]> git.ipfire.org Git - thirdparty/kernel/linux.git/commit
libceph: Avoid using invalid osd indices from primary_temp
authorRaphael Zimmer <raphael.zimmer@tu-ilmenau.de>
Tue, 28 Jul 2026 08:43:40 +0000 (10:43 +0200)
committerIlya Dryomov <idryomov@gmail.com>
Wed, 12 Aug 2026 19:21:41 +0000 (21:21 +0200)
commit3660b98d1204b419f6a77e9a295f148dcf38d042
tree42662452c591cb9576c4fcae20fad8d0c71425bb
parent00ead17c7de137a692edee59f2772e6af687e8eb
libceph: Avoid using invalid osd indices from primary_temp

A corrupted osdmap received from a Ceph monitor or OSD may contain osd
indices in its pg_temp, primary_temp, pg_upmap, and pg_upmap_items parts
that don't exist, i.e., that are greater than max_osd or smaller than
CEPH_HOMELESS_OSD (-1). These indices are used to create the up and
acting set in ceph_pg_to_up_acting_osds(), called from calc_target().
While most of these osd indices are checked, the one from primary_temp
is not. Subsequently, this may lead to calc_target() returning this
(potentially invalid) index as target osd for a (linger) request.
Because the osd_state, osd_weight, and osd_addr arrays only contain
max_osd entries (with indices 0 to max_osd -1), this leads to
out-of-bounds accesses when trying to read values from these arrays.

This patch fixes the issue by adding a check to get_temp_osds(), so that
only valid osd indices from primary_temp are used, and it falls back to
using the primary from pg_temp or the up set if it is invalid.

[ idryomov: changelog ]

Cc: stable@vger.kernel.org
Fixes: 5e8d4d36bf23 ("libceph: add support for primary_temp mappings")
Signed-off-by: Raphael Zimmer <raphael.zimmer@tu-ilmenau.de>
Reviewed-by: Ilya Dryomov <idryomov@gmail.com>
Signed-off-by: Ilya Dryomov <idryomov@gmail.com>
net/ceph/osdmap.c