From: Bill O'Donnell Date: Fri, 5 Oct 2018 02:36:11 +0000 (-0500) Subject: libxfs: add more bounds checking to sb sanity checks X-Git-Tag: v4.19.0-rc0~25 X-Git-Url: http://git.ipfire.org/?a=commitdiff_plain;h=5a5276224333719a422e8b6e54c455d9ccebeca9;p=thirdparty%2Fxfsprogs-dev.git libxfs: add more bounds checking to sb sanity checks Source kernel commit: 8756a5af18191a471e670cc577aea60b652fea4c Current sb verifier doesn't check bounds on sb_fdblocks and sb_ifree. Add sanity checks for these parameters. Signed-off-by: Bill O'Donnell [darrick: port to refactored sb validation predicates] Signed-off-by: Darrick J. Wong Reviewed-by: Eric Sandeen Signed-off-by: Eric Sandeen --- diff --git a/libxfs/xfs_sb.c b/libxfs/xfs_sb.c index c9ad7e364..85210df8c 100644 --- a/libxfs/xfs_sb.c +++ b/libxfs/xfs_sb.c @@ -147,6 +147,18 @@ xfs_validate_sb_write( struct xfs_mount *mp, struct xfs_sb *sbp) { + /* + * Carry out additional sb summary counter sanity checks when we write + * the superblock. We skip this in the read validator because there + * could be newer superblocks in the log and if the values are garbage + * we'll recalculate them at the end of log mount. + */ + if (sbp->sb_fdblocks > sbp->sb_dblocks || + sbp->sb_ifree > sbp->sb_icount) { + xfs_warn(mp, "SB summary counter sanity check failed"); + return -EFSCORRUPTED; + } + if (XFS_SB_VERSION_NUM(sbp) != XFS_SB_VERSION_5) return 0;