ext3: Add sanity check to make_indexed_dir
Make sure the rec_len field in the '..' entry is sane, lest we overrun the directory block and cause a kernel oops on a purposefully corrupted filesystem. This fixes a bug related to a bug originally reported by Sami Liedes for ext4 at: http://bugzilla.kernel.org/show_bug.cgi?id=12430 Signed-off-by: "Theodore Ts'o" <tytso@mit.edu> Cc: stable@kernel.org
This commit is contained in:
parent
e6b8bc09ba
commit
a21102b55c
1 changed files with 14 additions and 6 deletions
|
@ -1358,7 +1358,7 @@ static int make_indexed_dir(handle_t *handle, struct dentry *dentry,
|
||||||
struct fake_dirent *fde;
|
struct fake_dirent *fde;
|
||||||
|
|
||||||
blocksize = dir->i_sb->s_blocksize;
|
blocksize = dir->i_sb->s_blocksize;
|
||||||
dxtrace(printk("Creating index\n"));
|
dxtrace(printk(KERN_DEBUG "Creating index: inode %lu\n", dir->i_ino));
|
||||||
retval = ext3_journal_get_write_access(handle, bh);
|
retval = ext3_journal_get_write_access(handle, bh);
|
||||||
if (retval) {
|
if (retval) {
|
||||||
ext3_std_error(dir->i_sb, retval);
|
ext3_std_error(dir->i_sb, retval);
|
||||||
|
@ -1367,6 +1367,19 @@ static int make_indexed_dir(handle_t *handle, struct dentry *dentry,
|
||||||
}
|
}
|
||||||
root = (struct dx_root *) bh->b_data;
|
root = (struct dx_root *) bh->b_data;
|
||||||
|
|
||||||
|
/* The 0th block becomes the root, move the dirents out */
|
||||||
|
fde = &root->dotdot;
|
||||||
|
de = (struct ext3_dir_entry_2 *)((char *)fde +
|
||||||
|
ext3_rec_len_from_disk(fde->rec_len));
|
||||||
|
if ((char *) de >= (((char *) root) + blocksize)) {
|
||||||
|
ext3_error(dir->i_sb, __func__,
|
||||||
|
"invalid rec_len for '..' in inode %lu",
|
||||||
|
dir->i_ino);
|
||||||
|
brelse(bh);
|
||||||
|
return -EIO;
|
||||||
|
}
|
||||||
|
len = ((char *) root) + blocksize - (char *) de;
|
||||||
|
|
||||||
bh2 = ext3_append (handle, dir, &block, &retval);
|
bh2 = ext3_append (handle, dir, &block, &retval);
|
||||||
if (!(bh2)) {
|
if (!(bh2)) {
|
||||||
brelse(bh);
|
brelse(bh);
|
||||||
|
@ -1375,11 +1388,6 @@ static int make_indexed_dir(handle_t *handle, struct dentry *dentry,
|
||||||
EXT3_I(dir)->i_flags |= EXT3_INDEX_FL;
|
EXT3_I(dir)->i_flags |= EXT3_INDEX_FL;
|
||||||
data1 = bh2->b_data;
|
data1 = bh2->b_data;
|
||||||
|
|
||||||
/* The 0th block becomes the root, move the dirents out */
|
|
||||||
fde = &root->dotdot;
|
|
||||||
de = (struct ext3_dir_entry_2 *)((char *)fde +
|
|
||||||
ext3_rec_len_from_disk(fde->rec_len));
|
|
||||||
len = ((char *) root) + blocksize - (char *) de;
|
|
||||||
memcpy (data1, de, len);
|
memcpy (data1, de, len);
|
||||||
de = (struct ext3_dir_entry_2 *) data1;
|
de = (struct ext3_dir_entry_2 *) data1;
|
||||||
top = data1 + len;
|
top = data1 + len;
|
||||||
|
|
Loading…
Reference in a new issue