mirror of
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git
synced 2026-08-31 10:31:33 -04:00
ext4: reject mount if clusters/inodes per group are not 8-aligned
The block and inode bitmap checksums are computed over a whole number of bytes: ext4_inode_bitmap_csum_*() use EXT4_INODES_PER_GROUP(sb) >> 3 and ext4_block_bitmap_csum_*() use EXT4_CLUSTERS_PER_GROUP(sb) / 8 as the length passed to ext4_chksum(). If s_inodes_per_group or s_clusters_per_group is not a multiple of 8, the trailing fractional bits are excluded from the checksum. Those bits are then unprotected, and any incremental csum update path that assumes a byte-aligned bitmap can compute a checksum inconsistent with the full recalculation, corrupting the on-disk bitmap checksum. Reject such filesystems at mount time by adding the missing " & 7" alignment checks alongside the existing range validation. Suggested-by: Theodore Ts'o <tytso@mit.edu> Link: https://patch.msgid.link/h3n7jlfhyna64dn5o76qxcspnhxdddcs6crpxftmy7gnl7b3sx@jenszfpcsnit Reported-by: Sashiko <sashiko-bot@kernel.org> Closes: https://sashiko.dev/#/patchset/20260508121539.4174601-1-libaokun%40linux.alibaba.com?part=10 Signed-off-by: Baokun Li <libaokun@linux.alibaba.com> Reviewed-by: Jan Kara <jack@suse.cz> Reviewed-by: Zhang Yi <yi.zhang@huawei.com> Link: https://patch.msgid.link/20260608111150.827117-2-libaokun@linux.alibaba.com Signed-off-by: Theodore Ts'o <tytso@mit.edu>
This commit is contained in:
@@ -4475,8 +4475,9 @@ static int ext4_handle_clustersize(struct super_block *sb)
|
||||
sbi->s_cluster_bits = 0;
|
||||
}
|
||||
sbi->s_clusters_per_group = le32_to_cpu(es->s_clusters_per_group);
|
||||
if (sbi->s_clusters_per_group > sb->s_blocksize * 8) {
|
||||
ext4_msg(sb, KERN_ERR, "#clusters per group too big: %lu",
|
||||
if (sbi->s_clusters_per_group > sb->s_blocksize * 8 ||
|
||||
sbi->s_clusters_per_group & 7) {
|
||||
ext4_msg(sb, KERN_ERR, "invalid #clusters per group: %lu",
|
||||
sbi->s_clusters_per_group);
|
||||
return -EINVAL;
|
||||
}
|
||||
@@ -5308,8 +5309,9 @@ static int ext4_block_group_meta_init(struct super_block *sb, int silent)
|
||||
return -EINVAL;
|
||||
}
|
||||
if (sbi->s_inodes_per_group < sbi->s_inodes_per_block ||
|
||||
sbi->s_inodes_per_group > sb->s_blocksize * 8) {
|
||||
ext4_msg(sb, KERN_ERR, "invalid inodes per group: %lu\n",
|
||||
sbi->s_inodes_per_group > sb->s_blocksize * 8 ||
|
||||
sbi->s_inodes_per_group & 7) {
|
||||
ext4_msg(sb, KERN_ERR, "invalid inodes per group: %lu",
|
||||
sbi->s_inodes_per_group);
|
||||
return -EINVAL;
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user