* [PATCH] freevxfs: don't BUG() on unknown typed-extent type
@ 2026-05-30 3:35 Farhad Alemi
2026-06-01 7:09 ` Christoph Hellwig
0 siblings, 1 reply; 5+ messages in thread
From: Farhad Alemi @ 2026-05-30 3:35 UTC (permalink / raw)
To: Christoph Hellwig; +Cc: Christian Brauner, linux-kernel
vxfs_bmap_typed() dispatches on the on-disk typed-extent type,
(u32)(hdr >> VXFS_TYPED_TYPESHIFT), where hdr comes from the
attacker-controlled vt_hdr of each typed extent. Only four type values
are handled; any other value falls through the switch to the default
case, which is BUG(). After mounting a crafted VxFS image, an
ioctl(FIBMAP) on a regular file reaches this path and crashes the
kernel:
kernel BUG at fs/freevxfs/vxfs_bmap.c:230!
RIP: vxfs_bmap_typed fs/freevxfs/vxfs_bmap.c:230 [inline]
vxfs_bmap1+0x128a/0x12d0 fs/freevxfs/vxfs_bmap.c:257
Call Trace:
vxfs_getblk fs/freevxfs/vxfs_subr.c:104
generic_block_bmap fs/buffer.c:2764
bmap fs/inode.c:1948
ioctl_fibmap fs/ioctl.c:77 [inline]
file_ioctl+0x4b1/0x870 fs/ioctl.c:327
An unrecognized extent type is malformed on-disk input rather than a
kernel invariant violation. Replacing the BUG() with WARN_ON_ONCE()
would log the unexpected type once, and return 0 -- the failure value
vxfs_bmap_typed() already documents ("the physical block number on
success, else Zero") and the value its neighbouring DEV4 case returns.
vxfs_getblk() maps a 0 result to -EIO, so the FIBMAP ioctl fails
cleanly instead of crashing.
Reported-by: Farhad Alemi <farhad.alemi@berkeley.edu>
Signed-off-by: Farhad Alemi <farhad.alemi@berkeley.edu>
---
fs/freevxfs/vxfs_bmap.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/fs/freevxfs/vxfs_bmap.c b/fs/freevxfs/vxfs_bmap.c
index e85222892038..1b8216eb1d90 100644
--- a/fs/freevxfs/vxfs_bmap.c
+++ b/fs/freevxfs/vxfs_bmap.c
@@ -227,6 +227,7 @@ vxfs_bmap_typed(struct inode *ip, long iblock)
return 0;
}
default:
- BUG();
+ WARN_ON_ONCE(1);
+ return 0;
}
}
--
2.43.0
^ permalink raw reply [flat|nested] 5+ messages in thread
* Re: [PATCH] freevxfs: don't BUG() on unknown typed-extent type
2026-05-30 3:35 [PATCH] freevxfs: don't BUG() on unknown typed-extent type Farhad Alemi
@ 2026-06-01 7:09 ` Christoph Hellwig
2026-06-02 3:10 ` [PATCH v2] " Farhad Alemi
0 siblings, 1 reply; 5+ messages in thread
From: Christoph Hellwig @ 2026-06-01 7:09 UTC (permalink / raw)
To: Farhad Alemi; +Cc: Christoph Hellwig, Christian Brauner, linux-kernel
Not a fan of the attacker wording here - malіcious devices are not part
of the threat model of a read-only compatibility for a historic file
system used for hobby purposes. That being said, robustness is a good
thing, and the patch itself looks good.
Can we tone down the language a bit?
^ permalink raw reply [flat|nested] 5+ messages in thread
* [PATCH v2] freevxfs: don't BUG() on unknown typed-extent type
2026-06-01 7:09 ` Christoph Hellwig
@ 2026-06-02 3:10 ` Farhad Alemi
2026-06-02 6:18 ` Christoph Hellwig
2026-06-23 10:04 ` Christian Brauner
0 siblings, 2 replies; 5+ messages in thread
From: Farhad Alemi @ 2026-06-02 3:10 UTC (permalink / raw)
To: Christoph Hellwig; +Cc: Christian Brauner, linux-fsdevel, linux-kernel
vxfs_bmap_typed() handles four typed-extent types and calls BUG() in
its default case, so an on-disk typed extent with any other type value
crashes the kernel. It is reachable from ioctl(FIBMAP) on a regular
file:
kernel BUG at fs/freevxfs/vxfs_bmap.c:230!
RIP: vxfs_bmap_typed fs/freevxfs/vxfs_bmap.c:230 [inline]
vxfs_bmap1+0x128a/0x12d0 fs/freevxfs/vxfs_bmap.c:257
Replace the BUG() with WARN_ON_ONCE() and return 0 -- the value
vxfs_bmap_typed() already returns on failure (and from the DEV4 case
above); vxfs_getblk() maps 0 to -EIO, so the ioctl fails cleanly.
Reported-by: Farhad Alemi <farhad.alemi@berkeley.edu>
Signed-off-by: Farhad Alemi <farhad.alemi@berkeley.edu>
---
v2: tone down the changelog wording (Christoph Hellwig); code unchanged.
fs/freevxfs/vxfs_bmap.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/fs/freevxfs/vxfs_bmap.c b/fs/freevxfs/vxfs_bmap.c
index e85222892038..1b8216eb1d90 100644
--- a/fs/freevxfs/vxfs_bmap.c
+++ b/fs/freevxfs/vxfs_bmap.c
@@ -227,7 +227,8 @@ vxfs_bmap_typed(struct inode *ip, long iblock)
return 0;
}
default:
- BUG();
+ WARN_ON_ONCE(1);
+ return 0;
}
}
--
2.43.0
^ permalink raw reply [flat|nested] 5+ messages in thread
* Re: [PATCH v2] freevxfs: don't BUG() on unknown typed-extent type
2026-06-02 3:10 ` [PATCH v2] " Farhad Alemi
@ 2026-06-02 6:18 ` Christoph Hellwig
2026-06-23 10:04 ` Christian Brauner
1 sibling, 0 replies; 5+ messages in thread
From: Christoph Hellwig @ 2026-06-02 6:18 UTC (permalink / raw)
To: Farhad Alemi
Cc: Christoph Hellwig, Christian Brauner, linux-fsdevel, linux-kernel
Looks good:
Reviewed-by: Christoph Hellwig <hch@lst.de>
Christian, can you pick this up through the vfs tree?
^ permalink raw reply [flat|nested] 5+ messages in thread
* Re: [PATCH v2] freevxfs: don't BUG() on unknown typed-extent type
2026-06-02 3:10 ` [PATCH v2] " Farhad Alemi
2026-06-02 6:18 ` Christoph Hellwig
@ 2026-06-23 10:04 ` Christian Brauner
1 sibling, 0 replies; 5+ messages in thread
From: Christian Brauner @ 2026-06-23 10:04 UTC (permalink / raw)
To: Christoph Hellwig, Farhad Alemi
Cc: linux-fsdevel, linux-kernel, Christian Brauner
On Mon, 01 Jun 2026 20:10:08 -0700, Farhad Alemi wrote:
> freevxfs: don't BUG() on unknown typed-extent type
Applied to the vfs.fixes branch of the vfs/vfs.git tree.
Patches in the vfs.fixes branch should appear in linux-next soon.
Please report any outstanding bugs that were missed during review in a
new review to the original patch series allowing us to drop it.
It's encouraged to provide Acked-bys and Reviewed-bys even though the
patch has now been applied. If possible patch trailers will be updated.
Note that commit hashes shown below are subject to change due to rebase,
trailer updates or similar. If in doubt, please check the listed branch.
tree: https://git.kernel.org/pub/scm/linux/kernel/git/vfs/vfs.git
branch: vfs.fixes
[1/1] freevxfs: don't BUG() on unknown typed-extent type
https://git.kernel.org/vfs/vfs/c/f2f1b6ebe857
^ permalink raw reply [flat|nested] 5+ messages in thread
end of thread, other threads:[~2026-06-23 10:04 UTC | newest]
Thread overview: 5+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-05-30 3:35 [PATCH] freevxfs: don't BUG() on unknown typed-extent type Farhad Alemi
2026-06-01 7:09 ` Christoph Hellwig
2026-06-02 3:10 ` [PATCH v2] " Farhad Alemi
2026-06-02 6:18 ` Christoph Hellwig
2026-06-23 10:04 ` Christian Brauner
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®