linux-yocto/fs/nilfs2
Nathan Chancellor 1adc72411f nilfs2: fix CFI failure when accessing /sys/fs/nilfs2/features/*
commit 025e87f8ea2ae3a28bf1fe2b052bfa412c27ed4a upstream.

When accessing one of the files under /sys/fs/nilfs2/features when
CONFIG_CFI_CLANG is enabled, there is a CFI violation:

  CFI failure at kobj_attr_show+0x59/0x80 (target: nilfs_feature_revision_show+0x0/0x30; expected type: 0xfc392c4d)
  ...
  Call Trace:
   <TASK>
   sysfs_kf_seq_show+0x2a6/0x390
   ? __cfi_kobj_attr_show+0x10/0x10
   kernfs_seq_show+0x104/0x15b
   seq_read_iter+0x580/0xe2b
  ...

When the kobject of the kset for /sys/fs/nilfs2 is initialized, its ktype
is set to kset_ktype, which has a ->sysfs_ops of kobj_sysfs_ops.  When
nilfs_feature_attr_group is added to that kobject via
sysfs_create_group(), the kernfs_ops of each files is sysfs_file_kfops_rw,
which will call sysfs_kf_seq_show() when ->seq_show() is called.
sysfs_kf_seq_show() in turn calls kobj_attr_show() through
->sysfs_ops->show().  kobj_attr_show() casts the provided attribute out to
a 'struct kobj_attribute' via container_of() and calls ->show(), resulting
in the CFI violation since neither nilfs_feature_revision_show() nor
nilfs_feature_README_show() match the prototype of ->show() in 'struct
kobj_attribute'.

Resolve the CFI violation by adjusting the second parameter in
nilfs_feature_{revision,README}_show() from 'struct attribute' to 'struct
kobj_attribute' to match the expected prototype.

Link: https://lkml.kernel.org/r/20250906144410.22511-1-konishi.ryusuke@gmail.com
Fixes: aebe17f684 ("nilfs2: add /sys/fs/nilfs2/features group")
Signed-off-by: Nathan Chancellor <nathan@kernel.org>
Signed-off-by: Ryusuke Konishi <konishi.ryusuke@gmail.com>
Reported-by: kernel test robot <oliver.sang@intel.com>
Closes: https://lore.kernel.org/oe-lkp/202509021646.bc78d9ef-lkp@intel.com/
Cc: <stable@vger.kernel.org>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2025-09-25 11:13:45 +02:00
..
alloc.c
alloc.h
bmap.c
bmap.h
btnode.c
btnode.h
btree.c nilfs2: do not propagate ENOENT error from nilfs_btree_propagate() 2025-06-19 15:32:01 +02:00
btree.h
cpfile.c
cpfile.h
dat.c
dat.h
dir.c nilfs2: handle errors that nilfs_prepare_chunk() may return 2025-02-08 09:57:58 +01:00
direct.c nilfs2: add pointer check for nilfs_direct_propagate() 2025-06-19 15:32:01 +02:00
direct.h
export.h
file.c
gcinode.c
ifile.c
ifile.h
inode.c nilfs2: reject invalid file types when reading inodes 2025-08-01 09:48:43 +01:00
ioctl.c
Kconfig
Makefile
mdt.c
mdt.h
namei.c nilfs2: handle errors that nilfs_prepare_chunk() may return 2025-02-08 09:57:58 +01:00
nilfs.h nilfs2: handle errors that nilfs_prepare_chunk() may return 2025-02-08 09:57:58 +01:00
page.c
page.h
recovery.c
segbuf.c
segbuf.h
segment.c nilfs2: protect access to buffers with no active references 2025-02-08 09:57:58 +01:00
segment.h
sufile.c
sufile.h
super.c
sysfs.c nilfs2: fix CFI failure when accessing /sys/fs/nilfs2/features/* 2025-09-25 11:13:45 +02:00
sysfs.h nilfs2: fix CFI failure when accessing /sys/fs/nilfs2/features/* 2025-09-25 11:13:45 +02:00
the_nilfs.c nilfs2: fix deadlock warnings caused by lock dependency in init_nilfs() 2025-05-29 11:03:23 +02:00
the_nilfs.h