Re: [PATCH v2 2/2] ocfs2: validate dl_blkno and dl_fs_generation of dir index leaf blocks

From: Joseph Qi

Date: Sun Sep 06 2026 - 03:55:28 EST




On 9/5/26 10:45 PM, Heming Zhao wrote:
> On Sat, Sep 05, 2026 at 10:21:44PM +0800, Joseph Qi wrote:
>> ocfs2_validate_dx_leaf() checks the checksum, the signature and the
>> entry list counts, but it never checks dl_blkno or dl_fs_generation.
>> The inode, extent block, xattr block, refcount block and dir index root
>> validators all check the on-disk block number against bh->b_blocknr and
>> the generation against the superblock, and both dir index leaf fields
>> are documented as "Must match super block".
>>
>> Without the checks, a stale dir index leaf block left on the device from
>> a previously formatted filesystem at the same physical block number can
>> pass validation as long as its signature, entry counts and checksum
>> match. Its index entries would then be used in the new filesystem
>> context.
>>
>> Both fields are written unconditionally when a leaf block is formatted
>> in ocfs2_dx_dir_format_cluster(), from the live superblock generation
>> and the real block number, so a correctly formatted filesystem cannot
>> trip the new checks. The leaf block number read back here comes from
>> on-disk dir index root extent records.
>>
>> Reject dir index leaf blocks whose dl_blkno or dl_fs_generation does not
>> match, like the dir index root validator does.
>>
>> Signed-off-by: Joseph Qi <joseph.qi@xxxxxxxxxxxxxxxxx>
>> ---
>> fs/ocfs2/dir.c | 12 ++++++++++++
>> 1 file changed, 12 insertions(+)
>>
>> diff --git a/fs/ocfs2/dir.c b/fs/ocfs2/dir.c
>> index 329680b46227..55c4a305a282 100644
>> --- a/fs/ocfs2/dir.c
>> +++ b/fs/ocfs2/dir.c
>> @@ -733,6 +733,18 @@ static int ocfs2_validate_dx_leaf(struct super_block *sb,
>> return ocfs2_error(sb, "Dir Index Leaf has bad signature %.*s\n",
>> 7, dx_leaf->dl_signature);
>>
>> + if (le64_to_cpu(dx_leaf->dl_blkno) != bh->b_blocknr)
>> + return ocfs2_error(sb,
>> + "Dir Index Leaf # %llu has an invalid dl_blkno of %llu\n",
>> + (unsigned long long)bh->b_blocknr,
>> + (unsigned long long)le64_to_cpu(dx_leaf->dl_blkno));
>
> The patch looks fine to me.
> Reviewed-by: Heming Zhao <heming.zhao@xxxxxxxx>
>
> Only question: Do we add the same check for dl_blkno in ocfs2_validate_dx_root()?
>

Yes,it's already added by:
a08f83559463c ocfs2: validate suballoc slot and bit of xattr and dir index blocks

Thanks,
Joseph