]> git.ipfire.org Git - thirdparty/kernel/linux.git/commitdiff
btrfs: reject inline file extents item in get_new_location()
authorQu Wenruo <wqu@suse.com>
Tue, 23 Jun 2026 11:37:15 +0000 (21:07 +0930)
committerDavid Sterba <dsterba@suse.com>
Tue, 14 Jul 2026 05:03:15 +0000 (07:03 +0200)
Commit a6908f88c9da ("btrfs: validate data reloc tree file extent item
members") introduced extra checks on file extent items for data reloc
inodes, but it checked the file extent offset without checking if the file
extent is inlined.

This can lead to either false alerts (as the offset member is inside the
inlined data) or even reading beyond the item range.

This has already triggered a warning in a syzbot report.
Although the root fix is to avoid compression for data reloc inodes, for
the sake of consistency, reject inlined file extents first.

Fixes: a6908f88c9da ("btrfs: validate data reloc tree file extent item members")
CC: stable@vger.kernel.org
Reviewed-by: Filipe Manana <fdmanana@suse.com>
Signed-off-by: Qu Wenruo <wqu@suse.com>
Signed-off-by: David Sterba <dsterba@suse.com>
fs/btrfs/relocation.c

index 75bf2e5fcb6ed9869a78b52f6bf733d6b42b4093..6409c2cc1926440c4261fdad1a4e9ff3c9e5bfcd 100644 (file)
@@ -890,6 +890,13 @@ static int get_new_location(struct inode *reloc_inode, u64 *new_bytenr,
        leaf = path->nodes[0];
        fi = btrfs_item_ptr(leaf, path->slots[0],
                            struct btrfs_file_extent_item);
+       if (unlikely(btrfs_file_extent_type(leaf, fi) == BTRFS_FILE_EXTENT_INLINE)) {
+               btrfs_print_leaf(leaf);
+               btrfs_err(fs_info,
+       "unexpected inline file extent item for data reloc inode %llu key offset %llu",
+                         btrfs_ino(BTRFS_I(reloc_inode)), bytenr);
+               return -EUCLEAN;
+       }
 
        /*
         * The cluster-boundary key searched above is always written by