[PATCH] ufs: do not treat unreadable directory blocks as empty

Ali Ahmet Memis posted 1 patch 2 months ago
fs/ufs/dir.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
[PATCH] ufs: do not treat unreadable directory blocks as empty
Posted by Ali Ahmet Memis 2 months ago
ufs_empty_dir() scans every directory block to decide whether a
directory is empty before rmdir() removes it. When ufs_get_folio()
cannot read or validate a block it returns an error pointer, and the
loop currently skips that block with continue and keeps scanning the
remaining blocks.

If none of the readable blocks hold an entry, the function returns 1
and the caller unlinks the directory. A directory whose contents live
in a block that cannot be read, for example because of an I/O error or
corrupted directory metadata, is therefore seen as empty and removed,
losing the entries it still holds.

Follow the ext2 behaviour and treat an unreadable block as a reason to
consider the directory not empty, so rmdir() fails instead of
discarding data that could not be verified.

Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
Signed-off-by: Ali Ahmet Memis <ali@iusegentoo.com>
---
 fs/ufs/dir.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/fs/ufs/dir.c b/fs/ufs/dir.c
index e62fe5667..ce43cf20b 100644
--- a/fs/ufs/dir.c
+++ b/fs/ufs/dir.c
@@ -590,7 +590,7 @@ int ufs_empty_dir(struct inode * inode)
 
 		kaddr = ufs_get_folio(inode, i, &folio);
 		if (IS_ERR(kaddr))
-			continue;
+			return 0;
 
 		de = (struct ufs_dir_entry *)kaddr;
 		kaddr += ufs_last_byte(inode, i) - UFS_DIR_REC_LEN(1);
-- 
2.54.0
Re: [PATCH] ufs: do not treat unreadable directory blocks as empty
Posted by Christian Brauner 1 month, 1 week ago
On Sat, 01 Aug 2026 04:39:32 +0300, Ali Ahmet Memis wrote:
> ufs_empty_dir() scans every directory block to decide whether a
> directory is empty before rmdir() removes it. When ufs_get_folio()
> cannot read or validate a block it returns an error pointer, and the
> loop currently skips that block with continue and keeps scanning the
> remaining blocks.
> 
> If none of the readable blocks hold an entry, the function returns 1
> and the caller unlinks the directory. A directory whose contents live
> in a block that cannot be read, for example because of an I/O error or
> corrupted directory metadata, is therefore seen as empty and removed,
> losing the entries it still holds.
> 
> [...]

Applied to the vfs.fixes branch of the vfs/vfs.git tree.
Patches in the vfs.fixes branch should appear in linux-next soon.

Please report any outstanding bugs that were missed during review in a
new review to the original patch series allowing us to drop it.

It's encouraged to provide Acked-bys and Reviewed-bys even though the
patch has now been applied. If possible patch trailers will be updated.

Note that commit hashes shown below are subject to change due to rebase,
trailer updates or similar. If in doubt, please check the listed branch.

tree:   https://git.kernel.org/pub/scm/linux/kernel/git/vfs/vfs.git
branch: vfs.fixes

[1/1] ufs: do not treat unreadable directory blocks as empty
      https://git.kernel.org/vfs/vfs/c/08edfb34ee9c
Re: [PATCH] ufs: do not treat unreadable directory blocks as empty
Posted by Jan Kara 2 months ago
On Sat 01-08-26 04:39:32, Ali Ahmet Memis wrote:
> ufs_empty_dir() scans every directory block to decide whether a
> directory is empty before rmdir() removes it. When ufs_get_folio()
> cannot read or validate a block it returns an error pointer, and the
> loop currently skips that block with continue and keeps scanning the
> remaining blocks.
> 
> If none of the readable blocks hold an entry, the function returns 1
> and the caller unlinks the directory. A directory whose contents live
> in a block that cannot be read, for example because of an I/O error or
> corrupted directory metadata, is therefore seen as empty and removed,
> losing the entries it still holds.
> 
> Follow the ext2 behaviour and treat an unreadable block as a reason to
> consider the directory not empty, so rmdir() fails instead of
> discarding data that could not be verified.
> 
> Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
> Signed-off-by: Ali Ahmet Memis <ali@iusegentoo.com>

Fair. Feel free to add:

Reviewed-by: Jan Kara <jack@suse.cz>

								Honza

> ---
>  fs/ufs/dir.c | 2 +-
>  1 file changed, 1 insertion(+), 1 deletion(-)
> 
> diff --git a/fs/ufs/dir.c b/fs/ufs/dir.c
> index e62fe5667..ce43cf20b 100644
> --- a/fs/ufs/dir.c
> +++ b/fs/ufs/dir.c
> @@ -590,7 +590,7 @@ int ufs_empty_dir(struct inode * inode)
>  
>  		kaddr = ufs_get_folio(inode, i, &folio);
>  		if (IS_ERR(kaddr))
> -			continue;
> +			return 0;
>  
>  		de = (struct ufs_dir_entry *)kaddr;
>  		kaddr += ufs_last_byte(inode, i) - UFS_DIR_REC_LEN(1);
> -- 
> 2.54.0
> 
-- 
Jan Kara <jack@suse.com>
SUSE Labs, CR