Skip to content

Commit 09ca8dc

Browse files
committed
Merge tag 'f2fs-for-7.2-rc1' of git://git.kernel.org/pub/scm/linux/kernel/git/jaegeuk/f2fs
Pull f2fs updates from Jaegeuk Kim: "The changes primarily focus on filesystem error reporting, reducing memory footprint by reverting in-memory data structures used for runtime validation, honoring FDP hints, and adding trace and debug logs. In addition, there are critical bug fixes resolving out-of-bounds read vulnerabilities in inline directory and ACL handling, potential deadlocks in balance_fs, use-after-free issues in atomic writes, and false data/node type assignments in large sections. Enhancements: - Revert in-memory sit version and block bitmaps - support to report fserror - add trace_f2fs_fault_report - add iostat latency tracking for direct IO - add logs in f2fs_disable_checkpoint() - honor per-I/O write streams for direct writes - map data writes to FDP streams - skip inode folio lookup for cached overwrite - skip direct I/O iostat context when disabled - revert "check in-memory block bitmap" - revert "check in-memory sit version bitmap" Fixes: - optimize representative type determination in GC - fix incorrect FI_NO_EXTENT handling in __destroy_extent_node() - fix potential deadlock in f2fs_balance_fs() - fix potential deadlock in gc_merge path of f2fs_balance_fs() - atomic: fix UAF issue on f2fs_inode_info.atomic_inode - fix missing read bio submission on large folio error - pass correct iostat type for single node writes - fix to do sanity check on f2fs_get_node_folio_ra() - validate orphan inode entry count - keep atomic write retry from zeroing original data - read COW data with the original inode during atomic write - validate inline dentry name lengths before conversion - validate dentry name length before lookup compares it - reject setattr size changes on large folio files - revert "remove non-uptodate folio from the page cache in move_data_block" - validate ACL entry sizes in f2fs_acl_from_disk() - bound i_inline_xattr_size for non-inline-xattr inodes - fix listxattr handling of corrupted xattr entries - fix to round down start offset of fallocate for pin file" * tag 'f2fs-for-7.2-rc1' of git://git.kernel.org/pub/scm/linux/kernel/git/jaegeuk/f2fs: (42 commits) f2fs: fix to round down start offset of fallocate for pin file f2fs: fix listxattr handling of corrupted xattr entries f2fs: skip direct I/O iostat context when disabled f2fs: remove unneeded f2fs_is_compressed_page() f2fs: avoid unnecessary fscrypt_finalize_bounce_page() f2fs: avoid unnecessary sanity check on ckpt_valid_blocks f2fs: misc cleanup in f2fs_record_stop_reason() f2fs: fix wrong description in printed log f2fs: bound i_inline_xattr_size for non-inline-xattr inodes f2fs: validate ACL entry sizes in f2fs_acl_from_disk() Revert "f2fs: remove non-uptodate folio from the page cache in move_data_block" f2fs: Split f2fs_write_end_io() f2fs: Rename f2fs_post_read_wq into f2fs_wq f2fs: Prepare for supporting delayed bio completion f2fs: reject setattr size changes on large folio files f2fs: validate dentry name length before lookup compares it f2fs: validate inline dentry name lengths before conversion f2fs: read COW data with the original inode during atomic write f2fs: skip inode folio lookup for cached overwrite f2fs: keep atomic write retry from zeroing original data ...
2 parents bade58e + 4275b59 commit 09ca8dc

24 files changed

Lines changed: 502 additions & 183 deletions

File tree

‎Documentation/ABI/testing/sysfs-fs-f2fs‎

Lines changed: 3 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -270,7 +270,8 @@ Description: Shows all enabled kernel features.
270270
inode_checksum, flexible_inline_xattr, quota_ino,
271271
inode_crtime, lost_found, verity, sb_checksum,
272272
casefold, readonly, compression, test_dummy_encryption_v2,
273-
atomic_write, pin_file, encrypted_casefold, linear_lookup.
273+
atomic_write, pin_file, encrypted_casefold, linear_lookup,
274+
fserror.
274275

275276
What: /sys/fs/f2fs/<disk>/inject_rate
276277
Date: May 2016
@@ -1000,4 +1001,4 @@ Contact: "Chao Yu" <chao@kernel.org>
10001001
Description: It can be used to tune priority of f2fs critical task, e.g. f2fs_ckpt, f2fs_gc
10011002
threads, limitation as below:
10021003
- it requires user has CAP_SYS_NICE capability.
1003-
- the range is [100, 139], by default the value is 100.
1004+
- the range is [100, 139], by default the value is 120.

‎Documentation/filesystems/f2fs.rst‎

Lines changed: 9 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -137,6 +137,15 @@ noacl Disable POSIX Access Control List. Note: acl is enabled
137137
active_logs=%u Support configuring the number of active logs. In the
138138
current design, f2fs supports only 2, 4, and 6 logs.
139139
Default number is 6.
140+
When the underlying block device exposes write
141+
streams, the default active_logs=6 configuration
142+
maps hot, warm, and cold DATA writes to streams 1,
143+
2, and 3, respectively. If only one or two write
144+
streams are available, f2fs falls back to mapping
145+
all DATA writes to stream 1 or mapping hot/warm
146+
to stream 1 and cold to stream 2. If no write
147+
streams are exposed, f2fs leaves the stream
148+
unset.
140149
disable_ext_identify Disable the extension list configured by mkfs, so f2fs
141150
is not aware of cold files such as media files.
142151
inline_xattr Enable the inline xattrs feature.

‎fs/f2fs/acl.c‎

Lines changed: 16 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -47,6 +47,7 @@ static inline int f2fs_acl_count(size_t size)
4747
static struct posix_acl *f2fs_acl_from_disk(const char *value, size_t size)
4848
{
4949
int i, count;
50+
int err = -EINVAL;
5051
struct posix_acl *acl;
5152
struct f2fs_acl_header *hdr = (struct f2fs_acl_header *)value;
5253
struct f2fs_acl_entry *entry = (struct f2fs_acl_entry *)(hdr + 1);
@@ -70,8 +71,11 @@ static struct posix_acl *f2fs_acl_from_disk(const char *value, size_t size)
7071

7172
for (i = 0; i < count; i++) {
7273

73-
if ((char *)entry > end)
74+
if (unlikely((char *)entry +
75+
sizeof(struct f2fs_acl_entry_short) > end)) {
76+
err = -EFSCORRUPTED;
7477
goto fail;
78+
}
7579

7680
acl->a_entries[i].e_tag = le16_to_cpu(entry->e_tag);
7781
acl->a_entries[i].e_perm = le16_to_cpu(entry->e_perm);
@@ -86,13 +90,23 @@ static struct posix_acl *f2fs_acl_from_disk(const char *value, size_t size)
8690
break;
8791

8892
case ACL_USER:
93+
if (unlikely((char *)entry +
94+
sizeof(struct f2fs_acl_entry) > end)) {
95+
err = -EFSCORRUPTED;
96+
goto fail;
97+
}
8998
acl->a_entries[i].e_uid =
9099
make_kuid(&init_user_ns,
91100
le32_to_cpu(entry->e_id));
92101
entry = (struct f2fs_acl_entry *)((char *)entry +
93102
sizeof(struct f2fs_acl_entry));
94103
break;
95104
case ACL_GROUP:
105+
if (unlikely((char *)entry +
106+
sizeof(struct f2fs_acl_entry) > end)) {
107+
err = -EFSCORRUPTED;
108+
goto fail;
109+
}
96110
acl->a_entries[i].e_gid =
97111
make_kgid(&init_user_ns,
98112
le32_to_cpu(entry->e_id));
@@ -108,7 +122,7 @@ static struct posix_acl *f2fs_acl_from_disk(const char *value, size_t size)
108122
return acl;
109123
fail:
110124
posix_acl_release(acl);
111-
return ERR_PTR(-EINVAL);
125+
return ERR_PTR(err);
112126
}
113127

114128
static void *f2fs_acl_to_disk(struct f2fs_sb_info *sbi,

‎fs/f2fs/checkpoint.c‎

Lines changed: 13 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -943,6 +943,7 @@ int f2fs_recover_orphan_inodes(struct f2fs_sb_info *sbi)
943943
for (i = 0; i < orphan_blocks; i++) {
944944
struct folio *folio;
945945
struct f2fs_orphan_block *orphan_blk;
946+
unsigned int entry_count;
946947

947948
folio = f2fs_get_meta_folio(sbi, start_blk + i);
948949
if (IS_ERR(folio)) {
@@ -951,7 +952,18 @@ int f2fs_recover_orphan_inodes(struct f2fs_sb_info *sbi)
951952
}
952953

953954
orphan_blk = folio_address(folio);
954-
for (j = 0; j < le32_to_cpu(orphan_blk->entry_count); j++) {
955+
entry_count = le32_to_cpu(orphan_blk->entry_count);
956+
if (entry_count > F2FS_ORPHANS_PER_BLOCK) {
957+
f2fs_err(sbi, "invalid orphan inode entry count %u",
958+
entry_count);
959+
set_sbi_flag(sbi, SBI_NEED_FSCK);
960+
f2fs_handle_error(sbi, ERROR_INCONSISTENT_ORPHAN);
961+
err = -EFSCORRUPTED;
962+
f2fs_folio_put(folio, true);
963+
goto out;
964+
}
965+
966+
for (j = 0; j < entry_count; j++) {
955967
nid_t ino = le32_to_cpu(orphan_blk->ino[j]);
956968

957969
err = recover_orphan_inode(sbi, ino);

‎fs/f2fs/compress.c‎

Lines changed: 7 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -14,6 +14,7 @@
1414
#include <linux/lz4.h>
1515
#include <linux/zstd.h>
1616
#include <linux/folio_batch.h>
17+
#include <linux/fserror.h>
1718

1819
#include "f2fs.h"
1920
#include "node.h"
@@ -760,6 +761,7 @@ void f2fs_decompress_cluster(struct decompress_io_ctx *dic, bool in_task)
760761

761762
/* Avoid f2fs_commit_super in irq context */
762763
f2fs_handle_error(sbi, ERROR_FAIL_DECOMPRESSION);
764+
fserror_report_file_metadata(dic->inode, ret, GFP_NOFS);
763765
goto out_release;
764766
}
765767

@@ -1453,6 +1455,9 @@ static int f2fs_write_compressed_pages(struct compress_ctx *cc,
14531455
out_destroy_crypt:
14541456
page_array_free(sbi, cic->rpages, cc->cluster_size);
14551457

1458+
if (!fio.encrypted)
1459+
goto out_put_cic;
1460+
14561461
for (--i; i >= 0; i--) {
14571462
if (!cc->cpages[i])
14581463
continue;
@@ -1482,8 +1487,7 @@ void f2fs_compress_write_end_io(struct bio *bio, struct folio *folio)
14821487
struct page *page = &folio->page;
14831488
struct f2fs_sb_info *sbi = bio->bi_private;
14841489
struct compress_io_ctx *cic = folio->private;
1485-
enum count_type type = WB_DATA_TYPE(folio,
1486-
f2fs_is_compressed_page(folio));
1490+
enum count_type type = WB_DATA_TYPE(folio, true);
14871491
int i;
14881492

14891493
if (unlikely(bio->bi_status != BLK_STS_OK))
@@ -1807,7 +1811,7 @@ static void f2fs_put_dic(struct decompress_io_ctx *dic, bool in_task)
18071811
f2fs_free_dic(dic, false);
18081812
} else {
18091813
INIT_WORK(&dic->free_work, f2fs_late_free_dic);
1810-
queue_work(dic->sbi->post_read_wq, &dic->free_work);
1814+
queue_work(dic->sbi->wq, &dic->free_work);
18111815
}
18121816
}
18131817
}

0 commit comments

Comments
 (0)