* [RFC] ext4: off by one check in ext4_ext_convert_to_initialized()
@ 2012-06-23 9:15 Dan Carpenter
0 siblings, 0 replies; only message in thread
From: Dan Carpenter @ 2012-06-23 9:15 UTC (permalink / raw)
To: Theodore Ts'o
Cc: Andreas Dilger, linux-ext4, kernel-janitors, Yongqiang Yang
I am not very familiar with this code, but I think that we should be
using "<= EXT4_EXT_ZERO_LEN" here instead of "< EXT4_EXT_ZERO_LEN".
1) The other comparisons with EXT4_EXT_ZERO_LEN use "<=".
2) On the first side of the if else statement we do:
if (allocated <= EXT4_EXT_ZERO_LEN ...
split_map.m_len = allocated;
On this side, it would match to do:
if (map->m_lblk - ee_block + map->m_len <= EXT4_EXT_ZERO_LEN ...
split_map.m_len = map->m_lblk - ee_block + map->m_len;
It's not the most air tight of arguments, so I've submitted this with a
big warning message.
Signed-off-by: Dan Carpenter <dan.carpenter@oracle.com>
diff --git a/fs/ext4/extents.c b/fs/ext4/extents.c
index 91341ec..2df32a4 100644
--- a/fs/ext4/extents.c
+++ b/fs/ext4/extents.c
@@ -3208,7 +3208,7 @@ static int ext4_ext_convert_to_initialized(handle_t *handle,
goto out;
split_map.m_lblk = map->m_lblk;
split_map.m_len = allocated;
- } else if ((map->m_lblk - ee_block + map->m_len <
+ } else if ((map->m_lblk - ee_block + map->m_len <=
EXT4_EXT_ZERO_LEN) &&
(EXT4_EXT_MAY_ZEROOUT & split_flag)) {
/* case 2 */
^ permalink raw reply related [flat|nested] only message in thread
only message in thread, other threads:[~2012-06-23 9:15 UTC | newest]
Thread overview: (only message) (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2012-06-23 9:15 [RFC] ext4: off by one check in ext4_ext_convert_to_initialized() Dan Carpenter
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox