[PATCH v4 5/6] qnx6: abort mount on superblock magic mismatch when silent is set in qnx6_mmi_fill_super()

From: Hui Peng

Date: Tue Sep 29 2026 - 23:17:55 EST


In qnx6_mmi_fill_super(), if sb1->sb_magic does not match QNX6_SUPER_MAGIC,
the goto out error path was placed inside the if (!silent) block. If silent
mount is requested (silent != 0), execution fell through to crc32_be() on
invalid superblock data.

Move goto out outside the if (!silent) block so qnx6_mmi_fill_super()
always aborts mount when superblock magic does not match.

Tested in QEMU against tip of mainline commit 62f4c998b297 ("Merge tag 'parisc-for-7.3-rc5' of git://git.kernel.org/pub/scm/linux/kernel/git/deller/parisc-linux")
using a loop-device reproducer mounting an image with invalid
sb_magic=0xdeadbeef and MS_SILENT: on the unfixed kernel, mount succeeded
(rc=0); whereas with this fix applied, qnx6_mmi_fill_super() rejects the
corrupted superblock magic cleanly (rc=-1 errno=22 EINVAL).

Fixes: 5d026c724220 ("fs: initial qnx6fs addition")
Cc: stable@xxxxxxxxxxxxxxx
Assisted-by: LLM
Signed-off-by: Hui Peng <benquike@xxxxxxxxx>
---
Changes in v4:
- Rebased cleanly onto upstream mainline commit 62f4c998b297.
- Added QEMU test procedure and verification details in commit message body.

fs/qnx6/super_mmi.c | 5 ++---
1 file changed, 2 insertions(+), 3 deletions(-)

diff --git a/fs/qnx6/super_mmi.c b/fs/qnx6/super_mmi.c
index 797d8c238bbb..5f62df30467b 100644
--- a/fs/qnx6/super_mmi.c
+++ b/fs/qnx6/super_mmi.c
@@ -51,10 +51,9 @@ struct qnx6_super_block *qnx6_mmi_fill_super(struct super_block *s, int silent)
sb1 = (struct qnx6_mmi_super_block *)bh1->b_data;
sbi = QNX6_SB(s);
if (fs32_to_cpu(sbi, sb1->sb_magic) != QNX6_SUPER_MAGIC) {
- if (!silent) {
+ if (!silent)
pr_err("wrong signature (magic) in superblock #1.\n");
- goto out;
- }
+ goto out;
}

/* checksum check - start at byte 8 and end at byte 512 */
--
2.55.0.1082.g2b9226bbc0-goog