Commit 038ca189 authored by Dave Chinner's avatar Dave Chinner Committed by Chandan Babu R
Browse files

xfs: inode recovery does not validate the recovered inode



Discovered when trying to track down a weird recovery corruption
issue that wasn't detected at recovery time.

The specific corruption was a zero extent count field when big
extent counts are in use, and it turns out the dinode verifier
doesn't detect that specific corruption case, either. So fix it too.

Signed-off-by: default avatarDave Chinner <dchinner@redhat.com>
Reviewed-by: default avatar"Darrick J. Wong" <djwong@kernel.org>
Signed-off-by: default avatarChandan Babu R <chandanbabu@kernel.org>
parent a2e4388a
Loading
Loading
Loading
Loading
+3 −0
Original line number Diff line number Diff line
@@ -510,6 +510,9 @@ xfs_dinode_verify(
	if (mode && nextents + naextents > nblocks)
		return __this_address;

	if (nextents + naextents == 0 && nblocks != 0)
		return __this_address;

	if (S_ISDIR(mode) && nextents > mp->m_dir_geo->max_extents)
		return __this_address;

+13 −1
Original line number Diff line number Diff line
@@ -286,6 +286,7 @@ xlog_recover_inode_commit_pass2(
	struct xfs_log_dinode		*ldip;
	uint				isize;
	int				need_free = 0;
	xfs_failaddr_t			fa;

	if (item->ri_buf[0].i_len == sizeof(struct xfs_inode_log_format)) {
		in_f = item->ri_buf[0].i_addr;
@@ -528,8 +529,19 @@ xlog_recover_inode_commit_pass2(
	    (dip->di_mode != 0))
		error = xfs_recover_inode_owner_change(mp, dip, in_f,
						       buffer_list);
	/* re-generate the checksum. */
	/* re-generate the checksum and validate the recovered inode. */
	xfs_dinode_calc_crc(log->l_mp, dip);
	fa = xfs_dinode_verify(log->l_mp, in_f->ilf_ino, dip);
	if (fa) {
		XFS_CORRUPTION_ERROR(
			"Bad dinode after recovery",
				XFS_ERRLEVEL_LOW, mp, dip, sizeof(*dip));
		xfs_alert(mp,
			"Metadata corruption detected at %pS, inode 0x%llx",
			fa, in_f->ilf_ino);
		error = -EFSCORRUPTED;
		goto out_release;
	}

	ASSERT(bp->b_mount == mp);
	bp->b_flags |= _XBF_LOGRECOVERY;