]> git.ipfire.org Git - thirdparty/kernel/stable.git/commitdiff
orangefs: fix out-of-bounds fsid access
authorMike Marshall <hubcap@omnibond.com>
Wed, 1 May 2024 20:20:36 +0000 (16:20 -0400)
committerGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Thu, 18 Jul 2024 09:40:49 +0000 (11:40 +0200)
[ Upstream commit 53e4efa470d5fc6a96662d2d3322cfc925818517 ]

Arnd Bergmann sent a patch to fsdevel, he says:

"orangefs_statfs() copies two consecutive fields of the superblock into
the statfs structure, which triggers a warning from the string fortification
helpers"

Jan Kara suggested an alternate way to do the patch to make it more readable.

I ran both ideas through xfstests and both seem fine. This patch
is based on Jan Kara's suggestion.

Signed-off-by: Mike Marshall <hubcap@omnibond.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
fs/orangefs/super.c

index 2f2e430461b2141cb76d6d1c210d9c7f8bdc7b48..b48aef43b51d5efbfde9727c4b65c4b84811bed9 100644 (file)
@@ -200,7 +200,8 @@ static int orangefs_statfs(struct dentry *dentry, struct kstatfs *buf)
                     (long)new_op->downcall.resp.statfs.files_avail);
 
        buf->f_type = sb->s_magic;
-       memcpy(&buf->f_fsid, &ORANGEFS_SB(sb)->fs_id, sizeof(buf->f_fsid));
+       buf->f_fsid.val[0] = ORANGEFS_SB(sb)->fs_id;
+       buf->f_fsid.val[1] = ORANGEFS_SB(sb)->id;
        buf->f_bsize = new_op->downcall.resp.statfs.block_size;
        buf->f_namelen = ORANGEFS_NAME_MAX;