From nobody Tue Sep 29 08:31:13 2026 Received: from mail-pl1-f177.google.com (mail-pl1-f177.google.com [209.85.214.177]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id A7F12400E18 for ; Mon, 10 Aug 2026 14:21:33 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.214.177 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786371711; cv=none; b=pmx/PHwgq7OtR6U8luGb+cI2bnAimKAsOLyWx09U1gAPk2RnkOsSz7elh1XVACx178edD3v0q3omj6IL5LoevsbmqWhy0aMcEpBWePvOC0TA5BrUPOCQSuU1lQ4Cz7BXhqE7fJEyommBjcdei2HPAOEAQ7r9Rpnw2WYOY46FKZU= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786371711; c=relaxed/simple; bh=iGbQwBbiwYKpV2l+z6aMYGZpPBCSkgJqWqsLkmoFmnI=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=HTYdGicuUShq05PNWIQ9gxMh4RbnZpO2UCOG0Z/eRU9Fiwf34GF5Bx6sK6sSLDtkp/SkSEO8yKNRX/fMexic2LxvtyReDlKE1G0NIC6IoAjk12RqAouLl9shz/9YxnROKcbslaC5s9mIwmWhcsl5AlGRESsZS2T1mENmouvXda0= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=LMs9/rZU; arc=none smtp.client-ip=209.85.214.177 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="LMs9/rZU" Received: by mail-pl1-f177.google.com with SMTP id d9443c01a7336-2cc891373e0so22552405ad.2 for ; Mon, 10 Aug 2026 07:21:32 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1786371689; x=1786976489; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to:content-type; bh=jqiy8nmJjB3QSTB7FCM6fB8hERTHwuBy5zOEE7SD5kI=; b=LMs9/rZUzjIwfh0Cn+0nlmDVKkIeabOF4NixhGLWEILFbTIFIHVb4AOTZ4371KyZ15 tTa9Q/46W7GNRuwuepsU29PRJxnfRnG7kh5nEBTDnTuhm9XH2hgbDoUvFa8s25e0Nh6e n0/WpEpovW3BfxEUECY68BY7hsfX6wzYXjFWX7eGKg617EwPrgqcwaci6MiqXj/xQrJG VmDGdsPSDvMqy9SY6CHp0+vepYw2AWcpWAFizm2BBipX4mjpCJYLLH/mdZqhSgN9Hapw 49P1EJIYLPEhgWsl4P8A4kLB7jHSYlACLW6L75OasLmIY3H/WxdNnuYV3ps2gVhIek+n o/yg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1786371689; x=1786976489; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=jqiy8nmJjB3QSTB7FCM6fB8hERTHwuBy5zOEE7SD5kI=; b=fyIERd81tnP9b7o35s8VBMAy1Y1W5zL+qvo0ZT6+Q7yYIcbFSWkMPJ+RcTn9JAfu7T 2OItyhgWJSYoZ6co+WBP+2uYg9fC6frH+JgMhPPLNPdXqP6H2vnENcH1nHrxwVb1mefN P44Y2hhmC/24pmLrJbC+TLyKeGWV+R1bVeWss6534yalJToIZbDqCo+WexNSO4H6Laxx Bs6SQRQctEOTalShSaIe5jowa0ntuWVVNv/km1fVnHcnxMC0A5todBAZ1+9xWdYV4Tel QBvDY8vZ48dttlehHr62u8wjaqsO5zY8y+MmH7wTOUfwAeu0FMbKtfoQ1RgynEBqOzTU kYpw== X-Forwarded-Encrypted: i=1; AHgh+RrI+NfjRiW2YJLGUBUfFqx+lSPs3BEDKAyazqsRADA74iSUF4/agsfTj1ol5zbtDfgg9N3/pNL5iJWQw0o=@vger.kernel.org X-Gm-Message-State: AOJu0YweuTHPgDTbmKovYQPTXajBQY58wLS93vaepiN6CWY9da4I0EYD Zuz/e8CBf3tMiAKQlCGG+280M/0DJYV7dY6Y9n/QjmqZOImj/4d4CSuB X-Gm-Gg: AR+sD10GqzdOcyaJjgbone6QmsTekPVJQTrKrO2ev3D3Eszv+uermF8dZkUkVO37KU/ fRn5m8+g/vMwfge17hbO85CcAHZizSg7UlKUycx8sOFH2/5UimVqeHazqL971tULjunnonE9GVp //D7zQtwmJxGou3UOfmDwJp64mjA3Pe7gtTuLXZ51ZDCqIDwI6zVMQecHDuiGMu6R8Lw+7sI+65 46BIlc4v0J2SnmdPjUxDIV2NSltYLWEpw313hZsVO+uKQlpHAekGNn9/YeOtj8TrsfEj+qu5qxh nbn3fL1I0CN7Lf3v35NHem249AvfrEkHznsn0KRE5IBy7iPsXB4WYyTLvGzraJjJEUncYB8cVr4 KJVxq6N/cPmgcl/E64N4r5vnDuhL5dzkU4KWvo9uj0v4RN8ucmeUVSkws24t6Ez2LWYsm1aDm40 03NhyXGj27wu36GiYM6SN7yZeWug9FDlyYY7RJt5QoV1UebdUy61lE9Cgiu4RkCdZZNM8vqz+cn +S7niMsS6fXAcVf+qwRvELq X-Received: by 2002:a05:6300:218d:b0:3c3:7e9c:e292 with SMTP id adf61e73a8af0-3cc1a33a8bcmr2317062637.25.1786371688968; Mon, 10 Aug 2026 07:21:28 -0700 (PDT) Received: from carrot.devel.local (madb688455.ap.nuro.jp. [219.104.132.85]) by smtp.gmail.com with ESMTPSA id 41be03b00d2f7-cbe8f199cfasm4346129a12.6.2026.08.10.07.21.27 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 10 Aug 2026 07:21:28 -0700 (PDT) From: Ryusuke Konishi To: Viacheslav Dubeyko Cc: Wang Jianjian , linux-nilfs , LKML , syzbot+158be45e4d99232e1900@syzkaller.appspotmail.com, syzkaller-bugs@googlegroups.com Subject: [PATCH] nilfs2: enhance btree node keys check Date: Mon, 10 Aug 2026 23:20:52 +0900 Message-ID: <20260810142125.60264-1-konishi.ryusuke@gmail.com> X-Mailer: git-send-email 2.43.0 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" From: Wang Jianjian syzbot reported a warning on nilfs_btree_assign: WARNING: fs/nilfs2/btree.c:2302 at nilfs_btree_assign+0x983/0xbe0 fs/nilfs2= /btree.c:2302, Analysis found that a corrupted file has the following btree layout: Level2(key/ptr): [ 256/15 ] Level1(key/ptr): [ 0/8, 1/9, 0/10, 3/11, 4/12, 5/13, 6/14, 139637976727559/16, 0/17 ] The test truncated the file to 2 bytes, which partially zeroes the first block and adds the file to the dirty list. When the segment constructor writes it and assigns a new blocknr for the index block, it searches the btree with key=3D0 and min level=3D2, and apparently returns -ENOENT. Therefore, we should perform more checks on the btree nodes and return early. [ryusuke: split long lines in btree.c to satisfy checkpatch and improved the error message format for clarity] Reported-by: syzbot+158be45e4d99232e1900@syzkaller.appspotmail.com Closes: https://syzkaller.appspot.com/bug?extid=3D158be45e4d99232e1900 Signed-off-by: Wang Jianjian Fixes: 17c76b0104e4 ("nilfs2: B-tree based block mapping") Cc: # Warning suppression primarily Signed-off-by: Ryusuke Konishi --- Hi Viacheslav, Please apply this for the next cycle. This introduces a check for sorted keys when reading btree node blocks into the cache, preventing unexpected errors during the block number assignment phase in log writing caused by key order inconsistencies, as well as the kernel warnings reported by syzbot. Thanks, Ryusuke Konishi fs/nilfs2/btree.c | 19 ++++++++++++++++--- 1 file changed, 16 insertions(+), 3 deletions(-) diff --git a/fs/nilfs2/btree.c b/fs/nilfs2/btree.c index 64bac66af25b..6b8332e8c0db 100644 --- a/fs/nilfs2/btree.c +++ b/fs/nilfs2/btree.c @@ -341,7 +341,8 @@ static int nilfs_btree_node_broken(const struct nilfs_b= tree_node *node, sector_t blocknr) { int level, flags, nchildren; - int ret =3D 0; + __u64 key, prev_key; + int i; =20 level =3D nilfs_btree_node_get_level(node); flags =3D nilfs_btree_node_get_flags(node); @@ -356,9 +357,21 @@ static int nilfs_btree_node_broken(const struct nilfs_= btree_node *node, "bad btree node (ino=3D%llu, blocknr=3D%llu): level =3D %d, flags = =3D 0x%x, nchildren =3D %d", inode->i_ino, (unsigned long long)blocknr, level, flags, nchildren); - ret =3D 1; + return 1; } - return ret; + + for (i =3D 1, prev_key =3D nilfs_btree_node_get_key(node, 0); + i < nchildren; i++, prev_key =3D key) { + key =3D nilfs_btree_node_get_key(node, i); + if (unlikely(key <=3D prev_key)) { + nilfs_crit(inode->i_sb, + "bad btree node (ino=3D%llu, blocknr=3D%llu): unsorted keys at index %= d (%llu) and %d (%llu)", + inode->i_ino, (unsigned long long)blocknr, + i - 1, prev_key, i, key); + return 1; + } + } + return 0; } =20 /** --=20 2.43.0