All of lore.kernel.org
 help / color / mirror / Atom feed
From: Mark Tinguely <tinguely@sgi.com>
To: Eric Sandeen <sandeen@redhat.com>
Cc: xfs-oss <xfs@oss.sgi.com>
Subject: Re: [PATCH] xfs: catch invalid negative blknos in _xfs_buf_find()
Date: Wed, 26 Nov 2014 10:38:05 -0600	[thread overview]
Message-ID: <547601ED.7060704@sgi.com> (raw)
In-Reply-To: <546D15E3.5000200@redhat.com>

On 11/19/14 16:12, Eric Sandeen wrote:
> Here blkno is a daddr_t, which is a __s64; it's possible to hold
> a value which is negative, and thus pass the (blkno>= eofs)
> test.  Then we try to do a xfs_perag_get() for a ridiculous
> agno via xfs_daddr_to_agno(), and bad things happen when that
> fails, and returns a null pag which is dereferenced shortly
> thereafter.
>
> Found via a user-supplied fuzzed image...
>
> Signed-off-by: Eric Sandeen<sandeen@redhat.com>
> ---

Looks good.

I did a little playing with sending the try lock failure (EAGAIN?) and 
EFSCORRUPT error status up the stack. It looked straight forward and 
could save a xfs_buf allocation when we know it is not necessary.

Reviewed-by: Mark Tinguely <tinguely@sgi.com>

_______________________________________________
xfs mailing list
xfs@oss.sgi.com
http://oss.sgi.com/mailman/listinfo/xfs

      parent reply	other threads:[~2014-11-26 16:38 UTC|newest]

Thread overview: 4+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2014-11-19 22:12 [PATCH] xfs: catch invalid negative blknos in _xfs_buf_find() Eric Sandeen
2014-11-19 22:27 ` Eric Sandeen
2014-11-26 15:58 ` Eric Sandeen
2014-11-26 16:38 ` Mark Tinguely [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=547601ED.7060704@sgi.com \
    --to=tinguely@sgi.com \
    --cc=sandeen@redhat.com \
    --cc=xfs@oss.sgi.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.