Re: [PATCH] udf: fix return value for non-recorded-allocated extents in udf_map_block()
From: Jan Kara
Date: Wed Sep 30 2026 - 07:50:03 EST
On Mon 28-09-26 13:04:45, Giorgi Kobakhia wrote:
> In the if (!(map->iflags & UDF_MAP_CREATE)) check the ret is set to
> inode_bmap(inode, map->lblk, &epos, &eloc, &elen, &offset, &etype),
> which returns 1 on success, -errno on error and 0 on EOF. ret is set
> back to 0 only if the etype of the extent is EXT_RECORDED_ALLOCATED.
> In other cases the ret is still equal to 1, which is not a valid return
> value for udf_map_block() and is later accessed in page_get_link().
>
> Oops: general protection fault
> KASAN: maybe wild-memory-access
> RIP: 0010:page_get_link (fs/namei.c:6503)
> Call Trace:
> vfs_readlink (fs/namei.c:6419)
> do_readlinkat (fs/stat.c:583)
> __x64_sys_readlink (fs/stat.c:605 fs/stat.c:602 fs/stat.c:602)
>
> Move the reset to 0 line outside the if, so udf_map_block() returns either
> 0 or -errno, even if the extent type is not EXT_RECORDED_ALLOCATED.
>
> Fixes: c226964ec786 ("udf: refactor inode_bmap() to handle error")
> Cc: stable@xxxxxxxxxxxxxxx
> Assisted-by: LLM
> Tested-by: Xiang Mei <xmei5@xxxxxxx>
> Signed-off-by: Giorgi Kobakhia <gkobakhi@xxxxxxx>
Thanks for the fix! I've just rewritten the changelog to explain this can
happen only for corrupted filesystems and added the fix to my tree.
Honza
> ---
> fs/udf/inode.c | 2 +-
> 1 file changed, 1 insertion(+), 1 deletion(-)
>
> diff --git a/fs/udf/inode.c b/fs/udf/inode.c
> index e45e546a739a..2f04c4f0e1b8 100644
> --- a/fs/udf/inode.c
> +++ b/fs/udf/inode.c
> @@ -372,8 +372,8 @@ static int udf_map_block(struct inode *inode, struct udf_map_rq *map)
> map->pblk = udf_get_lb_pblock(inode->i_sb, &eloc,
> offset);
> map->oflags |= UDF_BLK_MAPPED;
> - ret = 0;
> }
> + ret = 0;
> out_read:
> up_read(&iinfo->i_data_sem);
> brelse(epos.bh);
> --
> 2.43.0
>
--
Jan Kara <jack@xxxxxxxx>
SUSE Labs, CR