVa7z2PH8dIeiN6LIuLzoxgSG7lKiacNnhAzQbU=; b=pvBTUVSGXVQUQD0OxQHDwmBcxj1jqInXpiPL9q4luY6aHhXrSueTVbPXpdBxWPvJrv VHGBsuVsesoCEhhXSSZfBo8uFiCb+fJdrN3VPpTslZZ/w4JCifSk6kI/qYKHdqeccxIB 5gduZ4QPjgkZB87M2Rnx0X/1uWwVJxkkOsxf/LkZ+txvgZ9PMTn9xmYPlB1m6mEwE/yL lITY1ZF0TbunuOIgRQ5WnPHih7JOrICrUN3dOCewasSWndzGxQyNwDCSDmkHYHpqFO5L 7G4HMGfJwnz/qZBiO9DbpEE7Wr/YxhkCxLBFK71TF/UokkDS8at3NQ9QITznQ2p6rY76 Jbpg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784711533; x=1785316333; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=e1BMRVa7z2PH8dIeiN6LIuLzoxgSG7lKiacNnhAzQbU=; b=hRysqQQRj2FKTp+zWdXpKgjd6knj+x4IoKTuJ1rsm52o+tlMVMmCmZznT3fzICWWOY FoXK0ikZQaafNmqUO8LUtoNy2tQaEvLtdfw2RX0d+2yB12Rj/vGAYdi2qXjT/DljhU3C 4dNgLgd/VUV2vcBiqgACzw7EBmAe2ZWS6yspsDHQw0gUebIUy6mRz8G7Kq6H3HAcdrp8 sEjqH9Vsw9ArTRP88WUBkkI+4Hx8TT37J0eTx3HEf0vcaZbYlJZdAhsrd9yNUUGFI22I TSKjweYDX3UmAt6aha+MMQobWKeIeCNoaTlVzYGreYcsdaz/xYhLCeobhIxesNa0oPS4 QZQA== X-Forwarded-Encrypted: i=1; AHgh+RphlrRMjbICeIi5WDrHOzd0UqhAtf9Y87omAm6Sc/touty2l2k1kfzeGc3FbqT6F9EERmpp2LFeRkAyjaI=@vger.kernel.org X-Gm-Message-State: AOJu0YzURY+37HJh51BaV6PDQra9g10oYr88qiSAzSIYW0gmAxv3z4Z5 IVfiZcCvRO6PU3aZWVN5tBayln/zKPfL/6HQjo8xQIUR+0k7KWrhVf7J X-Gm-Gg: AR+sD10KIH52L973DlmQ7BGlGFsLj4ltlVuJFPOOHwm5+vsN0ToWnv3JTxeRaVh60BW B8XXA87duOJgOMlB76Ew1PxnQnseKhuvF3TTE+Wp+4yXpUFYWEh45q9Pj2/F4B9Og6VaFh0mjLL XUkpT/r3rQVEvrqoNnRavcs/vRPhBpf61uq5+2HZMh154kTfGH0UStvzLPqqEGXZdanQW1HI9e0 fRp//oIywPCzWnYn8w3jLFQO0YehOKFlMPv0J4b7oMiFKn9AA3WgKFDN04bLttmA3TOs1994zA3 lNqU4+QFqqCuCziOEqDjkS2wg6heY8NMLHU5g4/kveLFOUFGRczIPXBNBM4rHCCBtyF98mvNUUs ZBIFUu+MFrc9xuFpvcuJTMIQAPZRhef6GZ0JxYWdg6SvNADWJrIgPqEFye5TGFkNAlxw6yR84N7 o1sdNU4AeOmVUvaBhg64adfwFAuAJ8lVnHpod00mX17oM= X-Received: by 2002:a17:90b:2c85:b0:381:28e0:6259 with SMTP id 98e67ed59e1d1-38e4b3d14cemr22448196a91.9.1784711532855; Wed, 22 Jul 2026 02:12:12 -0700 (PDT) Received: from gmail.com ([138.199.21.246]) by smtp.gmail.com with ESMTPSA id 98e67ed59e1d1-38e92169cebsm3031245a91.11.2026.07.22.02.12.07 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 22 Jul 2026 02:12:12 -0700 (PDT) From: ZhengYuan Huang To: mark@fasheh.com, jlbec@evilplan.org, joseph.qi@linux.alibaba.com Cc: ocfs2-devel@lists.linux.dev, linux-kernel@vger.kernel.org, baijiaju1990@gmail.com, r33s3n6@gmail.com, zzzccc427@gmail.com, tom442288@tuta.io, ZhengYuan Huang Subject: [PATCH] ocfs2: validate truncate log dinode before caching Date: Wed, 22 Jul 2026 17:11:57 +0800 Message-ID: <20260722091157.3141414-1-gality369@gmail.com> X-Mailer: git-send-email 2.43.0 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" [BUG] A corrupted truncate log dinode can pass through mount initialization and reach the delayed flush worker, where it triggers: kernel BUG at fs/ocfs2/alloc.c:6019! Oops: invalid opcode: 0000 [#1] SMP KASAN NOPTI RIP: 0010:__ocfs2_flush_truncate_log+0xa87/0xf10 fs/ocfs2/alloc.c:6019 Call Trace: ocfs2_flush_truncate_log fs/ocfs2/alloc.c:6084 [inline] ocfs2_truncate_log_worker+0xa9/0x180 fs/ocfs2/alloc.c:6097 process_one_work+0x8e0/0x1980 kernel/workqueue.c:3263 ... [CAUSE] ocfs2_get_truncate_log_info() assumes that ocfs2_read_inode_block() always validates the returned dinode. However, ocfs2_read_blocks() skips the validation callback for JBD-managed buffers. The function then reads truncate log fields and exposes the invalid buffer to callers, allowing ocfs2_truncate_log_init() to retain it in osb->osb_tl_bh. [FIX] Check the dinode signature in ocfs2_get_truncate_log_info() immediately after the inode read. Reject an invalid dinode as filesystem corruption before reading truncate log fields or returning the inode and buffer to the caller. This keeps invalid state out of the long-lived truncate log cache and preserves the validated-buffer invariant in append, flush, and recovery paths. Fixes: 10995aa2451a ("ocfs2: Morph the haphazard OCFS2_IS_VALID_DINODE() ch= ecks.") Assisted-by: Codex:gpt-5.6-sol Signed-off-by: ZhengYuan Huang --- fs/ocfs2/alloc.c | 13 +++++++++++++ 1 file changed, 13 insertions(+) diff --git a/fs/ocfs2/alloc.c b/fs/ocfs2/alloc.c index be09e766ac1f..e36ae2e522d3 100644 --- a/fs/ocfs2/alloc.c +++ b/fs/ocfs2/alloc.c @@ -6192,6 +6192,19 @@ static int ocfs2_get_truncate_log_info(struct ocfs2_= super *osb, } =20 di =3D (struct ocfs2_dinode *)bh->b_data; + /* + * A JBD-managed buffer may skip the read validation callback. Check + * the signature before exposing the truncate log to callers. + */ + if (!OCFS2_IS_VALID_DINODE(di)) { + status =3D ocfs2_error(osb->sb, + "Invalid truncate log dinode #%llu\n", + (unsigned long long)bh->b_blocknr); + iput(inode); + brelse(bh); + goto bail; + } + tl =3D &di->id2.i_dealloc; tl_count =3D le16_to_cpu(tl->tl_count); tl_used =3D le16_to_cpu(tl->tl_used); --=20 2.43.0