]> git.ipfire.org Git - thirdparty/kernel/stable.git/commitdiff
ext4: in ext4_seek_{hole,data}, return -ENXIO for negative offsets
authorDarrick J. Wong <darrick.wong@oracle.com>
Thu, 24 Aug 2017 17:22:06 +0000 (13:22 -0400)
committerWilly Tarreau <w@1wt.eu>
Thu, 2 Nov 2017 06:16:21 +0000 (07:16 +0100)
commit 1bd8d6cd3e413d64e543ec3e69ff43e75a1cf1ea upstream.

In the ext4 implementations of SEEK_HOLE and SEEK_DATA, make sure we
return -ENXIO for negative offsets instead of banging around inside
the extent code and returning -EFSCORRUPTED.

Reported-by: Mateusz S <muttdini@gmail.com>
Signed-off-by: Darrick J. Wong <darrick.wong@oracle.com>
Signed-off-by: Theodore Ts'o <tytso@mit.edu>
Cc: stable@vger.kernel.org # 4.6
Signed-off-by: Willy Tarreau <w@1wt.eu>
fs/ext4/file.c

index dfba7b38706ab2e1450a7025d6df199ae54b5655..ed2badabebf0074fc95f1fcae76600c75381f91f 100644 (file)
@@ -421,7 +421,7 @@ static loff_t ext4_seek_data(struct file *file, loff_t offset, loff_t maxsize)
        mutex_lock(&inode->i_mutex);
 
        isize = i_size_read(inode);
-       if (offset >= isize) {
+       if (offset < 0 || offset >= isize) {
                mutex_unlock(&inode->i_mutex);
                return -ENXIO;
        }
@@ -504,7 +504,7 @@ static loff_t ext4_seek_hole(struct file *file, loff_t offset, loff_t maxsize)
        mutex_lock(&inode->i_mutex);
 
        isize = i_size_read(inode);
-       if (offset >= isize) {
+       if (offset < 0 || offset >= isize) {
                mutex_unlock(&inode->i_mutex);
                return -ENXIO;
        }