From nobody Fri Jul 24 05:21:41 2026 Received: from mail-pf1-f171.google.com (mail-pf1-f171.google.com [209.85.210.171]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 4E1DA3CA497 for ; Thu, 23 Jul 2026 06:39:20 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.210.171 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784788762; cv=none; b=o2PoHsKojhxyOBnLC6cVwLdZkmBF1JRuadU5bc+KLtOmhX/kEGxHgUKC8KVL+e4XQo7U0/VaVs8PbRB+yWUYImnMYz7Y1Dj5sh7XEJe3c0w+k+DVNTaTjnQ3+qjv1HpPMcEGLeeDoDPttdXwMYgBBk7gXvwwYSDXwuvWqFLMsGM= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784788762; c=relaxed/simple; bh=/0HwtvNp/9LvmQragxj3efo4Ptadjv76oHlqVj9EYjg=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=GbWwVzYcG13Xz1vs88fyxrRvDknUzecJTKbAyPYCcc2LgYKmq/op/hyG6rTFWaHlwPHL9iZ+O8rOLzO0ehMvsdSzw6VTR9Z+cw090BeWU8LnblCsffMuJPFj5SGHfPrIp5tFkNQCxqgz6r96ygEx/5hIt0S7/+RdXULRdf2FoVg= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=n454Wbvd; arc=none smtp.client-ip=209.85.210.171 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="n454Wbvd" Received: by mail-pf1-f171.google.com with SMTP id d2e1a72fcca58-84830c774a0so286047b3a.1 for ; Wed, 22 Jul 2026 23:39:20 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1784788760; x=1785393560; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=uDhsKqXuqVQPpqbwNUDTPQFZ//zpU3w2f5MZYDjLQvg=; b=n454Wbvde9YsQK6ZW5NzRWWiLPW87okr/kwuMbIhZBitBH8UqOBkLoFm+mrMaOw4nZ DMdZxSzFYA/d0+KCl2qJK9lcyOe/BHp+ccNPoFLZBe86yC3PVF7QSbv2CjGjyHYWmiZ6 dN77FIUF3vjU+6EllMxhT1H04NthN3h9Erfvjm8/3Gks/OJp2TT/Vek2tDbnuBo8x0DY cOhek0v4LDF0KpFXejVPtXdfgflgvFJFc3rxOMY6oQQ+td6CrCEzv+MVFGZBordv619r lMSY/Sv+/LHS184WOuTM0jTVaBzBOjuVxhfT8aZeMSV6kvELiDAFeZdefh+DcjLkliVd hNKw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784788760; x=1785393560; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=uDhsKqXuqVQPpqbwNUDTPQFZ//zpU3w2f5MZYDjLQvg=; b=WAwjG6eRNtjMZfHuAKzcUdWGXLw6FmDhaau8t51utWXzjzo8S391wj4jHa0l4HOZhc xEaN95F3xn/w5zQGl1Yopo7N8fuP1g9yaILIWrXBlgtXIn9rkzh+KYk6J1tY0ApYYHo0 VHsj47ZSGo59WH1OIZTzSmsIWottmrNPSr88T/bylprjfTpGyxwfQZQjKeMwzmwy4rRg 9awlCclEh3ozgNJinQ1tmadbE8HAMcjYuXDedf38xHJEyvyGrGMAzV43DKEk3vRd3pij 2X27Nw0fFkMVHWBFXdChLQtVb5yej2JOfDE9rbO6p3hqqkHrUMpR4P7UBL5daZUEnBH7 By+w== X-Forwarded-Encrypted: i=1; AHgh+RouFfa0PflmCHbdLInitxjW6frraOFhRJnBII5IOMXA/pnbS4EicgBp14fr6vRoOj+OEe8L0811tOLYqZw=@vger.kernel.org X-Gm-Message-State: AOJu0YwZgtJrXSIJIhWGbPD4UkRt61sQfscRkGuLoFCiCPD9HhNSGlYn DydJS60Q1T5l6ZrgkkdMnd0SlWRL+zRNuaF0mCuXenVa+M9i9+2yR8t8 X-Gm-Gg: AR+sD134HtXDKshN7W1rrqL0rXu4A7npioGO+/8t2XbOtC0HYllXEWspMexwU/0iebi 6eJSgU/nk/qbKpUdeBEdhcSvMURCATEos45sNFOFt1lej1PhodPdz7UMRTj0N08/7wqy+mKMsU/ 6FjGUy5+5jquJdd/gahXSny+Zn2lbSC2S0hO8cXJckmLErG0ktHM7CfVNO58mmv4pjbyX/kLDhy ZKjRACquqJuFFz9v6UWPDbgy801SXXI5toyNFzyKdvesEUVGEFVChBu1Oj5+gnc+7UIiM5Db/rI 4xUpTNSWpnUvLK+02OlZA/AGwSBOcjLxKO7RQIFMT4kGOf/VjrcqgNdXDMWWCI7ExMsPM6ZmSCn 4JdVSW17c8uRvxvS92dPlAyvMirrYYiH28ccNNIJHnUccUtXE7YDRwVj28D2cpcd33P16esKGea Uj3zyj9pIfNB463dD1hRR6wwQ= X-Received: by 2002:a05:6a00:a229:b0:847:94bb:30db with SMTP id d2e1a72fcca58-84e2bb37412mr2405755b3a.49.1784788759316; Wed, 22 Jul 2026 23:39:19 -0700 (PDT) Received: from ustb520lab-MS-7E07.. ([115.25.44.221]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-84e17574784sm2507076b3a.35.2026.07.22.23.39.16 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 22 Jul 2026 23:39:18 -0700 (PDT) From: Jiaming Zhang To: slava@dubeyko.com Cc: frank.li@vivo.com, glaubitz@physik.fu-berlin.de, linux-fsdevel@vger.kernel.org, linux-kernel@vger.kernel.org, r772577952@gmail.com, syzkaller@googlegroups.com Subject: [PATCH v4] hfsplus: validate B-tree record offset table Date: Thu, 23 Jul 2026 14:39:10 +0800 Message-ID: <20260723063910.765543-1-r772577952@gmail.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <3d0cb82335583659fa6d044bcf4b8083907712bc.camel@dubeyko.com> References: <3d0cb82335583659fa6d044bcf4b8083907712bc.camel@dubeyko.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" A crafted HFS+ image can contain a corrupted B-tree node. The node descript= or may contain a record count that does not fit in the node, and record offset= s may be unordered, unaligned, outside the node, or point into the offset table itself. Several B-tree helpers consume these on-disk fields before validating them: hfs_bnode_dump() can walk past the offset table when num_recs is corrupted, hfs_brec_lenoff() can produce an underflowed length or a record range that overlaps the offset table. This can make the unlink/writeback path repeated= ly call hfs_bnode_read_u16() with invalid offsets while holding the HFS+ B-tree lock, producing a flood of "requested invalid offset" messages. Other write= back workers then block on tree->tree_lock and the system reports tasks hung in hfsplus_write_inode(). Validate num_recs against the node size before walking the record offset ta= ble. Reject record ranges that are unordered, unaligned, outside the node, or overlapping the offset table. Reject invalid record indexes before reading = their offset entries, and avoid decrementing an already-zero leaf_count. --- Changes in v4: - Rename hfs_find_reset() to hfs_find_result_init(). - Reset find result fields in __hfs_brec_find(). - Move num_recs validation next to descriptor field initialization. - Rename hfs_brec_range_valid() to hfs_brec_offpair_valid(). - Use U16_MAX for invalid offset/len/keylen sentinels and update callers. - Add hfs_brec_len_valid() to check validity of len/keylen. - Handle invalid B-tree map record lengths in hfs_bmap_get_map_page() and hfs_bmap_free(). - Return -EINVAL instead of -EIO for invalid remove cursor/leaf_count state. Changes in v3: - Drop the keylen =3D=3D len check. - Drop the explicit zero-record check in __hfs_brec_find(). - Move find cursor reset into hfs_find_reset() and call it from hfs_find_in= it() and hfs_brec_find(). - Rename helper-local variables as suggested. fs/hfsplus/bfind.c | 21 +++++------ fs/hfsplus/bnode.c | 16 ++++++--- fs/hfsplus/brec.c | 43 ++++++++++++++-------- fs/hfsplus/btree.c | 11 ++++++ fs/hfsplus/hfsplus_fs.h | 79 +++++++++++++++++++++++++++++++++++++++++ 5 files changed, 142 insertions(+), 28 deletions(-) diff --git a/fs/hfsplus/bfind.c b/fs/hfsplus/bfind.c index 9a55fa6d5294..301e653f029d 100644 --- a/fs/hfsplus/bfind.c +++ b/fs/hfsplus/bfind.c @@ -9,6 +9,7 @@ * Search routines for btrees */ =20 +#include #include #include "hfsplus_fs.h" =20 @@ -18,6 +19,7 @@ int hfs_find_init(struct hfs_btree *tree, struct hfs_find= _data *fd) =20 fd->tree =3D tree; fd->bnode =3D NULL; + hfs_find_result_init(fd); ptr =3D kzalloc(tree->max_key_len * 2 + 4, GFP_KERNEL); if (!ptr) return -ENOMEM; @@ -106,17 +108,20 @@ int __hfs_brec_find(struct hfs_bnode *bnode, struct h= fs_find_data *fd, u16 off, len, keylen; int rec; int b, e; - int res; + int res =3D -ENOENT; =20 BUG_ON(!rec_found); + hfs_find_result_init(fd); + if (!hfs_bnode_num_recs_valid(bnode)) + goto fail; + b =3D 0; e =3D bnode->num_recs - 1; - res =3D -ENOENT; do { rec =3D (e + b) / 2; len =3D hfs_brec_lenoff(bnode, rec, &off); keylen =3D hfs_brec_keylen(bnode, rec); - if (keylen =3D=3D 0) { + if (!hfs_brec_len_valid(len) || !hfs_brec_len_valid(keylen)) { res =3D -EINVAL; goto fail; } @@ -130,7 +135,7 @@ int __hfs_brec_find(struct hfs_bnode *bnode, struct hfs= _find_data *fd, if (rec !=3D e && e >=3D 0) { len =3D hfs_brec_lenoff(bnode, e, &off); keylen =3D hfs_brec_keylen(bnode, e); - if (keylen =3D=3D 0) { + if (!hfs_brec_len_valid(keylen) || !hfs_brec_len_valid(len)) { res =3D -EINVAL; goto fail; } @@ -158,11 +163,7 @@ int hfs_brec_find(struct hfs_find_data *fd, search_str= ategy_t do_key_compare) __be32 data; int height, res; =20 - fd->record =3D -1; - fd->keyoffset =3D -1; - fd->keylength =3D -1; - fd->entryoffset =3D -1; - fd->entrylength =3D -1; + hfs_find_result_init(fd); =20 tree =3D fd->tree; if (fd->bnode) @@ -274,7 +275,7 @@ int hfs_brec_goto(struct hfs_find_data *fd, int cnt) =20 len =3D hfs_brec_lenoff(bnode, fd->record, &off); keylen =3D hfs_brec_keylen(bnode, fd->record); - if (keylen =3D=3D 0) { + if (!hfs_brec_len_valid(len) || !hfs_brec_len_valid(keylen)) { res =3D -EINVAL; goto out; } diff --git a/fs/hfsplus/bnode.c b/fs/hfsplus/bnode.c index d088fb7eb0df..e5babf3a03b7 100644 --- a/fs/hfsplus/bnode.c +++ b/fs/hfsplus/bnode.c @@ -352,15 +352,22 @@ void hfs_bnode_dump(struct hfs_bnode *node) struct hfs_bnode_desc desc; __be32 cnid; int i, off, key_off; + u16 num_recs; =20 hfs_dbg("node %d\n", node->this); hfs_bnode_read(node, &desc, 0, sizeof(desc)); + num_recs =3D node->num_recs; hfs_dbg("next %d, prev %d, type %d, height %d, num_recs %d\n", be32_to_cpu(desc.next), be32_to_cpu(desc.prev), desc.type, desc.height, be16_to_cpu(desc.num_recs)); =20 + if (!hfs_bnode_num_recs_valid(node)) { + hfs_dbg("invalid num_recs %u\n", num_recs); + return; + } + off =3D node->tree->node_size - 2; - for (i =3D be16_to_cpu(desc.num_recs); i >=3D 0; off -=3D 2, i--) { + for (i =3D num_recs; i >=3D 0; off -=3D 2, i--) { key_off =3D hfs_bnode_read_u16(node, off); hfs_dbg(" key_off %d", key_off); if (i && node->type =3D=3D HFS_NODE_INDEX) { @@ -561,6 +568,9 @@ struct hfs_bnode *hfs_bnode_find(struct hfs_btree *tree= , u32 num) node->height =3D desc->height; kunmap_local(desc); =20 + if (!hfs_bnode_num_recs_valid(node)) + goto node_error; + switch (node->type) { case HFS_NODE_HEADER: case HFS_NODE_MAP: @@ -586,9 +596,7 @@ struct hfs_bnode *hfs_bnode_find(struct hfs_btree *tree= , u32 num) for (i =3D 1; i <=3D node->num_recs; off =3D next_off, i++) { rec_off -=3D 2; next_off =3D hfs_bnode_read_u16(node, rec_off); - if (next_off <=3D off || - next_off > tree->node_size || - next_off & 1) + if (!hfs_brec_offpair_valid(node, off, next_off, rec_off)) goto node_error; entry_size =3D next_off - off; if (node->type !=3D HFS_NODE_INDEX && diff --git a/fs/hfsplus/brec.c b/fs/hfsplus/brec.c index e3df89284079..42cc09aca80e 100644 --- a/fs/hfsplus/brec.c +++ b/fs/hfsplus/brec.c @@ -9,6 +9,8 @@ * Handle individual btree records */ =20 +#include + #include "hfsplus_fs.h" #include "hfsplus_raw.h" =20 @@ -20,41 +22,49 @@ static int hfs_btree_inc_height(struct hfs_btree *); u16 hfs_brec_lenoff(struct hfs_bnode *node, u16 rec, u16 *off) { __be16 retval[2]; - u16 dataoff; + u16 data_off; + u16 next_off; + + if (!hfs_brec_record_valid(node, rec)) { + *off =3D U16_MAX; + return U16_MAX; + } =20 - dataoff =3D node->tree->node_size - (rec + 2) * 2; - hfs_bnode_read(node, retval, dataoff, 4); + data_off =3D node->tree->node_size - (rec + 2) * 2; + hfs_bnode_read(node, retval, data_off, 4); *off =3D be16_to_cpu(retval[1]); - return be16_to_cpu(retval[0]) - *off; + next_off =3D be16_to_cpu(retval[0]); + if (!hfs_brec_offpair_valid(node, *off, next_off, data_off)) { + *off =3D U16_MAX; + return U16_MAX; + } + return next_off - *off; } =20 /* Get the length of the key from a keyed record */ u16 hfs_brec_keylen(struct hfs_bnode *node, u16 rec) { - u16 retval, recoff; + u16 retval, recoff, len; =20 if (node->type !=3D HFS_NODE_INDEX && node->type !=3D HFS_NODE_LEAF) return 0; + if (!hfs_brec_record_valid(node, rec)) + return U16_MAX; =20 if ((node->type =3D=3D HFS_NODE_INDEX) && !(node->tree->attributes & HFS_TREE_VARIDXKEYS) && (node->tree->cnid !=3D HFSPLUS_ATTR_CNID)) { retval =3D node->tree->max_key_len + 2; } else { - recoff =3D hfs_bnode_read_u16(node, - node->tree->node_size - (rec + 1) * 2); - if (!recoff) - return 0; - if (recoff > node->tree->node_size - 2) { - pr_err("recoff %d too large\n", recoff); - return 0; - } + len =3D hfs_brec_lenoff(node, rec, &recoff); + if (!hfs_brec_len_valid(len)) + return len; =20 retval =3D hfs_bnode_read_u16(node, recoff) + 2; if (retval > node->tree->max_key_len + 2) { pr_err("keylen %d too large\n", retval); - retval =3D 0; + retval =3D U16_MAX; } } return retval; @@ -185,10 +195,15 @@ int hfs_brec_remove(struct hfs_find_data *fd) tree =3D fd->tree; node =3D fd->bnode; again: + if (!hfs_brec_record_valid(node, fd->record)) + return -EINVAL; + rec_off =3D tree->node_size - (fd->record + 2) * 2; end_off =3D tree->node_size - (node->num_recs + 1) * 2; =20 if (node->type =3D=3D HFS_NODE_LEAF) { + if (tree->leaf_count =3D=3D 0) + return -EINVAL; tree->leaf_count--; mark_inode_dirty(tree->inode); } diff --git a/fs/hfsplus/btree.c b/fs/hfsplus/btree.c index 394542a47e60..85ba6cf1a803 100644 --- a/fs/hfsplus/btree.c +++ b/fs/hfsplus/btree.c @@ -12,6 +12,7 @@ #include #include #include +#include =20 #include "hfsplus_fs.h" #include "hfsplus_raw.h" @@ -168,6 +169,8 @@ static struct page *hfs_bmap_get_map_page(struct hfs_bn= ode *node, } =20 ctx->len =3D hfs_brec_lenoff(node, rec_idx, &off16); + if (ctx->len =3D=3D U16_MAX) + return ERR_PTR(-EINVAL); if (!ctx->len) return ERR_PTR(-ENOENT); =20 @@ -622,6 +625,10 @@ void hfs_bmap_free(struct hfs_bnode *node) if (IS_ERR(node)) return; len =3D hfs_brec_lenoff(node, 2, &off); + if (!hfs_brec_len_valid(len)) { + hfs_bnode_put(node); + return; + } while (nidx >=3D len * 8) { u32 i; =20 @@ -648,6 +655,10 @@ void hfs_bmap_free(struct hfs_bnode *node) return; } len =3D hfs_brec_lenoff(node, 0, &off); + if (!hfs_brec_len_valid(len)) { + hfs_bnode_put(node); + return; + } } =20 res =3D hfs_bmap_clear_bit(node, nidx); diff --git a/fs/hfsplus/hfsplus_fs.h b/fs/hfsplus/hfsplus_fs.h index ec04b82ad927..41d1e24309d4 100644 --- a/fs/hfsplus/hfsplus_fs.h +++ b/fs/hfsplus/hfsplus_fs.h @@ -16,6 +16,7 @@ #include #include #include +#include #include "hfsplus_raw.h" =20 /* Runtime config options */ @@ -587,6 +588,84 @@ bool is_bnode_offset_valid(struct hfs_bnode *node, u32= off) return is_valid; } =20 +static inline +bool hfs_bnode_num_recs_valid(struct hfs_bnode *node) +{ + u32 node_size; + u32 table_size; + u32 area_size; + u32 rec_size =3D sizeof(__be16); + u32 desc_size =3D sizeof(struct hfs_bnode_desc); + + if (!node || !node->tree) + return false; + + node_size =3D node->tree->node_size; + if (node_size < desc_size) + return false; + + area_size =3D node_size - desc_size; + table_size =3D ((u32)node->num_recs + 1) * rec_size; + + return table_size <=3D area_size; +} + +static inline +bool hfs_brec_record_valid(struct hfs_bnode *node, int record) +{ + if (!hfs_bnode_num_recs_valid(node)) + return false; + if (record < 0) + return false; + + return record < node->num_recs; +} + +static inline +bool hfs_brec_offpair_valid(struct hfs_bnode *node, u16 off, u16 next_off, + u16 rec_off) +{ + u32 table_size; + u32 table_start; + u32 rec_size =3D sizeof(__be16); + u32 desc_size =3D sizeof(struct hfs_bnode_desc); + + if (!node || !node->tree) + return false; + + if (off < desc_size || (off & 1)) + return false; + + if (next_off <=3D off || + next_off > node->tree->node_size || + next_off > rec_off || + (next_off & 1)) + return false; + + table_size =3D ((u32)node->num_recs + 1) * rec_size; + table_start =3D node->tree->node_size - table_size; + if (next_off > table_start) + return false; + + return true; +} + +static inline +bool hfs_brec_len_valid(u16 len) +{ + return len !=3D U16_MAX && len !=3D 0; +} + +static inline +void hfs_find_result_init(struct hfs_find_data *fd) +{ + fd->record =3D -1; + fd->keyoffset =3D -1; + fd->keylength =3D -1; + fd->entryoffset =3D -1; + fd->entrylength =3D -1; +} + static inline u32 check_and_correct_requested_length(struct hfs_bnode *node, u32 off, u3= 2 len) { --=20 2.43.0