]> git.ipfire.org Git - thirdparty/kernel/stable.git/commitdiff
ext4: set type of ac_groups_linear_remaining to __u32 to avoid overflow
authorBaokun Li <libaokun1@huawei.com>
Tue, 19 Mar 2024 11:33:23 +0000 (19:33 +0800)
committerGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Sun, 16 Jun 2024 11:41:40 +0000 (13:41 +0200)
commit 9a9f3a9842927e4af7ca10c19c94dad83bebd713 upstream.

Now ac_groups_linear_remaining is of type __u16 and s_mb_max_linear_groups
is of type unsigned int, so an overflow occurs when setting a value above
65535 through the mb_max_linear_groups sysfs interface. Therefore, the
type of ac_groups_linear_remaining is set to __u32 to avoid overflow.

Fixes: 196e402adf2e ("ext4: improve cr 0 / cr 1 group scanning")
CC: stable@kernel.org
Signed-off-by: Baokun Li <libaokun1@huawei.com>
Reviewed-by: Zhang Yi <yi.zhang@huawei.com>
Reviewed-by: Jan Kara <jack@suse.cz>
Link: https://lore.kernel.org/r/20240319113325.3110393-8-libaokun1@huawei.com
Signed-off-by: Theodore Ts'o <tytso@mit.edu>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
fs/ext4/mballoc.h

index 00b3898df4a764ca26f3b41d196682c7f6007a09..538703499d0839bb75dc42ba042a53bcbda4e2d6 100644 (file)
@@ -180,8 +180,8 @@ struct ext4_allocation_context {
 
        __u32 ac_groups_considered;
        __u32 ac_flags;         /* allocation hints */
+       __u32 ac_groups_linear_remaining;
        __u16 ac_groups_scanned;
-       __u16 ac_groups_linear_remaining;
        __u16 ac_found;
        __u16 ac_tail;
        __u16 ac_buddy;