Received: by 2002:a05:6a10:8c0a:0:0:0:0 with SMTP id go10csp1977180pxb; Fri, 5 Mar 2021 04:36:32 -0800 (PST) X-Google-Smtp-Source: ABdhPJz7qZnrb87fe0W5xdgBAjjeebWrOdoINglGCwhcynSYiBqOYrLYrkMifczJeQEZVTAB9p2x X-Received: by 2002:aa7:c843:: with SMTP id g3mr9023598edt.228.1614947792199; Fri, 05 Mar 2021 04:36:32 -0800 (PST) ARC-Seal: i=1; a=rsa-sha256; t=1614947792; cv=none; d=google.com; s=arc-20160816; b=R328ZsHXQxcQvbIA1uMEpUer0x3r70fw7M5LolJ0DQuoc1EUE5lit5HeuCMNZeueK3 Z+CSZaFEEGncWxUZqeGwjnVbNNZg0iHb6a9I93pEgKfKxt8U1mfru8rSQY/Zonywmcu8 KShuth8EsRCbLxNxGAJKtg4XI6KVkQy5WheKMUtZYBcAuAOZJNkeHemJzC4bZ1TeOLrc 0AAzUpTVQ0e4AXeAThWTHThhQkyY6A6gH0vNUaHK2mrS/JqHYxl/CdKKFR82AcLShayL XXRg6/wE+JzlUdIxFsXMJbTWAtjRXSlN6TqwrQDBTzWG2K6SAfsOzsFxPZ5H1OnC346u gIqA== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:content-transfer-encoding:mime-version :user-agent:references:in-reply-to:message-id:date:subject:cc:to :from:dkim-signature; bh=C24l4BdIaFOrVp/Gs4OxMZDdiW6S0NoB36z5k+2XV4c=; b=z+gE+h3sv/hRpOL4wns9+N1bXAWxthR/OfV/LyUjjUvTK6m0htgCLZQftLkoW6Kh5m PVxr4+L74tDJHADzPThsmfMnPxCDKBOhe22QMDFP9cNw4TvhqwFE6cHj5uOK21x9pHE3 8xyx9wFtlh46jE6tanZwebDHma0OEeL29nUkRGKDQQUxrLHiO3BBFM6IkNHTVoJAXSR+ xVQZOLaBJXqhVkCmD+PY9mdssdsiSydc5RYGwjuOxD4ezn9wBBJmKHNSdmDVfvJU+45K OhKT3FkmcFHn9A8TyP0O/dD2vqcZVSxVfiZE29YCHZtpZlUo68eXELtVZ0wRGytO+RsK FXRQ== ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@linuxfoundation.org header.s=korg header.b=QLbN5jt0; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 23.128.96.18 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=linuxfoundation.org Return-Path: Received: from vger.kernel.org (vger.kernel.org. [23.128.96.18]) by mx.google.com with ESMTP id y13si1446379edm.557.2021.03.05.04.36.08; Fri, 05 Mar 2021 04:36:32 -0800 (PST) Received-SPF: pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 23.128.96.18 as permitted sender) client-ip=23.128.96.18; Authentication-Results: mx.google.com; dkim=pass header.i=@linuxfoundation.org header.s=korg header.b=QLbN5jt0; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 23.128.96.18 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=linuxfoundation.org Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S231976AbhCEMe2 (ORCPT + 99 others); Fri, 5 Mar 2021 07:34:28 -0500 Received: from mail.kernel.org ([198.145.29.99]:44956 "EHLO mail.kernel.org" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S231362AbhCEMds (ORCPT ); Fri, 5 Mar 2021 07:33:48 -0500 Received: by mail.kernel.org (Postfix) with ESMTPSA id F170465004; Fri, 5 Mar 2021 12:33:47 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=linuxfoundation.org; s=korg; t=1614947628; bh=4CgwHuUXHbjaJ1tcVEVsLFIfm+G2M+11iHmp3wU+JPw=; h=From:To:Cc:Subject:Date:In-Reply-To:References:From; b=QLbN5jt0hSkenlgKak4lHGX9DpO46sndtVeES+FRd+a0Ve00Ik/3lqZ61CuZDEhuo uk5rIlYFgkjozgSUxHqZXDO6ZDPJLaursBXmMJYvOCUrEdUOxtzK11R0wPbshZPB4B N6HW1MPyOIhGwcyiA6S67vcfLOQmJXTtZiRfFDok= From: Greg Kroah-Hartman To: linux-kernel@vger.kernel.org Cc: Greg Kroah-Hartman , stable@vger.kernel.org, syzbot+36315852ece4132ec193@syzkaller.appspotmail.com, Randy Dunlap , Dave Kleikamp , jfs-discussion@lists.sourceforge.net, kernel test robot Subject: [PATCH 5.4 07/72] JFS: more checks for invalid superblock Date: Fri, 5 Mar 2021 13:21:09 +0100 Message-Id: <20210305120857.704783536@linuxfoundation.org> X-Mailer: git-send-email 2.30.1 In-Reply-To: <20210305120857.341630346@linuxfoundation.org> References: <20210305120857.341630346@linuxfoundation.org> User-Agent: quilt/0.66 MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org From: Randy Dunlap commit 3bef198f1b17d1bb89260bad947ef084c0a2d1a6 upstream. syzbot is feeding invalid superblock data to JFS for mount testing. JFS does not check several of the fields -- just assumes that they are good since the JFS_MAGIC and version fields are good. In this case (syzbot reproducer), we have s_l2bsize == 0xda0c, pad == 0xf045, and s_state == 0x50, all of which are invalid IMO. Having s_l2bsize == 0xda0c causes this UBSAN warning: UBSAN: shift-out-of-bounds in fs/jfs/jfs_mount.c:373:25 shift exponent -9716 is negative s_l2bsize can be tested for correctness. pad can be tested for non-0 and punted. s_state can be tested for its valid values and punted. Do those 3 tests and if any of them fails, report the superblock as invalid/corrupt and let fsck handle it. With this patch, chkSuper() says this when JFS_DEBUG is enabled: jfs_mount: Mount Failure: superblock is corrupt! Mount JFS Failure: -22 jfs_mount failed w/return code = -22 The obvious problem with this method is that next week there could be another syzbot test that uses different fields for invalid values, this making this like a game of whack-a-mole. syzkaller link: https://syzkaller.appspot.com/bug?extid=36315852ece4132ec193 Reported-by: syzbot+36315852ece4132ec193@syzkaller.appspotmail.com Reported-by: kernel test robot # v2 Signed-off-by: Randy Dunlap Signed-off-by: Dave Kleikamp Cc: jfs-discussion@lists.sourceforge.net Signed-off-by: Greg Kroah-Hartman --- fs/jfs/jfs_filsys.h | 1 + fs/jfs/jfs_mount.c | 10 ++++++++++ 2 files changed, 11 insertions(+) --- a/fs/jfs/jfs_filsys.h +++ b/fs/jfs/jfs_filsys.h @@ -268,5 +268,6 @@ * fsck() must be run to repair */ #define FM_EXTENDFS 0x00000008 /* file system extendfs() in progress */ +#define FM_STATE_MAX 0x0000000f /* max value of s_state */ #endif /* _H_JFS_FILSYS */ --- a/fs/jfs/jfs_mount.c +++ b/fs/jfs/jfs_mount.c @@ -36,6 +36,7 @@ #include #include +#include #include "jfs_incore.h" #include "jfs_filsys.h" @@ -365,6 +366,15 @@ static int chkSuper(struct super_block * sbi->bsize = bsize; sbi->l2bsize = le16_to_cpu(j_sb->s_l2bsize); + /* check some fields for possible corruption */ + if (sbi->l2bsize != ilog2((u32)bsize) || + j_sb->pad != 0 || + le32_to_cpu(j_sb->s_state) > FM_STATE_MAX) { + rc = -EINVAL; + jfs_err("jfs_mount: Mount Failure: superblock is corrupt!"); + goto out; + } + /* * For now, ignore s_pbsize, l2bfactor. All I/O going through buffer * cache.