Skip to content

Commit 06c6dcb

Browse files
tytsosashalevin
authored andcommitted
ext4: fix hang when processing corrupted orphaned inode list
[ Upstream commit c9eb13a ] If the orphaned inode list contains inode #5, ext4_iget() returns a bad inode (since the bootloader inode should never be referenced directly). Because of the bad inode, we end up processing the inode repeatedly and this hangs the machine. This can be reproduced via: mke2fs -t ext4 /tmp/foo.img 100 debugfs -w -R "ssv last_orphan 5" /tmp/foo.img mount -o loop /tmp/foo.img /mnt (But don't do this if you are using an unpatched kernel if you care about the system staying functional. :-) This bug was found by the port of American Fuzzy Lop into the kernel to find file system problems[1]. (Since it *only* happens if inode #5 shows up on the orphan list --- 3, 7, 8, etc. won't do it, it's not surprising that AFL needed two hours before it found it.) [1] http://events.linuxfoundation.org/sites/events/files/slides/AFL%20filesystem%20fuzzing%2C%20Vault%202016_0.pdf Cc: [email protected] Reported by: Vegard Nossum <[email protected]> Signed-off-by: Theodore Ts'o <[email protected]> Signed-off-by: Sasha Levin <[email protected]>
1 parent bb3412e commit 06c6dcb

File tree

1 file changed

+6
-4
lines changed

1 file changed

+6
-4
lines changed

fs/ext4/ialloc.c

Lines changed: 6 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -1142,11 +1142,13 @@ struct inode *ext4_orphan_get(struct super_block *sb, unsigned long ino)
11421142
goto iget_failed;
11431143

11441144
/*
1145-
* If the orphans has i_nlinks > 0 then it should be able to be
1146-
* truncated, otherwise it won't be removed from the orphan list
1147-
* during processing and an infinite loop will result.
1145+
* If the orphans has i_nlinks > 0 then it should be able to
1146+
* be truncated, otherwise it won't be removed from the orphan
1147+
* list during processing and an infinite loop will result.
1148+
* Similarly, it must not be a bad inode.
11481149
*/
1149-
if (inode->i_nlink && !ext4_can_truncate(inode))
1150+
if ((inode->i_nlink && !ext4_can_truncate(inode)) ||
1151+
is_bad_inode(inode))
11501152
goto bad_orphan;
11511153

11521154
if (NEXT_ORPHAN(inode) > max_ino)

0 commit comments

Comments
 (0)