Donate to e Foundation | Murena handsets with /e/OS | Own a part of Murena! Learn more

Commit 1e55b329 authored by Mark Salyzyn's avatar Mark Salyzyn Committed by Gerrit - the friendly Code Review server
Browse files

BACKPORT: f2fs: add a max block check for get_data_block_bmap



(cherry pick from commit 179448bfe4cd201e98e728391c6b01b25c849fe8)

This patch adds a max block check for get_data_block_bmap.

Trinity test program will send a block number as parameter into
ioctl_fibmap, which will be used in get_node_path(), when the block
number large than f2fs max blocks, it will trigger kernel bug.

Signed-off-by: default avatarYunlei He <heyunlei@huawei.com>
Signed-off-by: default avatarXue Liu <liuxueliu.liu@huawei.com>
[Jaegeuk Kim: fix missing condition, pointed by Chao Yu]
Signed-off-by: default avatarJaegeuk Kim <jaegeuk@kernel.org>
Bug: 28271368
Git-repo: https://android.googlesource.com/kernel/tegra.git


Git-commit: 3c714201e02ec08652be4b9544a5267e79bde3a9
Change-Id: Ia5acae04522993d5b60a0bcb5ccc184c66532be8
[d-cagle@codeaurora.org Resolve trivial merge conflicts]
Signed-off-by: default avatarDennis Cagle <d-cagle@codeaurora.org>
parent c5f4a0a0
Loading
Loading
Loading
Loading
+10 −1
Original line number Original line Diff line number Diff line
@@ -737,6 +737,15 @@ int f2fs_fiemap(struct inode *inode, struct fiemap_extent_info *fieinfo,
				start, len, get_data_block_fiemap);
				start, len, get_data_block_fiemap);
}
}


static int get_data_block_bmap(struct inode *inode, sector_t iblock,
			struct buffer_head *bh_result, int create)
{
	/* Block number less than F2FS MAX BLOCKS */
	if (unlikely(iblock >= max_file_size(0)))
		return -EFBIG;
	return get_data_block_ro(inode, iblock, bh_result, create);
}

static int f2fs_read_data_page(struct file *file, struct page *page)
static int f2fs_read_data_page(struct file *file, struct page *page)
{
{
	struct inode *inode = page->mapping->host;
	struct inode *inode = page->mapping->host;
@@ -1153,7 +1162,7 @@ static sector_t f2fs_bmap(struct address_space *mapping, sector_t block)
	if (f2fs_has_inline_data(inode))
	if (f2fs_has_inline_data(inode))
		return 0;
		return 0;


	return generic_block_bmap(mapping, block, get_data_block);
	return generic_block_bmap(mapping, block, get_data_block_bmap);
}
}


const struct address_space_operations f2fs_dblock_aops = {
const struct address_space_operations f2fs_dblock_aops = {
+1 −0
Original line number Original line Diff line number Diff line
@@ -1246,6 +1246,7 @@ static inline int f2fs_add_link(struct dentry *dentry, struct inode *inode)
/*
/*
 * super.c
 * super.c
 */
 */
loff_t max_file_size(unsigned bits);
int f2fs_sync_fs(struct super_block *, int);
int f2fs_sync_fs(struct super_block *, int);
extern __printf(3, 4)
extern __printf(3, 4)
void f2fs_msg(struct super_block *, const char *, const char *, ...);
void f2fs_msg(struct super_block *, const char *, const char *, ...);
+1 −1
Original line number Original line Diff line number Diff line
@@ -752,7 +752,7 @@ static const struct export_operations f2fs_export_ops = {
	.get_parent = f2fs_get_parent,
	.get_parent = f2fs_get_parent,
};
};


static loff_t max_file_size(unsigned bits)
loff_t max_file_size(unsigned bits)
{
{
	loff_t result = (DEF_ADDRS_PER_INODE - F2FS_INLINE_XATTR_ADDRS);
	loff_t result = (DEF_ADDRS_PER_INODE - F2FS_INLINE_XATTR_ADDRS);
	loff_t leaf_count = ADDRS_PER_BLOCK;
	loff_t leaf_count = ADDRS_PER_BLOCK;