Skip to content

Commit af15e52

Browse files
eraykaradagUlrich Hecht
authored andcommitted
ext4: guard against EA inode refcount underflow in xattr update
commit 57295e835408d8d425bef58da5253465db3d6888 upstream. syzkaller found a path where ext4_xattr_inode_update_ref() reads an EA inode refcount that is already <= 0 and then applies ref_change (often -1). That lets the refcount underflow and we proceed with a bogus value, triggering errors like: EXT4-fs error: EA inode <n> ref underflow: ref_count=-1 ref_change=-1 EXT4-fs warning: ea_inode dec ref err=-117 Make the invariant explicit: if the current refcount is non-positive, treat this as on-disk corruption, emit ext4_error_inode(), and fail the operation with -EFSCORRUPTED instead of updating the refcount. Delete the WARN_ONCE() as negative refcounts are now impossible; keep error reporting in ext4_error_inode(). This prevents the underflow and the follow-on orphan/cleanup churn. Reported-by: syzbot+0be4f339a8218d2a5bb1@syzkaller.appspotmail.com Fixes: https://syzbot.org/bug?extid=0be4f339a8218d2a5bb1 Cc: stable@kernel.org Co-developed-by: Albin Babu Varghese <albinbabuvarghese20@gmail.com> Signed-off-by: Albin Babu Varghese <albinbabuvarghese20@gmail.com> Signed-off-by: Ahmet Eray Karadag <eraykrdg1@gmail.com> Message-ID: <20250920021342.45575-1-eraykrdg1@gmail.com> Signed-off-by: Theodore Ts'o <tytso@mit.edu> Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org> Signed-off-by: Ulrich Hecht <uli@kernel.org>
1 parent 02eb86d commit af15e52

1 file changed

Lines changed: 8 additions & 7 deletions

File tree

fs/ext4/xattr.c

Lines changed: 8 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -1050,7 +1050,7 @@ static int ext4_xattr_inode_update_ref(handle_t *handle, struct inode *ea_inode,
10501050
int ref_change)
10511051
{
10521052
struct ext4_iloc iloc;
1053-
s64 ref_count;
1053+
u64 ref_count;
10541054
int ret;
10551055

10561056
inode_lock_nested(ea_inode, I_MUTEX_XATTR);
@@ -1062,13 +1062,17 @@ static int ext4_xattr_inode_update_ref(handle_t *handle, struct inode *ea_inode,
10621062
}
10631063

10641064
ref_count = ext4_xattr_inode_get_ref(ea_inode);
1065+
if ((ref_count == 0 && ref_change < 0) || (ref_count == U64_MAX && ref_change > 0)) {
1066+
ext4_error_inode(ea_inode, __func__, __LINE__, 0,
1067+
"EA inode %lu ref wraparound: ref_count=%lld ref_change=%d",
1068+
ea_inode->i_ino, ref_count, ref_change);
1069+
ret = -EFSCORRUPTED;
1070+
goto out;
1071+
}
10651072
ref_count += ref_change;
10661073
ext4_xattr_inode_set_ref(ea_inode, ref_count);
10671074

10681075
if (ref_change > 0) {
1069-
WARN_ONCE(ref_count <= 0, "EA inode %lu ref_count=%lld",
1070-
ea_inode->i_ino, ref_count);
1071-
10721076
if (ref_count == 1) {
10731077
WARN_ONCE(ea_inode->i_nlink, "EA inode %lu i_nlink=%u",
10741078
ea_inode->i_ino, ea_inode->i_nlink);
@@ -1077,9 +1081,6 @@ static int ext4_xattr_inode_update_ref(handle_t *handle, struct inode *ea_inode,
10771081
ext4_orphan_del(handle, ea_inode);
10781082
}
10791083
} else {
1080-
WARN_ONCE(ref_count < 0, "EA inode %lu ref_count=%lld",
1081-
ea_inode->i_ino, ref_count);
1082-
10831084
if (ref_count == 0) {
10841085
WARN_ONCE(ea_inode->i_nlink != 1,
10851086
"EA inode %lu i_nlink=%u",

0 commit comments

Comments
 (0)