]> git.ipfire.org Git - thirdparty/kernel/linux.git/commitdiff
hfsplus: Remove the duplicate attr inode dirty marking action
authorEdward Adam Davis <eadavis@qq.com>
Thu, 16 Apr 2026 03:37:53 +0000 (11:37 +0800)
committerViacheslav Dubeyko <slava@dubeyko.com>
Mon, 27 Apr 2026 22:22:17 +0000 (15:22 -0700)
Syzbot reported a null-ptr-deref in [1].
If the attributes file is not loaded during system mount, a trigger
occurs [1] when setxattr is executed in userspace.

Remove the first mark attr inode dirty operation.

[1]
KASAN: null-ptr-deref in range [0x0000000000000008-0x000000000000000f]
Call Trace:
 hfsplus_setxattr+0x124/0x340 fs/hfsplus/xattr.c:555
 hfsplus_trusted_setxattr+0x40/0x60 fs/hfsplus/xattr_trusted.c:30
 __vfs_setxattr+0x43c/0x480 fs/xattr.c:218
 __vfs_setxattr_noperm+0x12d/0x660 fs/xattr.c:252
 vfs_setxattr+0x163/0x360 fs/xattr.c:339
 do_setxattr fs/xattr.c:654 [inline]

Reported-by: syzbot+bc70a12e438dadba4fb4@syzkaller.appspotmail.com
Fixes: ee8422d00b7c ("hfsplus: fix potential Allocation File corruption after fsync")
Closes: https://syzkaller.appspot.com/bug?extid=bc70a12e438dadba4fb4
Signed-off-by: Edward Adam Davis <eadavis@qq.com>
Reviewed-by: Viacheslav Dubeyko <slava@dubeyko.com>
Signed-off-by: Viacheslav Dubeyko <slava@dubeyko.com>
Link: https://lore.kernel.org/r/tencent_A8D47429765566CC3C8B378496D036664A09@qq.com
Signed-off-by: Viacheslav Dubeyko <slava@dubeyko.com>
fs/hfsplus/xattr.c

index 452a1f9becb2d1de3ff7ff338b574208bfd44f45..21a1c196c71f2ee26cac0b690f8bc707c4b1693a 100644 (file)
@@ -317,7 +317,6 @@ check_attr_tree_state_again:
                next_node++;
        }
 
-       hfsplus_mark_inode_dirty(HFSPLUS_ATTR_TREE_I(sb), HFSPLUS_I_ATTR_DIRTY);
        hfsplus_mark_inode_dirty(attr_file, HFSPLUS_I_ATTR_DIRTY);
 
        sbi->attr_tree = hfs_btree_open(sb, HFSPLUS_ATTR_CNID);