)]}'
{
  "commit": "d7d9d29a837358636e12fe09c90a7882b53b2220",
  "tree": "f3236e6504133a24b7326b1874c5a5854cb0bb9e",
  "parents": [
    "ad19d1e78fd51f5b4bf3ebbcbf3a133c8c03c49d"
  ],
  "author": {
    "name": "Chao Yu",
    "email": "yuchao0@huawei.com",
    "time": "Sun Jul 08 22:16:55 2018 +0800"
  },
  "committer": {
    "name": "Greg Kroah-Hartman",
    "email": "gregkh@linuxfoundation.org",
    "time": "Wed Dec 05 19:41:16 2018 +0100"
  },
  "message": "f2fs: fix to do sanity check with i_extra_isize\n\ncommit 18dd6470c2d14d10f5a2dd926925dc80dbd3abfd upstream.\n\nIf inode.i_extra_isize was fuzzed to an abnormal value, when\ncalculating inline data size, the result will overflow, result\nin accessing invalid memory area when operating inline data.\n\nLet\u0027s do sanity check with i_extra_isize during inode loading\nfor fixing.\n\nhttps://bugzilla.kernel.org/show_bug.cgi?id\u003d200421\n\n- Reproduce\n\n- POC (poc.c)\n    #define _GNU_SOURCE\n    #include \u003csys/types.h\u003e\n    #include \u003csys/mount.h\u003e\n    #include \u003csys/mman.h\u003e\n    #include \u003csys/stat.h\u003e\n    #include \u003csys/xattr.h\u003e\n\n    #include \u003cdirent.h\u003e\n    #include \u003cerrno.h\u003e\n    #include \u003cerror.h\u003e\n    #include \u003cfcntl.h\u003e\n    #include \u003cstdio.h\u003e\n    #include \u003cstdlib.h\u003e\n    #include \u003cstring.h\u003e\n    #include \u003cunistd.h\u003e\n\n    #include \u003clinux/falloc.h\u003e\n    #include \u003clinux/loop.h\u003e\n\n    static void activity(char *mpoint) {\n\n      char *foo_bar_baz;\n      char *foo_baz;\n      char *xattr;\n      int err;\n\n      err \u003d asprintf(\u0026foo_bar_baz, \"%s/foo/bar/baz\", mpoint);\n      err \u003d asprintf(\u0026foo_baz, \"%s/foo/baz\", mpoint);\n      err \u003d asprintf(\u0026xattr, \"%s/foo/bar/xattr\", mpoint);\n\n      rename(foo_bar_baz, foo_baz);\n\n      char buf2[113];\n      memset(buf2, 0, sizeof(buf2));\n      listxattr(xattr, buf2, sizeof(buf2));\n      removexattr(xattr, \"user.mime_type\");\n\n    }\n\n    int main(int argc, char *argv[]) {\n      activity(argv[1]);\n      return 0;\n    }\n\n- Kernel message\nUmount the image will leave the following message\n[ 2910.995489] F2FS-fs (loop0): Mounted with checkpoint version \u003d 2\n[ 2918.416465] \u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\n[ 2918.416807] BUG: KASAN: slab-out-of-bounds in f2fs_iget+0xcb9/0x1a80\n[ 2918.417009] Read of size 4 at addr ffff88018efc2068 by task a.out/1229\n\n[ 2918.417311] CPU: 1 PID: 1229 Comm: a.out Not tainted 4.17.0+ #1\n[ 2918.417314] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS Ubuntu-1.8.2-1ubuntu1 04/01/2014\n[ 2918.417323] Call Trace:\n[ 2918.417366]  dump_stack+0x71/0xab\n[ 2918.417401]  print_address_description+0x6b/0x290\n[ 2918.417407]  kasan_report+0x28e/0x390\n[ 2918.417411]  ? f2fs_iget+0xcb9/0x1a80\n[ 2918.417415]  f2fs_iget+0xcb9/0x1a80\n[ 2918.417422]  ? f2fs_lookup+0x2e7/0x580\n[ 2918.417425]  f2fs_lookup+0x2e7/0x580\n[ 2918.417433]  ? __recover_dot_dentries+0x400/0x400\n[ 2918.417447]  ? legitimize_path.isra.29+0x5a/0xa0\n[ 2918.417453]  __lookup_slow+0x11c/0x220\n[ 2918.417457]  ? may_delete+0x2a0/0x2a0\n[ 2918.417475]  ? deref_stack_reg+0xe0/0xe0\n[ 2918.417479]  ? __lookup_hash+0xb0/0xb0\n[ 2918.417483]  lookup_slow+0x3e/0x60\n[ 2918.417488]  walk_component+0x3ac/0x990\n[ 2918.417492]  ? generic_permission+0x51/0x1e0\n[ 2918.417495]  ? inode_permission+0x51/0x1d0\n[ 2918.417499]  ? pick_link+0x3e0/0x3e0\n[ 2918.417502]  ? link_path_walk+0x4b1/0x770\n[ 2918.417513]  ? _raw_spin_lock_irqsave+0x25/0x50\n[ 2918.417518]  ? walk_component+0x990/0x990\n[ 2918.417522]  ? path_init+0x2e6/0x580\n[ 2918.417526]  path_lookupat+0x13f/0x430\n[ 2918.417531]  ? trailing_symlink+0x3a0/0x3a0\n[ 2918.417534]  ? do_renameat2+0x270/0x7b0\n[ 2918.417538]  ? __kasan_slab_free+0x14c/0x190\n[ 2918.417541]  ? do_renameat2+0x270/0x7b0\n[ 2918.417553]  ? kmem_cache_free+0x85/0x1e0\n[ 2918.417558]  ? do_renameat2+0x270/0x7b0\n[ 2918.417563]  filename_lookup+0x13c/0x280\n[ 2918.417567]  ? filename_parentat+0x2b0/0x2b0\n[ 2918.417572]  ? kasan_unpoison_shadow+0x31/0x40\n[ 2918.417575]  ? kasan_kmalloc+0xa6/0xd0\n[ 2918.417593]  ? strncpy_from_user+0xaa/0x1c0\n[ 2918.417598]  ? getname_flags+0x101/0x2b0\n[ 2918.417614]  ? path_listxattr+0x87/0x110\n[ 2918.417619]  path_listxattr+0x87/0x110\n[ 2918.417623]  ? listxattr+0xc0/0xc0\n[ 2918.417637]  ? mm_fault_error+0x1b0/0x1b0\n[ 2918.417654]  do_syscall_64+0x73/0x160\n[ 2918.417660]  entry_SYSCALL_64_after_hwframe+0x44/0xa9\n[ 2918.417676] RIP: 0033:0x7f2f3a3480d7\n[ 2918.417677] Code: f0 ff ff 73 01 c3 48 8b 0d be dd 2b 00 f7 d8 64 89 01 48 83 c8 ff c3 66 2e 0f 1f 84 00 00 00 00 00 66 90 b8 c2 00 00 00 0f 05 \u003c48\u003e 3d 01 f0 ff ff 73 01 c3 48 8b 0d 91 dd 2b 00 f7 d8 64 89 01 48\n[ 2918.417732] RSP: 002b:00007fff4095b7d8 EFLAGS: 00000206 ORIG_RAX: 00000000000000c2\n[ 2918.417744] RAX: ffffffffffffffda RBX: 0000000000000000 RCX: 00007f2f3a3480d7\n[ 2918.417746] RDX: 0000000000000071 RSI: 00007fff4095b810 RDI: 000000000126a0c0\n[ 2918.417749] RBP: 00007fff4095b890 R08: 000000000126a010 R09: 0000000000000000\n[ 2918.417751] R10: 00000000000001ab R11: 0000000000000206 R12: 00000000004005e0\n[ 2918.417753] R13: 00007fff4095b990 R14: 0000000000000000 R15: 0000000000000000\n\n[ 2918.417853] Allocated by task 329:\n[ 2918.418002]  kasan_kmalloc+0xa6/0xd0\n[ 2918.418007]  kmem_cache_alloc+0xc8/0x1e0\n[ 2918.418023]  mempool_init_node+0x194/0x230\n[ 2918.418027]  mempool_init+0x12/0x20\n[ 2918.418042]  bioset_init+0x2bd/0x380\n[ 2918.418052]  blk_alloc_queue_node+0xe9/0x540\n[ 2918.418075]  dm_create+0x2c0/0x800\n[ 2918.418080]  dev_create+0xd2/0x530\n[ 2918.418083]  ctl_ioctl+0x2a3/0x5b0\n[ 2918.418087]  dm_ctl_ioctl+0xa/0x10\n[ 2918.418092]  do_vfs_ioctl+0x13e/0x8c0\n[ 2918.418095]  ksys_ioctl+0x66/0x70\n[ 2918.418098]  __x64_sys_ioctl+0x3d/0x50\n[ 2918.418102]  do_syscall_64+0x73/0x160\n[ 2918.418106]  entry_SYSCALL_64_after_hwframe+0x44/0xa9\n\n[ 2918.418204] Freed by task 0:\n[ 2918.418301] (stack is not available)\n\n[ 2918.418521] The buggy address belongs to the object at ffff88018efc0000\n                which belongs to the cache biovec-max of size 8192\n[ 2918.418894] The buggy address is located 104 bytes to the right of\n                8192-byte region [ffff88018efc0000, ffff88018efc2000)\n[ 2918.419257] The buggy address belongs to the page:\n[ 2918.419431] page:ffffea00063bf000 count:1 mapcount:0 mapping:ffff8801f2242540 index:0x0 compound_mapcount: 0\n[ 2918.419702] flags: 0x17fff8000008100(slab|head)\n[ 2918.419879] raw: 017fff8000008100 dead000000000100 dead000000000200 ffff8801f2242540\n[ 2918.420101] raw: 0000000000000000 0000000000030003 00000001ffffffff 0000000000000000\n[ 2918.420322] page dumped because: kasan: bad access detected\n\n[ 2918.420599] Memory state around the buggy address:\n[ 2918.420764]  ffff88018efc1f00: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb\n[ 2918.420975]  ffff88018efc1f80: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb\n[ 2918.421194] \u003effff88018efc2000: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc\n[ 2918.421406]                                                           ^\n[ 2918.421627]  ffff88018efc2080: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc\n[ 2918.421838]  ffff88018efc2100: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb\n[ 2918.422046] \u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\n[ 2918.422264] Disabling lock debugging due to kernel taint\n[ 2923.901641] BUG: unable to handle kernel paging request at ffff88018f0db000\n[ 2923.901884] PGD 22226a067 P4D 22226a067 PUD 222273067 PMD 18e642063 PTE 800000018f0db061\n[ 2923.902120] Oops: 0003 [#1] SMP KASAN PTI\n[ 2923.902274] CPU: 1 PID: 1231 Comm: umount Tainted: G    B             4.17.0+ #1\n[ 2923.902490] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS Ubuntu-1.8.2-1ubuntu1 04/01/2014\n[ 2923.902761] RIP: 0010:__memset+0x24/0x30\n[ 2923.902906] Code: 90 90 90 90 90 90 66 66 90 66 90 49 89 f9 48 89 d1 83 e2 07 48 c1 e9 03 40 0f b6 f6 48 b8 01 01 01 01 01 01 01 01 48 0f af c6 \u003cf3\u003e 48 ab 89 d1 f3 aa 4c 89 c8 c3 90 49 89 f9 40 88 f0 48 89 d1 f3\n[ 2923.903446] RSP: 0018:ffff88018ddf7ae0 EFLAGS: 00010206\n[ 2923.903622] RAX: 0000000000000000 RBX: ffff8801d549d888 RCX: 1ffffffffffdaffb\n[ 2923.903833] RDX: 0000000000000000 RSI: 0000000000000000 RDI: ffff88018f0daffc\n[ 2923.904062] RBP: ffff88018efc206c R08: 1ffff10031df840d R09: ffff88018efc206c\n[ 2923.904273] R10: ffffffffffffe1ee R11: ffffed0031df65fa R12: 0000000000000000\n[ 2923.904485] R13: ffff8801d549dc98 R14: 00000000ffffc3db R15: ffffea00063bec80\n[ 2923.904693] FS:  00007fa8b2f8a840(0000) GS:ffff8801f3b00000(0000) knlGS:0000000000000000\n[ 2923.904937] CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n[ 2923.910080] CR2: ffff88018f0db000 CR3: 000000018f892000 CR4: 00000000000006e0\n[ 2923.914930] Call Trace:\n[ 2923.919724]  f2fs_truncate_inline_inode+0x114/0x170\n[ 2923.924487]  f2fs_truncate_blocks+0x11b/0x7c0\n[ 2923.929178]  ? f2fs_truncate_data_blocks+0x10/0x10\n[ 2923.933834]  ? dqget+0x670/0x670\n[ 2923.938437]  ? f2fs_destroy_extent_tree+0xd6/0x270\n[ 2923.943107]  ? __radix_tree_lookup+0x2f/0x150\n[ 2923.947772]  f2fs_truncate+0xd4/0x1a0\n[ 2923.952491]  f2fs_evict_inode+0x5ab/0x610\n[ 2923.957204]  evict+0x15f/0x280\n[ 2923.961898]  __dentry_kill+0x161/0x250\n[ 2923.966634]  shrink_dentry_list+0xf3/0x250\n[ 2923.971897]  shrink_dcache_parent+0xa9/0x100\n[ 2923.976561]  ? shrink_dcache_sb+0x1f0/0x1f0\n[ 2923.981177]  ? wait_for_completion+0x8a/0x210\n[ 2923.985781]  ? migrate_swap_stop+0x2d0/0x2d0\n[ 2923.990332]  do_one_tree+0xe/0x40\n[ 2923.994735]  shrink_dcache_for_umount+0x3a/0xa0\n[ 2923.999077]  generic_shutdown_super+0x3e/0x1c0\n[ 2924.003350]  kill_block_super+0x4b/0x70\n[ 2924.007619]  deactivate_locked_super+0x65/0x90\n[ 2924.011812]  cleanup_mnt+0x5c/0xa0\n[ 2924.015995]  task_work_run+0xce/0xf0\n[ 2924.020174]  exit_to_usermode_loop+0x115/0x120\n[ 2924.024293]  do_syscall_64+0x12f/0x160\n[ 2924.028479]  entry_SYSCALL_64_after_hwframe+0x44/0xa9\n[ 2924.032709] RIP: 0033:0x7fa8b2868487\n[ 2924.036888] Code: 83 c8 ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 44 00 00 31 f6 e9 09 00 00 00 66 0f 1f 84 00 00 00 00 00 b8 a6 00 00 00 0f 05 \u003c48\u003e 3d 01 f0 ff ff 73 01 c3 48 8b 0d e1 c9 2b 00 f7 d8 64 89 01 48\n[ 2924.045750] RSP: 002b:00007ffc39824d58 EFLAGS: 00000246 ORIG_RAX: 00000000000000a6\n[ 2924.050190] RAX: 0000000000000000 RBX: 00000000008ea030 RCX: 00007fa8b2868487\n[ 2924.054604] RDX: 0000000000000001 RSI: 0000000000000000 RDI: 00000000008f4360\n[ 2924.058940] RBP: 00000000008f4360 R08: 0000000000000000 R09: 0000000000000014\n[ 2924.063186] R10: 00000000000006b2 R11: 0000000000000246 R12: 00007fa8b2d7183c\n[ 2924.067418] R13: 0000000000000000 R14: 00000000008ea210 R15: 00007ffc39824fe0\n[ 2924.071534] Modules linked in: snd_hda_codec_generic snd_hda_intel snd_hda_codec snd_hda_core snd_hwdep snd_pcm snd_timer joydev input_leds serio_raw snd soundcore mac_hid i2c_piix4 ib_iser rdma_cm iw_cm ib_cm ib_core configfs iscsi_tcp libiscsi_tcp libiscsi scsi_transport_iscsi btrfs zstd_decompress zstd_compress xxhash raid10 raid456 async_raid6_recov async_memcpy async_pq async_xor async_tx xor raid6_pq libcrc32c raid1 raid0 multipath linear 8139too qxl ttm drm_kms_helper syscopyarea sysfillrect sysimgblt fb_sys_fops drm crct10dif_pclmul crc32_pclmul ghash_clmulni_intel pcbc aesni_intel psmouse aes_x86_64 8139cp crypto_simd cryptd mii glue_helper pata_acpi floppy\n[ 2924.098044] CR2: ffff88018f0db000\n[ 2924.102520] ---[ end trace a8e0d899985faf31 ]---\n[ 2924.107012] RIP: 0010:__memset+0x24/0x30\n[ 2924.111448] Code: 90 90 90 90 90 90 66 66 90 66 90 49 89 f9 48 89 d1 83 e2 07 48 c1 e9 03 40 0f b6 f6 48 b8 01 01 01 01 01 01 01 01 48 0f af c6 \u003cf3\u003e 48 ab 89 d1 f3 aa 4c 89 c8 c3 90 49 89 f9 40 88 f0 48 89 d1 f3\n[ 2924.120724] RSP: 0018:ffff88018ddf7ae0 EFLAGS: 00010206\n[ 2924.125312] RAX: 0000000000000000 RBX: ffff8801d549d888 RCX: 1ffffffffffdaffb\n[ 2924.129931] RDX: 0000000000000000 RSI: 0000000000000000 RDI: ffff88018f0daffc\n[ 2924.134537] RBP: ffff88018efc206c R08: 1ffff10031df840d R09: ffff88018efc206c\n[ 2924.139175] R10: ffffffffffffe1ee R11: ffffed0031df65fa R12: 0000000000000000\n[ 2924.143825] R13: ffff8801d549dc98 R14: 00000000ffffc3db R15: ffffea00063bec80\n[ 2924.148500] FS:  00007fa8b2f8a840(0000) GS:ffff8801f3b00000(0000) knlGS:0000000000000000\n[ 2924.153247] CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n[ 2924.158003] CR2: ffff88018f0db000 CR3: 000000018f892000 CR4: 00000000000006e0\n[ 2924.164641] BUG: Bad rss-counter state mm:00000000fa04621e idx:0 val:4\n[ 2924.170007] BUG: Bad rss-counter\ntate mm:00000000fa04621e idx:1 val:2\n\n- Location\nhttps://elixir.bootlin.com/linux/v4.18-rc3/source/fs/f2fs/inline.c#L78\n\tmemset(addr + from, 0, MAX_INLINE_DATA(inode) - from);\nHere the length can be negative.\n\nReported-by Wen Xu \u003cwen.xu@gatech.edu\u003e\nSigned-off-by: Chao Yu \u003cyuchao0@huawei.com\u003e\nSigned-off-by: Jaegeuk Kim \u003cjaegeuk@kernel.org\u003e\n[bwh: Backported to 4.14: adjust context]\nSigned-off-by: Ben Hutchings \u003cben.hutchings@codethink.co.uk\u003e\nSigned-off-by: Sasha Levin \u003csashal@kernel.org\u003e\n",
  "tree_diff": [
    {
      "type": "modify",
      "old_id": "aeed9943836a3b42ea3d38a18a40ac4feeed1852",
      "old_mode": 33188,
      "old_path": "fs/f2fs/inode.c",
      "new_id": "9a40724dbaa62afadc2c57d052b0845a88a1cba8",
      "new_mode": 33188,
      "new_path": "fs/f2fs/inode.c"
    }
  ]
}
