All of lore.kernel.org
 help / color / mirror / Atom feed
From: Brian Foster <bfoster@redhat.com>
To: Joanne Koong <joannelkoong@gmail.com>
Cc: miklos@szeredi.hu, linux-fsdevel@vger.kernel.org
Subject: Re: [PATCH] fuse: fix fuse_fill_write_pages() upper bound calculation
Date: Sat, 14 Jun 2025 06:58:06 -0400	[thread overview]
Message-ID: <aE1VvnDfZj0oJMMv@bfoster> (raw)
In-Reply-To: <20250614000114.910380-1-joannelkoong@gmail.com>

On Fri, Jun 13, 2025 at 05:01:14PM -0700, Joanne Koong wrote:
> This fixes a bug in commit 63c69ad3d18a ("fuse: refactor
> fuse_fill_write_pages()") where max_pages << PAGE_SHIFT is mistakenly
> used as the calculation for the max_pages upper limit but there's the
> possibility that copy_folio_from_iter_atomic() may copy over bytes
> from the iov_iter that are less than the full length of the folio,
> which would lead to exceeding max_pages.
> 
> This commit fixes it by adding a 'ap->num_folios < max_folios' check.
> 
> Signed-off-by: Joanne Koong <joannelkoong@gmail.com>
> Fixes: 63c69ad3d18a ("fuse: refactor fuse_fill_write_pages()")
> Reported-by: Brian Foster <bfoster@redhat.com>
> Closes: https://lore.kernel.org/linux-fsdevel/aEq4haEQScwHIWK6@bfoster/
> ---

This resolves the problem for me as well. Thanks again..

Tested-by: Brian Foster <bfoster@redhat.com>

>  fs/fuse/file.c | 5 ++---
>  1 file changed, 2 insertions(+), 3 deletions(-)
> 
> diff --git a/fs/fuse/file.c b/fs/fuse/file.c
> index 3d0b33be3824..a05a589dc701 100644
> --- a/fs/fuse/file.c
> +++ b/fs/fuse/file.c
> @@ -1147,7 +1147,7 @@ static ssize_t fuse_send_write_pages(struct fuse_io_args *ia,
>  static ssize_t fuse_fill_write_pages(struct fuse_io_args *ia,
>  				     struct address_space *mapping,
>  				     struct iov_iter *ii, loff_t pos,
> -				     unsigned int max_pages)
> +				     unsigned int max_folios)
>  {
>  	struct fuse_args_pages *ap = &ia->ap;
>  	struct fuse_conn *fc = get_fuse_conn(mapping->host);
> @@ -1157,12 +1157,11 @@ static ssize_t fuse_fill_write_pages(struct fuse_io_args *ia,
>  	int err = 0;
>  
>  	num = min(iov_iter_count(ii), fc->max_write);
> -	num = min(num, max_pages << PAGE_SHIFT);
>  
>  	ap->args.in_pages = true;
>  	ap->descs[0].offset = offset;
>  
> -	while (num) {
> +	while (num && ap->num_folios < max_folios) {
>  		size_t tmp;
>  		struct folio *folio;
>  		pgoff_t index = pos >> PAGE_SHIFT;
> -- 
> 2.47.1
> 


  reply	other threads:[~2025-06-14 10:54 UTC|newest]

Thread overview: 6+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2025-06-14  0:01 [PATCH] fuse: fix fuse_fill_write_pages() upper bound calculation Joanne Koong
2025-06-14 10:58 ` Brian Foster [this message]
2025-06-24  0:35   ` Joanne Koong
2025-06-24  9:07     ` Christian Brauner
2025-06-24 22:57       ` Joanne Koong
2025-06-24  9:07 ` Christian Brauner

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=aE1VvnDfZj0oJMMv@bfoster \
    --to=bfoster@redhat.com \
    --cc=joannelkoong@gmail.com \
    --cc=linux-fsdevel@vger.kernel.org \
    --cc=miklos@szeredi.hu \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.