|
|
Log in / Subscribe / Register

ntfs: validate attribute values on lookup

From:  DaeMyung Kang <charsyam-AT-gmail.com>
To:  Namjae Jeon <linkinjeon-AT-kernel.org>, Hyunchul Lee <hyc.lee-AT-gmail.com>
Subject:  [PATCH v4 0/6] ntfs: validate attribute values on lookup
Date:  Sat, 30 May 2026 23:35:08 +0900
Message-ID:  <20260530143514.3083601-1-charsyam@gmail.com>
Cc:  linux-fsdevel-AT-vger.kernel.org, linux-kernel-AT-vger.kernel.org, DaeMyung Kang <charsyam-AT-gmail.com>
Archive-link:  Article

This v4 supersedes the previous single-patch v3. Per review, it expands
the lookup-time attribute value validation into a series so $VOLUME_NAME
and $INDEX_ROOT can be validated safely.

The first patch keeps the original $FILE_NAME corruption fix and moves
the duplicated non-resident mapping-pairs metadata checks into the common
attribute value validator. It also keeps resident value matching in the
external attribute lookup path on the actual value length and fixes the
matching attrlist duplicate check for resident attributes. The next
patches prepare the volume label write and mount read paths to cope with
a rejected $VOLUME_NAME, add $VOLUME_NAME validation, fix the
ntfs_ir_truncate() shrink ordering issue, and then enable $INDEX_ROOT
validation.

Changes since v3:
- Expand the single patch into a 6-patch series as requested.
- Keep corruption messages using numeric attribute types and drop the
  attribute type name helper.
- Move non-resident mapping-pairs metadata validation into the shared
  ntfs_attr_value_is_valid() helper.
- Preserve resident @val matching in ntfs_external_attr_find() using the
  actual resident value length, and avoid reading the non-resident
  lowest_vcn union member when checking resident attrlist duplicates.
- Make ntfs_write_volume_label() add a replacement only after successful
  removal or after -ENOENT, and propagate other lookup/removal errors.
- Reinitialize the mount-time search context before the
  $VOLUME_INFORMATION lookup, since a rejected $VOLUME_NAME leaves the
  context in an undefined state.
- Add $VOLUME_NAME-specific validation, and reject non-resident
  $VOLUME_NAME records like non-resident $FILE_NAME.
- Include the ntfs_ir_truncate() shrink ordering fix.
- Add $INDEX_ROOT-specific validation on top of the shrink fix.

DaeMyung Kang (6):
  ntfs: validate attribute values on lookup
  ntfs: do not replace volume name after lookup errors
  ntfs: reinit search context before volume information lookup
  ntfs: validate resident volume name values on lookup
  ntfs: update index root allocated size before shrink
  ntfs: validate resident index root values on lookup

 fs/ntfs/attrib.c   | 203 +++++++++++++++++++++++++++++++++++++----------------
 fs/ntfs/attrlist.c |  11 ++-
 fs/ntfs/index.c    |  18 ++++-
 fs/ntfs/super.c    |  12 +++-
 4 files changed, 174 insertions(+), 70 deletions(-)


base-commit: 8553f258a57607dbde0b8baab47459aa28eb92f7
-- 
2.43.0



Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds