Linux kernel mirror (for testing) git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git
kernel os linux
1
fork

Configure Feed

Select the types of activity you want to include in your feed.

ext4: guard against EA inode refcount underflow in xattr update

syzkaller found a path where ext4_xattr_inode_update_ref() reads an EA
inode refcount that is already <= 0 and then applies ref_change (often
-1). That lets the refcount underflow and we proceed with a bogus value,
triggering errors like:

EXT4-fs error: EA inode <n> ref underflow: ref_count=-1 ref_change=-1
EXT4-fs warning: ea_inode dec ref err=-117

Make the invariant explicit: if the current refcount is non-positive,
treat this as on-disk corruption, emit ext4_error_inode(), and fail the
operation with -EFSCORRUPTED instead of updating the refcount. Delete the
WARN_ONCE() as negative refcounts are now impossible; keep error reporting
in ext4_error_inode().

This prevents the underflow and the follow-on orphan/cleanup churn.

Reported-by: syzbot+0be4f339a8218d2a5bb1@syzkaller.appspotmail.com
Fixes: https://syzbot.org/bug?extid=0be4f339a8218d2a5bb1
Cc: stable@kernel.org
Co-developed-by: Albin Babu Varghese <albinbabuvarghese20@gmail.com>
Signed-off-by: Albin Babu Varghese <albinbabuvarghese20@gmail.com>
Signed-off-by: Ahmet Eray Karadag <eraykrdg1@gmail.com>
Message-ID: <20250920021342.45575-1-eraykrdg1@gmail.com>
Signed-off-by: Theodore Ts'o <tytso@mit.edu>

authored by

Ahmet Eray Karadag and committed by
Theodore Ts'o
57295e83 04a91570

+8 -7
+8 -7
fs/ext4/xattr.c
··· 1019 1019 int ref_change) 1020 1020 { 1021 1021 struct ext4_iloc iloc; 1022 - s64 ref_count; 1022 + u64 ref_count; 1023 1023 int ret; 1024 1024 1025 1025 inode_lock_nested(ea_inode, I_MUTEX_XATTR); ··· 1029 1029 goto out; 1030 1030 1031 1031 ref_count = ext4_xattr_inode_get_ref(ea_inode); 1032 + if ((ref_count == 0 && ref_change < 0) || (ref_count == U64_MAX && ref_change > 0)) { 1033 + ext4_error_inode(ea_inode, __func__, __LINE__, 0, 1034 + "EA inode %lu ref wraparound: ref_count=%lld ref_change=%d", 1035 + ea_inode->i_ino, ref_count, ref_change); 1036 + ret = -EFSCORRUPTED; 1037 + goto out; 1038 + } 1032 1039 ref_count += ref_change; 1033 1040 ext4_xattr_inode_set_ref(ea_inode, ref_count); 1034 1041 1035 1042 if (ref_change > 0) { 1036 - WARN_ONCE(ref_count <= 0, "EA inode %lu ref_count=%lld", 1037 - ea_inode->i_ino, ref_count); 1038 - 1039 1043 if (ref_count == 1) { 1040 1044 WARN_ONCE(ea_inode->i_nlink, "EA inode %lu i_nlink=%u", 1041 1045 ea_inode->i_ino, ea_inode->i_nlink); ··· 1048 1044 ext4_orphan_del(handle, ea_inode); 1049 1045 } 1050 1046 } else { 1051 - WARN_ONCE(ref_count < 0, "EA inode %lu ref_count=%lld", 1052 - ea_inode->i_ino, ref_count); 1053 - 1054 1047 if (ref_count == 0) { 1055 1048 WARN_ONCE(ea_inode->i_nlink != 1, 1056 1049 "EA inode %lu i_nlink=%u",