1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30#include "ubifs.h"
31
32
33
34
35
36
37
38
39
40static int scan_padding_bytes(void *buf, int len)
41{
42 int pad_len = 0, max_pad_len = min_t(int, UBIFS_PAD_NODE_SZ, len);
43 uint8_t *p = buf;
44
45 dbg_scan("not a node");
46
47 while (pad_len < max_pad_len && *p++ == UBIFS_PADDING_BYTE)
48 pad_len += 1;
49
50 if (!pad_len || (pad_len & 7))
51 return SCANNED_GARBAGE;
52
53 dbg_scan("%d padding bytes", pad_len);
54
55 return pad_len;
56}
57
58
59
60
61
62
63
64
65
66
67
68
69int ubifs_scan_a_node(const struct ubifs_info *c, void *buf, int len, int lnum,
70 int offs, int quiet)
71{
72 struct ubifs_ch *ch = buf;
73 uint32_t magic;
74
75 magic = le32_to_cpu(ch->magic);
76
77 if (magic == 0xFFFFFFFF) {
78 dbg_scan("hit empty space");
79 return SCANNED_EMPTY_SPACE;
80 }
81
82 if (magic != UBIFS_NODE_MAGIC)
83 return scan_padding_bytes(buf, len);
84
85 if (len < UBIFS_CH_SZ)
86 return SCANNED_GARBAGE;
87
88 dbg_scan("scanning %s", dbg_ntype(ch->node_type));
89
90 if (ubifs_check_node(c, buf, lnum, offs, quiet, 1))
91 return SCANNED_A_CORRUPT_NODE;
92
93 if (ch->node_type == UBIFS_PAD_NODE) {
94 struct ubifs_pad_node *pad = buf;
95 int pad_len = le32_to_cpu(pad->pad_len);
96 int node_len = le32_to_cpu(ch->len);
97
98
99 if (pad_len < 0 ||
100 offs + node_len + pad_len > c->leb_size) {
101 if (!quiet) {
102 ubifs_err("bad pad node at LEB %d:%d",
103 lnum, offs);
104 dbg_dump_node(c, pad);
105 }
106 return SCANNED_A_BAD_PAD_NODE;
107 }
108
109
110 if ((node_len + pad_len) & 7) {
111 if (!quiet)
112 dbg_err("bad padding length %d - %d",
113 offs, offs + node_len + pad_len);
114 return SCANNED_A_BAD_PAD_NODE;
115 }
116
117 dbg_scan("%d bytes padded, offset now %d",
118 pad_len, ALIGN(offs + node_len + pad_len, 8));
119
120 return node_len + pad_len;
121 }
122
123 return SCANNED_A_NODE;
124}
125
126
127
128
129
130
131
132
133
134
135struct ubifs_scan_leb *ubifs_start_scan(const struct ubifs_info *c, int lnum,
136 int offs, void *sbuf)
137{
138 struct ubifs_scan_leb *sleb;
139 int err;
140
141 dbg_scan("scan LEB %d:%d", lnum, offs);
142
143 sleb = kzalloc(sizeof(struct ubifs_scan_leb), GFP_NOFS);
144 if (!sleb)
145 return ERR_PTR(-ENOMEM);
146
147 sleb->lnum = lnum;
148 INIT_LIST_HEAD(&sleb->nodes);
149 sleb->buf = sbuf;
150
151 err = ubifs_leb_read(c, lnum, sbuf + offs, offs, c->leb_size - offs, 0);
152 if (err && err != -EBADMSG) {
153 ubifs_err("cannot read %d bytes from LEB %d:%d,"
154 " error %d", c->leb_size - offs, lnum, offs, err);
155 kfree(sleb);
156 return ERR_PTR(err);
157 }
158
159 if (err == -EBADMSG)
160 sleb->ecc = 1;
161
162 return sleb;
163}
164
165
166
167
168
169
170
171
172
173
174void ubifs_end_scan(const struct ubifs_info *c, struct ubifs_scan_leb *sleb,
175 int lnum, int offs)
176{
177 lnum = lnum;
178 dbg_scan("stop scanning LEB %d at offset %d", lnum, offs);
179 ubifs_assert(offs % c->min_io_size == 0);
180
181 sleb->endpt = ALIGN(offs, c->min_io_size);
182}
183
184
185
186
187
188
189
190
191
192
193int ubifs_add_snod(const struct ubifs_info *c, struct ubifs_scan_leb *sleb,
194 void *buf, int offs)
195{
196 struct ubifs_ch *ch = buf;
197 struct ubifs_ino_node *ino = buf;
198 struct ubifs_scan_node *snod;
199
200 snod = kmalloc(sizeof(struct ubifs_scan_node), GFP_NOFS);
201 if (!snod)
202 return -ENOMEM;
203
204 snod->sqnum = le64_to_cpu(ch->sqnum);
205 snod->type = ch->node_type;
206 snod->offs = offs;
207 snod->len = le32_to_cpu(ch->len);
208 snod->node = buf;
209
210 switch (ch->node_type) {
211 case UBIFS_INO_NODE:
212 case UBIFS_DENT_NODE:
213 case UBIFS_XENT_NODE:
214 case UBIFS_DATA_NODE:
215
216
217
218
219 key_read(c, &ino->key, &snod->key);
220 break;
221 default:
222 invalid_key_init(c, &snod->key);
223 break;
224 }
225 list_add_tail(&snod->list, &sleb->nodes);
226 sleb->nodes_cnt += 1;
227 return 0;
228}
229
230
231
232
233
234
235
236
237void ubifs_scanned_corruption(const struct ubifs_info *c, int lnum, int offs,
238 void *buf)
239{
240 int len;
241
242 ubifs_err("corruption at LEB %d:%d", lnum, offs);
243 if (dbg_is_tst_rcvry(c))
244 return;
245 len = c->leb_size - offs;
246 if (len > 8192)
247 len = 8192;
248 dbg_err("first %d bytes from LEB %d:%d", len, lnum, offs);
249 print_hex_dump(KERN_DEBUG, "", DUMP_PREFIX_OFFSET, 32, 4, buf, len, 1);
250}
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268struct ubifs_scan_leb *ubifs_scan(const struct ubifs_info *c, int lnum,
269 int offs, void *sbuf, int quiet)
270{
271 void *buf = sbuf + offs;
272 int err, len = c->leb_size - offs;
273 struct ubifs_scan_leb *sleb;
274
275 sleb = ubifs_start_scan(c, lnum, offs, sbuf);
276 if (IS_ERR(sleb))
277 return sleb;
278
279 while (len >= 8) {
280 struct ubifs_ch *ch = buf;
281 int node_len, ret;
282
283 dbg_scan("look at LEB %d:%d (%d bytes left)",
284 lnum, offs, len);
285
286 cond_resched();
287
288 ret = ubifs_scan_a_node(c, buf, len, lnum, offs, quiet);
289 if (ret > 0) {
290
291 offs += ret;
292 buf += ret;
293 len -= ret;
294 continue;
295 }
296
297 if (ret == SCANNED_EMPTY_SPACE)
298
299 break;
300
301 switch (ret) {
302 case SCANNED_GARBAGE:
303 dbg_err("garbage");
304 goto corrupted;
305 case SCANNED_A_NODE:
306 break;
307 case SCANNED_A_CORRUPT_NODE:
308 case SCANNED_A_BAD_PAD_NODE:
309 dbg_err("bad node");
310 goto corrupted;
311 default:
312 dbg_err("unknown");
313 err = -EINVAL;
314 goto error;
315 }
316
317 err = ubifs_add_snod(c, sleb, buf, offs);
318 if (err)
319 goto error;
320
321 node_len = ALIGN(le32_to_cpu(ch->len), 8);
322 offs += node_len;
323 buf += node_len;
324 len -= node_len;
325 }
326
327 if (offs % c->min_io_size) {
328 if (!quiet)
329 ubifs_err("empty space starts at non-aligned offset %d",
330 offs);
331 goto corrupted;
332 }
333
334 ubifs_end_scan(c, sleb, lnum, offs);
335
336 for (; len > 4; offs += 4, buf = buf + 4, len -= 4)
337 if (*(uint32_t *)buf != 0xffffffff)
338 break;
339 for (; len; offs++, buf++, len--)
340 if (*(uint8_t *)buf != 0xff) {
341 if (!quiet)
342 ubifs_err("corrupt empty space at LEB %d:%d",
343 lnum, offs);
344 goto corrupted;
345 }
346
347 return sleb;
348
349corrupted:
350 if (!quiet) {
351 ubifs_scanned_corruption(c, lnum, offs, buf);
352 ubifs_err("LEB %d scanning failed", lnum);
353 }
354 err = -EUCLEAN;
355 ubifs_scan_destroy(sleb);
356 return ERR_PTR(err);
357
358error:
359 ubifs_err("LEB %d scanning failed, error %d", lnum, err);
360 ubifs_scan_destroy(sleb);
361 return ERR_PTR(err);
362}
363
364
365
366
367
368void ubifs_scan_destroy(struct ubifs_scan_leb *sleb)
369{
370 struct ubifs_scan_node *node;
371 struct list_head *head;
372
373 head = &sleb->nodes;
374 while (!list_empty(head)) {
375 node = list_entry(head->next, struct ubifs_scan_node, list);
376 list_del(&node->list);
377 kfree(node);
378 }
379 kfree(sleb);
380}
381