[PATCH v2 2/2] ocfs2: validate dl_blkno and dl_fs_generation of dir index leaf blocks
From: Joseph Qi
Date: Sat Sep 05 2026 - 10:22:39 EST
ocfs2_validate_dx_leaf() checks the checksum, the signature and the
entry list counts, but it never checks dl_blkno or dl_fs_generation.
The inode, extent block, xattr block, refcount block and dir index root
validators all check the on-disk block number against bh->b_blocknr and
the generation against the superblock, and both dir index leaf fields
are documented as "Must match super block".
Without the checks, a stale dir index leaf block left on the device from
a previously formatted filesystem at the same physical block number can
pass validation as long as its signature, entry counts and checksum
match. Its index entries would then be used in the new filesystem
context.
Both fields are written unconditionally when a leaf block is formatted
in ocfs2_dx_dir_format_cluster(), from the live superblock generation
and the real block number, so a correctly formatted filesystem cannot
trip the new checks. The leaf block number read back here comes from
on-disk dir index root extent records.
Reject dir index leaf blocks whose dl_blkno or dl_fs_generation does not
match, like the dir index root validator does.
Signed-off-by: Joseph Qi <joseph.qi@xxxxxxxxxxxxxxxxx>
---
fs/ocfs2/dir.c | 12 ++++++++++++
1 file changed, 12 insertions(+)
diff --git a/fs/ocfs2/dir.c b/fs/ocfs2/dir.c
index 329680b46227..55c4a305a282 100644
--- a/fs/ocfs2/dir.c
+++ b/fs/ocfs2/dir.c
@@ -733,6 +733,18 @@ static int ocfs2_validate_dx_leaf(struct super_block *sb,
return ocfs2_error(sb, "Dir Index Leaf has bad signature %.*s\n",
7, dx_leaf->dl_signature);
+ if (le64_to_cpu(dx_leaf->dl_blkno) != bh->b_blocknr)
+ return ocfs2_error(sb,
+ "Dir Index Leaf # %llu has an invalid dl_blkno of %llu\n",
+ (unsigned long long)bh->b_blocknr,
+ (unsigned long long)le64_to_cpu(dx_leaf->dl_blkno));
+
+ if (le32_to_cpu(dx_leaf->dl_fs_generation) != OCFS2_SB(sb)->fs_generation)
+ return ocfs2_error(sb,
+ "Dir Index Leaf # %llu has an invalid dl_fs_generation of #%u\n",
+ (unsigned long long)bh->b_blocknr,
+ le32_to_cpu(dx_leaf->dl_fs_generation));
+
if (le16_to_cpu(dx_leaf->dl_list.de_count) !=
ocfs2_dx_entries_per_leaf(sb))
return ocfs2_error(sb,
--
2.39.3