Re: [PATCH] isofs: reject short directory records in isofs_read_level3_size()
From: Jan Kara
Date: Thu Sep 24 2026 - 11:08:30 EST
Hi!
On Thu 24-09-26 01:52:15, Matthias Goergens wrote:
> I'm sorry, I missed your patch when I sent mine for the same function a
> few days later ("[PATCH v2] isofs: validate directory records in
> isofs_read_level3_size()"), and Jan has since applied mine to his tree.
>
> I did test yours, on mainline and on Jan's for_next, running fs/isofs in
> a userspace harness with ASan and UBSan: it fixes the three fuzzer
> images that made isofs_read_level3_size() read past a record, and I
> found no change on valid multi-extent images.
For record I think your fix was better because it used proper entry
validation helper which catches more problems.
> The part of yours that mine doesn't have is the limit on how many empty
> blocks the walk skips. Without it, a run of zero blocks is walked until
> the end of the device. On top of for_next that would be a small
> follow-up, and if you'd like to send it I'm happy to test and review it.
> If you'd rather I send it, I'll credit you with Suggested-by, or with
> Co-developed-by followed by your Signed-off-by if you prefer.
Based on the standard empty directory blocks are not allowed (there must be
at least one directory record in each directory block). So I'd perhaps just
add checks to refuse them. Then the limit on the number of sections of inode
description already present in isofs_read_level3_size() will naturally take
care of the rest.
Honza
--
Jan Kara <jack@xxxxxxxx>
SUSE Labs, CR