Re: [PATCH] nilfs2: handle corrupted checkpoint count gracefully during deletion

From: Ryusuke Konishi

Date: Mon Jul 06 2026 - 12:41:27 EST


On Mon, Jul 6, 2026 at 8:08 PM Igor Putko wrote:
>
> Syzkaller reported a kernel warning in nilfs_cpfile_delete_checkpoints()
> due to a corrupted checkpoint count on the storage medium where
> le32_to_cpu(cp->cp_checkpoints_count) is less than the number of
> checkpoints being deleted.
> Triggering a WARN_ON() for disk image corruption is suboptimal. Fix
> this by returning -EIO and reporting a filesystem error via
> nilfs_error() instead of interrupting execution with a kernel warning.
>
> Reported-by: syzbot+79b815da3aec0a6a4d02@xxxxxxxxxxxxxxxxxxxxxxxxx
> Closes: https://syzkaller.appspot.com/bug?extid=79b815da3aec0a6a4d02
> Signed-off-by: Igor Putko <igorpetindev@xxxxxxxxx>
> ---
> fs/nilfs2/cpfile.c | 20 ++++++++++++++++----
> 1 file changed, 16 insertions(+), 4 deletions(-)

Thanks for the patch proposal!

A filesystem inconsistency is indeed the root cause, and WARN_ON is
undesirably catching it.

The proposed fix looks appropriate to me, so I plan to apply it after
running some tests on my end.

Thanks,
Ryusuke Konishi

>
> diff --git a/fs/nilfs2/cpfile.c b/fs/nilfs2/cpfile.c
> index 4bbdc832d..d3349fa58 100644
> --- a/fs/nilfs2/cpfile.c
> +++ b/fs/nilfs2/cpfile.c
> @@ -81,18 +81,26 @@ nilfs_cpfile_block_add_valid_checkpoints(const struct inode *cpfile,
> return count;
> }
>
> -static unsigned int
> +static int
> nilfs_cpfile_block_sub_valid_checkpoints(const struct inode *cpfile,
> struct buffer_head *bh,
> unsigned int n)
> {
> struct nilfs_checkpoint *cp;
> - unsigned int count;
> + unsigned int checkpoints_count;
> + int count;
>
> cp = kmap_local_folio(bh->b_folio,
> offset_in_folio(bh->b_folio, bh->b_data));
> - WARN_ON(le32_to_cpu(cp->cp_checkpoints_count) < n);
> - count = le32_to_cpu(cp->cp_checkpoints_count) - n;
> + checkpoints_count = le32_to_cpu(cp->cp_checkpoints_count);
> + if (unlikely(checkpoints_count < n)) {
> + nilfs_error(cpfile->i_sb,
> + "deleted checkpoints count %u exceeds block count %u",
> + n, checkpoints_count);
> + kunmap_local(cp);
> + return -EIO;
> + }
> + count = checkpoints_count - n;
> cp->cp_checkpoints_count = cpu_to_le32(count);
> kunmap_local(cp);
> return count;
> @@ -522,6 +530,10 @@ int nilfs_cpfile_delete_checkpoints(struct inode *cpfile,
> count = nilfs_cpfile_block_sub_valid_checkpoints(cpfile, cp_bh,
> nicps);
> brelse(cp_bh);
> + if (unlikely(count < 0)) {
> + ret = count;
> + break;
> + }
> if (count)
> continue;
>
> --
> 2.47.3
>