android_kernel_motorola_sm6375/fs
Repository files (latest commit first)
Filename Latest commit message Latest commit date
Thadeu Lima de Souza Cascardo f57725bcc5 hfsplus: don't query the device logical block size multiple times
[ Upstream commit 1c82587cb57687de3f18ab4b98a8850c789bedcf ]

Devices block sizes may change. One of these cases is a loop device by
using ioctl LOOP_SET_BLOCK_SIZE.

While this may cause other issues like IO being rejected, in the case of
hfsplus, it will allocate a block by using that size and potentially write
out-of-bounds when hfsplus_read_wrapper calls hfsplus_submit_bio and the
latter function reads a different io_size.

Using a new min_io_size initally set to sb_min_blocksize works for the
purposes of the original fix, since it will be set to the max between
HFSPLUS_SECTOR_SIZE and the first seen logical block size. We still use the
max between HFSPLUS_SECTOR_SIZE and min_io_size in case the latter is not
initialized.

Tested by mounting an hfsplus filesystem with loop block sizes 512, 1024
and 4096.

The produced KASAN report before the fix looks like this:

[  419.944641] ==================================================================
[  419.945655] BUG: KASAN: slab-use-after-free in hfsplus_read_wrapper+0x659/0xa0a
[  419.946703] Read of size 2 at addr ffff88800721fc00 by task repro/10678
[  419.947612]
[  419.947846] CPU: 0 UID: 0 PID: 10678 Comm: repro Not tainted 6.12.0-rc5-00008-gdf56e0f2f3ca #84
[  419.949007] Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.15.0-1 04/01/2014
[  419.950035] Call Trace:
[  419.950384]  <TASK>
[  419.950676]  dump_stack_lvl+0x57/0x78
[  419.951212]  ? hfsplus_read_wrapper+0x659/0xa0a
[  419.951830]  print_report+0x14c/0x49e
[  419.952361]  ? __virt_addr_valid+0x267/0x278
[  419.952979]  ? kmem_cache_debug_flags+0xc/0x1d
[  419.953561]  ? hfsplus_read_wrapper+0x659/0xa0a
[  419.954231]  kasan_report+0x89/0xb0
[  419.954748]  ? hfsplus_read_wrapper+0x659/0xa0a
[  419.955367]  hfsplus_read_wrapper+0x659/0xa0a
[  419.955948]  ? __pfx_hfsplus_read_wrapper+0x10/0x10
[  419.956618]  ? do_raw_spin_unlock+0x59/0x1a9
[  419.957214]  ? _raw_spin_unlock+0x1a/0x2e
[  419.957772]  hfsplus_fill_super+0x348/0x1590
[  419.958355]  ? hlock_class+0x4c/0x109
[  419.958867]  ? __pfx_hfsplus_fill_super+0x10/0x10
[  419.959499]  ? __pfx_string+0x10/0x10
[  419.960006]  ? lock_acquire+0x3e2/0x454
[  419.960532]  ? bdev_name.constprop.0+0xce/0x243
[  419.961129]  ? __pfx_bdev_name.constprop.0+0x10/0x10
[  419.961799]  ? pointer+0x3f0/0x62f
[  419.962277]  ? __pfx_pointer+0x10/0x10
[  419.962761]  ? vsnprintf+0x6c4/0xfba
[  419.963178]  ? __pfx_vsnprintf+0x10/0x10
[  419.963621]  ? setup_bdev_super+0x376/0x3b3
[  419.964029]  ? snprintf+0x9d/0xd2
[  419.964344]  ? __pfx_snprintf+0x10/0x10
[  419.964675]  ? lock_acquired+0x45c/0x5e9
[  419.965016]  ? set_blocksize+0x139/0x1c1
[  419.965381]  ? sb_set_blocksize+0x6d/0xae
[  419.965742]  ? __pfx_hfsplus_fill_super+0x10/0x10
[  419.966179]  mount_bdev+0x12f/0x1bf
[  419.966512]  ? __pfx_mount_bdev+0x10/0x10
[  419.966886]  ? vfs_parse_fs_string+0xce/0x111
[  419.967293]  ? __pfx_vfs_parse_fs_string+0x10/0x10
[  419.967702]  ? __pfx_hfsplus_mount+0x10/0x10
[  419.968073]  legacy_get_tree+0x104/0x178
[  419.968414]  vfs_get_tree+0x86/0x296
[  419.968751]  path_mount+0xba3/0xd0b
[  419.969157]  ? __pfx_path_mount+0x10/0x10
[  419.969594]  ? kmem_cache_free+0x1e2/0x260
[  419.970311]  do_mount+0x99/0xe0
[  419.970630]  ? __pfx_do_mount+0x10/0x10
[  419.971008]  __do_sys_mount+0x199/0x1c9
[  419.971397]  do_syscall_64+0xd0/0x135
[  419.971761]  entry_SYSCALL_64_after_hwframe+0x76/0x7e
[  419.972233] RIP: 0033:0x7c3cb812972e
[  419.972564] Code: 48 8b 0d f5 46 0d 00 f7 d8 64 89 01 48 83 c8 ff c3 66 2e 0f 1f 84 00 00 00 00 00 90 f3 0f 1e fa 49 89 ca b8 a5 00 00 00 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 8b 0d c2 46 0d 00 f7 d8 64 89 01 48
[  419.974371] RSP: 002b:00007ffe30632548 EFLAGS: 00000286 ORIG_RAX: 00000000000000a5
[  419.975048] RAX: ffffffffffffffda RBX: 00007ffe306328d8 RCX: 00007c3cb812972e
[  419.975701] RDX: 0000000020000000 RSI: 0000000020000c80 RDI: 00007ffe306325d0
[  419.976363] RBP: 00007ffe30632720 R08: 00007ffe30632610 R09: 0000000000000000
[  419.977034] R10: 0000000000200008 R11: 0000000000000286 R12: 0000000000000000
[  419.977713] R13: 00007ffe306328e8 R14: 00005a0eb298bc68 R15: 00007c3cb8356000
[  419.978375]  </TASK>
[  419.978589]

Fixes: 6596528e39 ("hfsplus: ensure bio requests are not smaller than the hardware sectors")
Signed-off-by: Thadeu Lima de Souza Cascardo <cascardo@igalia.com>
Link: https://lore.kernel.org/r/20241107114109.839253-1-cascardo@igalia.com
Signed-off-by: Christian Brauner <brauner@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2024-12-14 19:44:22 +01:00
..
9p fs/9p: drop inodes immediately on non-.L too 2024-05-17 11:43:53 +02:00
adfs
affs affs: initialize fsdata in affs_truncate() 2023-02-06 07:52:36 +01:00
afs afs: Don't cross .backup mountpoint from backup volume 2024-06-16 13:28:48 +02:00
autofs autofs: fix memory leak of waitqueues in autofs_catatonic_mode 2023-09-23 11:00:02 +02:00
befs
bfs
btrfs btrfs: reinitialize delayed ref list after deleting it from the list 2024-11-17 14:58:51 +01:00
cachefiles cachefiles: fix memory leak in cachefiles_add_cache() 2024-03-06 14:36:10 +00:00
ceph ceph: remove the incorrect Fw reference check when dirtying pages 2024-11-08 16:20:35 +01:00
cifs cifs: Fix buffer overflow when parsing NFS reparse points 2024-12-14 19:44:21 +01:00
coda coda: Avoid partial allocation of sig_inputArgs 2023-03-11 16:43:56 +01:00
configfs configfs: fix possible memory leak in configfs_create_dir() 2023-01-18 11:41:09 +01:00
cramfs
crypto
debugfs new helper: lookup_positive_unlocked() 2023-09-23 10:59:40 +02:00
devpts
dlm dlm: fix plock lookup when using multiple lockspaces 2023-09-23 10:59:55 +02:00
ecryptfs ecryptfs: Fix buffer size for tag 66 packet 2024-06-16 13:28:32 +02:00
efivarfs
efs
erofs erofs: fix lz4 inplace decompression 2024-11-08 16:20:49 +01:00
exportfs
ext2 ext2: fix datatype of block number in ext2_xattr_set2() 2023-09-23 11:00:04 +02:00
ext4 ext4: nested locking for xattr inode 2024-11-08 16:20:44 +01:00
f2fs f2fs: Require FMODE_WRITE for atomic write ioctls 2024-11-08 16:20:36 +01:00
fat fat: fix uninitialized variable 2024-11-08 16:20:47 +01:00
freevxfs
fscache
fuse fuse: use unsigned type for getxattr/listxattr size truncation 2024-09-12 11:03:51 +02:00
gfs2 gfs2: setattr_chown: Add missing initialization 2024-09-04 13:14:54 +02:00
hfs hfs: fix to initialize fields of hfs_inode_info after hfs_alloc_inode() 2024-08-19 05:33:36 +02:00
hfsplus hfsplus: don't query the device logical block size multiple times 2024-12-14 19:44:22 +01:00
hostfs
hpfs
hugetlbfs fs,hugetlb: fix NULL pointer dereference in hugetlbs_fill_super 2024-03-06 14:36:10 +00:00
iomap iomap: Set all uptodate bits for an Uptodate page 2024-03-01 13:13:35 +01:00
isofs isofs: handle CDs with bad root inode but good Joliet root directory 2024-04-13 12:51:38 +02:00
jbd2 jbd2: stop waiting for space when jbd2_cleanup_journal_tail() returns error 2024-11-08 16:20:40 +01:00
jffs2 jffs2: Fix potential illegal address access in jffs2_free_inode 2024-07-18 11:40:49 +02:00
jfs jfs: Fix sanity check in dbMount 2024-11-08 16:20:50 +01:00
kernfs fs/kernfs/dir: obey S_ISGID 2024-02-23 08:25:03 +01:00
lockd fs: lockd: avoid possible wrong NULL parameter 2023-09-23 10:59:48 +02:00
minix
nfs nfs: Fix KMSAN warning in decode_getfattr_attrs() 2024-11-17 14:58:51 +01:00
nfs_common
nfsd NFSD: Force all NFSv4.2 COPY requests to be synchronous 2024-12-14 19:44:21 +01:00
nilfs2 nilfs2: fix null-ptr-deref in block_dirty_buffer tracepoint 2024-12-14 19:44:19 +01:00
nls fs/nls: make load_nls() take a const parameter 2023-09-23 10:59:38 +02:00
notify fanotify: disallow mount/sb marks on kernel internal pseudo fs 2023-07-27 08:37:26 +02:00
ntfs ntfs: check overflow when iterating ATTR_RECORDs 2022-11-25 17:42:22 +01:00
ocfs2 ocfs2: fix UBSAN warning in ocfs2_verify_volume() 2024-12-14 19:44:19 +01:00
omfs treewide: Remove uninitialized_var() usage 2023-06-09 10:29:01 +02:00
openpromfs openpromfs: finish conversion to the new mount API 2024-06-16 13:28:32 +02:00
orangefs orangefs: fix out-of-bounds fsid access 2024-07-18 11:40:49 +02:00
overlayfs ovl: skip overlayfs superblocks at global sync 2023-12-08 08:44:27 +01:00
proc proc/softirqs: replace seq_printf with seq_put_decimal_ull_width 2024-12-14 19:44:21 +01:00
pstore pstore/ram: Fix crash when setting number of cpus to an odd number 2024-02-23 08:24:55 +01:00
qnx4
qnx6
quota quota: Remove BUG_ON from dqget() 2024-09-04 13:14:54 +02:00
ramfs
reiserfs reiserfs: Check the return value from __getblk() 2023-09-23 10:59:40 +02:00
romfs
squashfs Squashfs: sanity check symbolic link size 2024-09-12 11:03:55 +02:00
sysfs fs: sysfs: Fix reference leak in sysfs_break_active_protection() 2024-05-02 16:18:32 +02:00
sysv sysv: don't call sb_bread() with pointers_lock held 2024-04-13 12:51:38 +02:00
tracefs tracefs: Add missing lockdown check to tracefs_create_dir() 2023-09-23 11:00:06 +02:00
ubifs ubifs: Set page uptodate in the correct place 2024-04-13 12:51:23 +02:00
udf udf: fix uninit-value use in udf_get_fileshortad 2024-11-08 16:20:50 +01:00
ufs
unicode unicode: Don't special case ignorable code points 2024-11-08 16:20:43 +01:00
verity fsverity: skip PKCS#7 parser when keyring is empty 2023-09-23 10:59:55 +02:00
xfs xfs: verify buffer contents when we skip log replay 2023-06-28 10:18:42 +02:00
aio.c fs/aio: Check IOCB_AIO_RW before the struct aio_kiocb conversion 2024-04-13 12:51:29 +02:00
anon_inodes.c
attr.c attr: block mode changes of symlinks 2023-09-23 11:00:06 +02:00
bad_inode.c
binfmt_aout.c binfmt: Move install_exec_creds after setup_new_exec to match binfmt_elf 2023-01-18 11:41:46 +01:00
binfmt_elf.c
binfmt_elf_fdpic.c fs: binfmt_elf_efpic: don't use missing interpreter's properties 2024-09-04 13:14:54 +02:00
binfmt_em86.c
binfmt_flat.c binfmt: Move install_exec_creds after setup_new_exec to match binfmt_elf 2023-01-18 11:41:46 +01:00
binfmt_misc.c binfmt_misc: cleanup on filesystem umount 2024-09-04 13:14:53 +02:00
binfmt_script.c
block_dev.c block: Don't invalidate pagecache for invalid falloc modes 2024-01-08 11:29:48 +01:00
buffer.c mm: fs: initialize fsdata passed to write_begin/write_end interface 2022-11-25 17:42:22 +01:00
char_dev.c chardev: fix error handling in cdev_device_add() 2023-01-18 11:41:25 +01:00
compat.c
compat_binfmt_elf.c
compat_ioctl.c lsm: new security_file_ioctl_compat() hook 2024-02-23 08:25:15 +01:00
coredump.c
d_path.c
dax.c
dcache.c fs: better handle deep ancestor chains in is_subdir() 2024-07-27 10:38:32 +02:00
dcookies.c
direct-io.c
drop_caches.c
eventfd.c eventfd: prevent underflow for eventfd semaphores 2023-09-23 10:59:40 +02:00
eventpoll.c epoll: ep_autoremove_wake_function should use list_del_init_careful 2023-06-28 10:18:35 +02:00
exec.c parisc: Fix stack start for ADDR_NO_RANDOMIZE personality 2024-11-08 16:20:40 +01:00
fcntl.c fs: Fix file_set_fowner LSM hook inconsistencies 2024-11-08 16:20:34 +01:00
fhandle.c do_sys_name_to_handle(): use kzalloc() to fix kernel-infoleak 2024-03-26 18:22:13 -04:00
file.c fix bitmap corruption on close_range() with CLOSE_RANGE_UNSHARE 2024-09-04 13:14:50 +02:00
file_table.c
filesystems.c
fs-writeback.c writeback: fix call of incorrect macro 2023-05-17 11:35:58 +02:00
fs_context.c fs: avoid empty option when generating legacy mount string 2023-07-27 08:37:25 +02:00
fs_parser.c
fs_pin.c
fs_struct.c
fs_types.c
fsopen.c
inode.c vfs: fix race between evice_inodes() and find_inode()&iput() 2024-11-08 16:20:34 +01:00
internal.h fs: Establish locking order for unrelated directories 2023-07-27 08:37:26 +02:00
io_uring.c io_uring: fail NOP if non-zero op flags is passed in 2024-06-16 13:28:48 +02:00
ioctl.c
Kconfig
Kconfig.binfmt
libfs.c libfs: add DEFINE_SIMPLE_ATTRIBUTE_SIGNED for signed value 2023-01-18 11:40:55 +01:00
locks.c filelock: Correct the filelock owner in fcntl_setlk/fcntl_setlk64 2024-09-04 13:15:02 +02:00
Makefile
mbcache.c mbcache: Avoid nesting of cache->c_list_lock under bit locks 2023-01-18 11:41:59 +01:00
mount.h
mpage.c
namei.c fs: move S_ISGID stripping into the vfs_*() helpers 2024-02-23 08:24:49 +01:00
namespace.c mount: handle OOM on mnt_warn_timestamp_expiry 2024-11-08 16:20:26 +01:00
no-block.c
nsfs.c
open.c ftruncate: pass a signed offset 2024-07-05 09:08:31 +02:00
pipe.c
pnode.c pnode: terminate at peers of source 2023-01-18 11:41:44 +01:00
pnode.h
posix_acl.c
proc_namespace.c
read_write.c
readdir.c
select.c fs/select: rework stack allocation hack for clang 2024-03-26 18:22:13 -04:00
seq_file.c
signalfd.c
splice.c
stack.c
stat.c
statfs.c statfs: enforce statfs[64] structure initialization 2023-05-30 12:44:07 +01:00
super.c fs: explicitly unregister per-superblock BDIs 2024-11-08 16:20:26 +01:00
sync.c ovl: skip overlayfs superblocks at global sync 2023-12-08 08:44:27 +01:00
timerfd.c
userfaultfd.c
utimes.c
xattr.c fs: don't audit the capability check in simple_xattr_list() 2023-01-18 11:40:53 +01:00