From nobody Thu Sep 10 02:32:09 2026 X-Original-To: dev-commits-src-branches@mlmmj.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mlmmj.nyi.freebsd.org (Postfix) with ESMTP id 4hgMBx6Fbbz6rscv for ; Thu, 10 Sep 2026 02:32:09 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from mxrelay.nyi.freebsd.org (mxrelay.nyi.freebsd.org [IPv6:2610:1c1:1:606c::19:3]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature RSA-PSS (4096 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "mxrelay.nyi.freebsd.org", Issuer "YR2" (not verified)) by mx1.freebsd.org (Postfix) with ESMTPS id 4hgMBx54jNz3Kgj for ; Thu, 10 Sep 2026 02:32:09 +0000 (UTC) (envelope-from git@FreeBSD.org) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1789007529; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=NUEpobz7ysfwygs5lHnnOFIsK3tK6a97UnI7MnenJ3M=; b=gKMIjb2ZeAA2ZCFNw3q5MV14b8LRwdO2gde1hqauSyMfeWAduRknIcdRALBxg72ti7Mc5n J643HZckuXQ5FDiqjbmKH/XMhA9eohd1KyM9Izx6cFYeA9u5bGGAZqBqBmSuCIZWcXcXXA 9puj2vbMKmeIxVAkt4tdvakkPHzebZpwRfa6MxHepbA0eXs8hbvccicfcx1mPV/TzOZ+3Z yd1DWTtsNiyn3Pl7JLBc1dzSYBpwViiD85iIZLwUgKlruZ/LZTEuc5FoodviUFSAit92rn t+CwS5UT34WluSjTi5GJQBAvlvdk2dslFvDXMPdVwtTGmUqxpvFQKYwHMAi7UA== ARC-Seal: i=1; a=rsa-sha256; d=freebsd.org; s=dkim; cv=none; t=1789007529; b=pCf6q2Fx51myw+AUDh8NjhnFMmqvm/2uFmzfcvs2KYJeXhdzpEOT4tGoh33V8JxPUBW87g FjoSz5naLcJDAtMAFDwHAMtlmU71EDMlfE1jGrMIqVVupAclCCb2Mg0PSRalZqd/soysOg krTuxBX6XF6EGgFBqCbxdgjruz3Mu29u4NfwWNsKhWL7WD7lEw7neP1XzX1ZOsxQriN/vi zIIdXIcx7U5Td65Y0oivIxSfxtxd1rUIi+Epq/1irlyU8KO00X1ZbCC+KabnShRq0qFN2V 3st50uy4tUD2a/EmopPv/bIcOxwE+wKmIgtgdyctd5gz8UwL72R4l1iem7D/sg== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1789007529; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=NUEpobz7ysfwygs5lHnnOFIsK3tK6a97UnI7MnenJ3M=; b=DzjooGOj3jxSTOQbiM21uXa9I+e841eeL5OEgrWkUIFGapfXueGQnsgNs1tXFUxMG/SpFv OPPZYnClRaKsseth9oHwwnVlyi0qOcRg4m6+pBv+p3Qm8BBXuFF/1RxpeIA2wlfPW4lLhG dqmbcxrdKF48+70AiIkjTVtsseFyvoeszAC27qBU+uJ51OOEpJUiRnYxkPkn0NRrsCcRQd g+14upiVhSNvx0cBAsekOq9wXK5TPswvEDQiNqy0DLLvrQLG2S34V7s4vtzDXHOfsKzI/g CusELUw3Pyu3PEaK4kQ0PisXLwt+n9z/rJbxV4T9ONfYvZqcB6O5hywabEPGtg== ARC-Authentication-Results: i=1; mx1.freebsd.org; none Received: from gitrepo.freebsd.org (gitrepo.freebsd.org [IPv6:2610:1c1:1:6068::e6a:5]) by mxrelay.nyi.freebsd.org (Postfix) with ESMTP id 4hgMBx3BLlz1MgY for ; Thu, 10 Sep 2026 02:32:09 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from git (uid 1279) (envelope-from git@FreeBSD.org) id 203e2 by gitrepo.freebsd.org (DragonFly Mail Agent v0.13+ on gitrepo.freebsd.org); Thu, 10 Sep 2026 02:32:09 +0000 To: src-committers@FreeBSD.org, dev-commits-src-all@FreeBSD.org, dev-commits-src-branches@FreeBSD.org From: Xin LI Subject: git: 79e284a3d0ca - stable/14 - MFC: fsck_msdosfs: add tests for the 32-bit boot block field decoding List-Id: Commits to the stable branches of the FreeBSD src repository List-Archive: https://lists.freebsd.org/archives/dev-commits-src-branches List-Help: List-Post: List-Subscribe: List-Unsubscribe: X-BeenThere: dev-commits-src-branches@freebsd.org Sender: owner-dev-commits-src-branches@FreeBSD.org List-Id: List-Post: List-Help: List-Subscribe: List-Unsubscribe: List-Owner: Precedence: list MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 8bit X-Git-Committer: delphij X-Git-Repository: src X-Git-Refname: refs/heads/stable/14 X-Git-Reftype: branch X-Git-Commit: 79e284a3d0ca5781a167a270b2a77353f599c569 Auto-Submitted: auto-generated Date: Thu, 10 Sep 2026 02:32:09 +0000 Message-Id: <6aa216a9.203e2.203b202d@gitrepo.freebsd.org> The branch stable/14 has been updated by delphij: URL: https://cgit.FreeBSD.org/src/commit/?id=79e284a3d0ca5781a167a270b2a77353f599c569 commit 79e284a3d0ca5781a167a270b2a77353f599c569 Author: Xin LI AuthorDate: 2026-09-03 05:23:53 +0000 Commit: Xin LI CommitDate: 2026-09-10 02:31:05 +0000 MFC: fsck_msdosfs: add tests for the 32-bit boot block field decoding (cherry picked from commit c4f458da4411872df4968e02ca292389df462b7b) --- sbin/fsck_msdosfs/tests/Makefile | 3 +- sbin/fsck_msdosfs/tests/fsck_msdosfs_boot_test.sh | 214 ++++++++++++++++++++++ 2 files changed, 216 insertions(+), 1 deletion(-) diff --git a/sbin/fsck_msdosfs/tests/Makefile b/sbin/fsck_msdosfs/tests/Makefile index a36439f91bce..c8963837b7b0 100644 --- a/sbin/fsck_msdosfs/tests/Makefile +++ b/sbin/fsck_msdosfs/tests/Makefile @@ -1,5 +1,6 @@ PACKAGE= tests -ATF_TESTS_SH= fsck_msdosfs_test +ATF_TESTS_SH= fsck_msdosfs_test \ + fsck_msdosfs_boot_test .include diff --git a/sbin/fsck_msdosfs/tests/fsck_msdosfs_boot_test.sh b/sbin/fsck_msdosfs/tests/fsck_msdosfs_boot_test.sh new file mode 100644 index 000000000000..51333982a96b --- /dev/null +++ b/sbin/fsck_msdosfs/tests/fsck_msdosfs_boot_test.sh @@ -0,0 +1,214 @@ +# +# SPDX-License-Identifier: BSD-2-Clause +# +# Copyright (c) 2026 The FreeBSD Foundation +# + +# Tests for the 32 bit BIOS Parameter Block and FSInfo fields decoded by +# readboot() in sbin/fsck_msdosfs/boot.c. Each case sets one field to a +# value whose most significant byte has its high bit set, which is the +# range that a byte-by-byte "b[3] << 24" decode has to shift into the +# sign bit of an int. +# +# Each case makes two assertions: +# +# 1. On stdout, that fsck_msdosfs(8) reports the full unsigned 32 bit +# value back. This covers the decoding itself in an ordinary build. +# +# 2. On stderr, that nothing reports a runtime error. A byte-by-byte +# decode of these values is undefined behavior, but every compiler we +# use wraps it into the same bit pattern, so it cannot be caught by +# the value alone. In a WITH_UBSAN build it is caught here, because +# bsd.sanitizer.mk builds with -fsanitize=undefined and +# -fsanitize-recover=undefined, so the shift is reported on stderr and +# execution continues. In a build without the sanitizer these +# assertions are trivially true. +# +# Note that assertion 2 also fails on unrelated undefined behavior that +# these images reach anywhere in fsck_msdosfs(8), which is intentional. + +IMG=fat32.img + +# The high bit of the most significant byte is set in all of these. +HIGH=2147483648 # 0x80000000 +HIGH1=2147483649 # 0x80000001 + +# A UBSan report, as produced by a WITH_UBSAN build. It never appears +# in a build without the sanitizer. +UB='runtime error' + +# Read an unsigned little-endian integer of $3 bytes at offset $2 of $1. +bpb_read() +{ + od -An -v -tu1 -j "$2" -N "$3" "$1" | awk ' + { for (i = 1; i <= NF; i++) b[n++] = $i } + END { v = 0; for (i = n - 1; i >= 0; i--) v = v * 256 + b[i] + print v }' +} + +# Write the unsigned 32 bit little-endian value $3 at offset $2 of $1. +poke32() +{ + printf "$(printf '\\%03o\\%03o\\%03o\\%03o' $(($3 & 255)) \ + $((($3 >> 8) & 255)) $((($3 >> 16) & 255)) \ + $((($3 >> 24) & 255)))" | + dd of="$1" bs=1 seek="$2" conv=notrunc status=none +} + +# Byte offset of the FSInfo sector of $IMG. +fsinfo_off() +{ + echo $(($(bpb_read ${IMG} 48 2) * $(bpb_read ${IMG} 11 2))) +} + +# Create a 40 MiB FAT32 file system in $IMG. One sector per cluster +# keeps it comfortably above the 65525 cluster FAT32 minimum. +make_image() +{ + atf_check -s exit:0 -o ignore -e ignore \ + newfs_msdos -C 40m -F 32 -c 1 -S 512 ./${IMG} + # A freshly created file system must be clean, and must not have + # tripped the sanitizer on its way through readboot(). + atf_check -s exit:0 -o ignore -e not-match:"${UB}" \ + fsck_msdosfs -y ./${IMG} +} + +atf_test_case hidden_secs_high_bit +hidden_secs_high_bit_head() +{ + atf_set "descr" "Hidden sector count with the high bit set" + atf_set "require.progs" "newfs_msdos fsck_msdosfs" +} +hidden_secs_high_bit_body() +{ + make_image + poke32 ${IMG} 28 ${HIGH} + + # readboot() decodes bpbHiddenSecs but nothing uses it, so the + # only thing to check is that the file system still comes out + # clean and that decoding it was well defined. + atf_check -s exit:0 -o not-match:'Invalid' -e not-match:"${UB}" \ + fsck_msdosfs -n ./${IMG} +} + +atf_test_case fsinfo_free_high_bit +fsinfo_free_high_bit_head() +{ + atf_set "descr" "FSInfo free cluster count with the high bit set" + atf_set "require.progs" "newfs_msdos fsck_msdosfs" +} +fsinfo_free_high_bit_body() +{ + make_image + poke32 ${IMG} $(($(fsinfo_off) + 0x1e8)) ${HIGH} + + # The count is far larger than the number of clusters, so it has + # to be reported as wrong, with the decoded value spelled out. + atf_check -s exit:0 \ + -o match:"Free space in FSInfo block \(${HIGH}\) not correct" \ + -e not-match:"${UB}" fsck_msdosfs -n ./${IMG} + + # Once repaired the bogus count must be gone for good. + atf_check -s exit:0 -o ignore -e not-match:"${UB}" \ + fsck_msdosfs -y ./${IMG} + atf_check -s exit:0 -o not-match:'Free space in FSInfo block' \ + -e not-match:"${UB}" fsck_msdosfs -n ./${IMG} +} + +atf_test_case fsinfo_next_high_bit +fsinfo_next_high_bit_head() +{ + atf_set "descr" "FSInfo next free cluster with the high bit set" + atf_set "require.progs" "newfs_msdos fsck_msdosfs" +} +fsinfo_next_high_bit_body() +{ + make_image + poke32 ${IMG} $(($(fsinfo_off) + 0x1ec)) ${HIGH1} + + atf_check -s exit:0 \ + -o match:"Next free cluster in FSInfo block \(${HIGH1}\) invalid" \ + -e not-match:"${UB}" fsck_msdosfs -n ./${IMG} + + atf_check -s exit:0 -o ignore -e not-match:"${UB}" \ + fsck_msdosfs -y ./${IMG} + atf_check -s exit:0 -o not-match:'Next free cluster in FSInfo block' \ + -e not-match:"${UB}" fsck_msdosfs -n ./${IMG} +} + +atf_test_case root_cluster_high_bit +root_cluster_high_bit_head() +{ + atf_set "descr" "FAT32 root directory cluster with the high bit set" + atf_set "require.progs" "newfs_msdos fsck_msdosfs" +} +root_cluster_high_bit_body() +{ + make_image + poke32 ${IMG} 44 ${HIGH} + + # Out of range, so readboot() gives up before any phase runs. + atf_check -s exit:8 \ + -o match:"Root directory starts with cluster out of range\(${HIGH}\)" \ + -e not-match:"${UB}" fsck_msdosfs -n ./${IMG} +} + +atf_test_case fatsecs_high_bit +fatsecs_high_bit_head() +{ + atf_set "descr" "FAT32 sectors per FAT with the high bit set" + atf_set "require.progs" "newfs_msdos fsck_msdosfs" +} +fatsecs_high_bit_body() +{ + local nfats + + make_image + nfats=$(bpb_read ${IMG} 16 1) + poke32 ${IMG} 36 ${HIGH} + + # ${HIGH} FAT sectors times ${nfats} FATs overflows 32 bits. + atf_check -s exit:8 \ + -o match:"Invalid FATs\(${nfats}\) with FATsecs\(${HIGH}\)" \ + -e not-match:"${UB}" fsck_msdosfs -n ./${IMG} +} + +atf_test_case huge_sectors_high_bit +huge_sectors_high_bit_head() +{ + atf_set "descr" "32 bit total sector count with the high bit set" + atf_set "require.progs" "newfs_msdos fsck_msdosfs" +} +huge_sectors_high_bit_body() +{ + local bps spc rsvd nfats fatsz first clusters + + make_image + bps=$(bpb_read ${IMG} 11 2) + spc=$(bpb_read ${IMG} 13 1) + rsvd=$(bpb_read ${IMG} 14 2) + nfats=$(bpb_read ${IMG} 16 1) + fatsz=$(bpb_read ${IMG} 36 4) + poke32 ${IMG} 32 ${HIGH} + + # The root directory has no fixed entries on FAT32, so the data + # area starts right after the reserved sectors and the FATs. + first=$((rsvd + nfats * fatsz)) + clusters=$(((HIGH - first) / spc)) + + # Too many clusters for FAT32; the count in the message is + # derived from the decoded sector count. + atf_check -s exit:8 \ + -o match:"Filesystem too big \(${clusters} clusters\) for FAT32" \ + -e not-match:"${UB}" fsck_msdosfs -n ./${IMG} +} + +atf_init_test_cases() +{ + atf_add_test_case hidden_secs_high_bit + atf_add_test_case fsinfo_free_high_bit + atf_add_test_case fsinfo_next_high_bit + atf_add_test_case root_cluster_high_bit + atf_add_test_case fatsecs_high_bit + atf_add_test_case huge_sectors_high_bit +}