Donate to e Foundation | Murena handsets with /e/OS | Own a part of Murena! Learn more

Commit 022ed023 authored by Goldwyn Rodrigues's avatar Goldwyn Rodrigues Committed by Greg Kroah-Hartman
Browse files

btrfs: allocate btrfs_ioctl_defrag_range_args on stack



commit c853a5783ebe123847886d432354931874367292 upstream.

Instead of using kmalloc() to allocate btrfs_ioctl_defrag_range_args,
allocate btrfs_ioctl_defrag_range_args on stack, the size is reasonably
small and ioctls are called in process context.

sizeof(btrfs_ioctl_defrag_range_args) = 48

Reviewed-by: default avatarAnand Jain <anand.jain@oracle.com>
Signed-off-by: default avatarGoldwyn Rodrigues <rgoldwyn@suse.com>
Reviewed-by: default avatarDavid Sterba <dsterba@suse.com>
Signed-off-by: default avatarDavid Sterba <dsterba@suse.com>
[ This patch is needed to fix a memory leak of "range" that was
introduced when commit 173431b274a9 ("btrfs: defrag: reject unknown
flags of btrfs_ioctl_defrag_range_args") was backported to kernels
lacking this patch. Now with these two patches applied in reverse order,
range->flags needed to change back to range.flags.
This bug was discovered and resolved using Coverity Static Analysis
Security Testing (SAST) by Synopsys, Inc.]
Signed-off-by: default avatarMaximilian Heyne <mheyne@amazon.de>
Signed-off-by: default avatarGreg Kroah-Hartman <gregkh@linuxfoundation.org>
parent 45f99d44
Loading
Loading
Loading
Loading
+8 −17
Original line number Original line Diff line number Diff line
@@ -2992,7 +2992,7 @@ static int btrfs_ioctl_defrag(struct file *file, void __user *argp)
{
{
	struct inode *inode = file_inode(file);
	struct inode *inode = file_inode(file);
	struct btrfs_root *root = BTRFS_I(inode)->root;
	struct btrfs_root *root = BTRFS_I(inode)->root;
	struct btrfs_ioctl_defrag_range_args *range;
	struct btrfs_ioctl_defrag_range_args range = {0};
	int ret;
	int ret;


	ret = mnt_want_write_file(file);
	ret = mnt_want_write_file(file);
@@ -3024,37 +3024,28 @@ static int btrfs_ioctl_defrag(struct file *file, void __user *argp)
			goto out;
			goto out;
		}
		}


		range = kzalloc(sizeof(*range), GFP_KERNEL);
		if (!range) {
			ret = -ENOMEM;
			goto out;
		}

		if (argp) {
		if (argp) {
			if (copy_from_user(range, argp,
			if (copy_from_user(&range, argp, sizeof(range))) {
					   sizeof(*range))) {
				ret = -EFAULT;
				ret = -EFAULT;
				kfree(range);
				goto out;
				goto out;
			}
			}
			if (range->flags & ~BTRFS_DEFRAG_RANGE_FLAGS_SUPP) {
			if (range.flags & ~BTRFS_DEFRAG_RANGE_FLAGS_SUPP) {
				ret = -EOPNOTSUPP;
				ret = -EOPNOTSUPP;
				goto out;
				goto out;
			}
			}
			/* compression requires us to start the IO */
			/* compression requires us to start the IO */
			if ((range->flags & BTRFS_DEFRAG_RANGE_COMPRESS)) {
			if ((range.flags & BTRFS_DEFRAG_RANGE_COMPRESS)) {
				range->flags |= BTRFS_DEFRAG_RANGE_START_IO;
				range.flags |= BTRFS_DEFRAG_RANGE_START_IO;
				range->extent_thresh = (u32)-1;
				range.extent_thresh = (u32)-1;
			}
			}
		} else {
		} else {
			/* the rest are all set to zero by kzalloc */
			/* the rest are all set to zero by kzalloc */
			range->len = (u64)-1;
			range.len = (u64)-1;
		}
		}
		ret = btrfs_defrag_file(file_inode(file), file,
		ret = btrfs_defrag_file(file_inode(file), file,
					range, BTRFS_OLDEST_GENERATION, 0);
					&range, BTRFS_OLDEST_GENERATION, 0);
		if (ret > 0)
		if (ret > 0)
			ret = 0;
			ret = 0;
		kfree(range);
		break;
		break;
	default:
	default:
		ret = -EINVAL;
		ret = -EINVAL;