Linux XFS filesystem development
 help / color / mirror / Atom feed
From: Eric Sandeen <sandeen@redhat.com>
To: linux-xfs@vger.kernel.org
Cc: djwong@kernel.org, aalbersh@kernel.org,
	Eric Sandeen <sandeen@redhat.com>
Subject: [PATCH 3/3] libxfs: do not allow cache growth to overflow
Date: Fri, 25 Sep 2026 14:41:45 -0500	[thread overview]
Message-ID: <20260925194535.397036-4-sandeen@redhat.com> (raw)
In-Reply-To: <20260925194535.397036-1-sandeen@redhat.com>

Nothing stops cache_expand() from growing c_maxcount (via *2)
repeatedly until it overflows.

Add a bounds check here and return failure if for any reason we try to
grow too much.

With the prior fixes, we should never get this far, but it's worth
defending against anyway.

Signed-off-by: Eric Sandeen <sandeen@redhat.com>
---
 libxfs/cache.c | 20 +++++++++++++++-----
 1 file changed, 15 insertions(+), 5 deletions(-)

diff --git a/libxfs/cache.c b/libxfs/cache.c
index 60bfcdc5..03b62bc7 100644
--- a/libxfs/cache.c
+++ b/libxfs/cache.c
@@ -79,16 +79,24 @@ cache_init(
 	return cache;
 }
 
-static void
+/* Double the cache size limit; return false if it would overflow. */
+static bool
 cache_expand(
 	struct cache *		cache)
 {
+	bool			expanded = false;
+
 	pthread_mutex_lock(&cache->c_mutex);
+	if (cache->c_maxcount <= UINT_MAX / 2) {
 #ifdef CACHE_DEBUG
-	fprintf(stderr, "doubling cache size to %u\n", 2 * cache->c_maxcount);
+		fprintf(stderr, "doubling cache size to %u\n",
+				2 * cache->c_maxcount);
 #endif
-	cache->c_maxcount *= 2;
+		cache->c_maxcount *= 2;
+		expanded = true;
+	}
 	pthread_mutex_unlock(&cache->c_mutex);
+	return expanded;
 }
 
 void
@@ -375,7 +383,8 @@ __cache_node_purge(
  * Otherwise, we allocate a new node, taking care not to expand the
  * cache beyond the requested maximum size (shrink it if it would).
  * Returns zero if hit in cache, one if a new node was allocated.  Returns
- * -ENOMEM if allocation fails after cache shaking is exhausted.
+ * -ENOMEM if allocation fails after cache shaking is exhausted, or if the
+ * cache cannot be expanded further without overflowing.
  */
 int
 cache_node_get(
@@ -485,8 +494,9 @@ next_object:
 			 */
 			if (error < 0)
 				return error;
+			if (!cache_expand(cache))
+				return -ENOMEM;
 			priority = 0;
-			cache_expand(cache);
 		}
 	}
 
-- 
2.55.0


  parent reply	other threads:[~2026-09-25 19:45 UTC|newest]

Thread overview: 10+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-25 19:41 [PATCH 0/3 V3] libxfs: better cache allocation error handling Eric Sandeen
2026-09-25 19:41 ` [PATCH 1/3] libxfs: change cache_node_allocate function signature Eric Sandeen
2026-09-25 22:56   ` Darrick J. Wong
2026-09-25 19:41 ` [PATCH 2/3] libxfs: Return -ENOMEM on actual cache node allocation failures Eric Sandeen
2026-09-25 22:58   ` Darrick J. Wong
2026-09-28 15:07     ` Eric Sandeen
2026-09-25 19:41 ` Eric Sandeen [this message]
2026-09-25 22:59   ` [PATCH 3/3] libxfs: do not allow cache growth to overflow Darrick J. Wong
2026-09-28  8:16 ` [PATCH 0/3 V3] libxfs: better cache allocation error handling Christoph Hellwig
2026-09-28 15:05   ` Eric Sandeen

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260925194535.397036-4-sandeen@redhat.com \
    --to=sandeen@redhat.com \
    --cc=aalbersh@kernel.org \
    --cc=djwong@kernel.org \
    --cc=linux-xfs@vger.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox