Re: [PATCH] cifs: fix loff_t underflow in cifs_remap_file_range() when len == 0
Namjae Jeon <[email protected]>
| Newsgroups | org.kernel.vger.linux-cifs,org.kernel.vger.stable |
|---|---|
| Message-ID | <CAKYAXd-eHBebxFfNgSwJ2iHd6WX9u7xvLzeRwzp=yJTamEYcmQ@mail.gmail.com> |
On Sun, Aug 23, 2026 at 6:55 AM Frank Sorenson <[email protected]> wrote: > > With len == 0 (clone to EOF), the effective length is computed as: > > len = src_inode->i_size - off; > > If off > i_size, this is a negative loff_t, corrupting the ByteCount > in the FSCTL_DUPLICATE_EXTENTS_TO_FILE request and inverting the range > in filemap_write_and_wait_range(). The existing off >= i_size check > fires only after the ioctl has already been sent. > > Snapshot i_size_read() once for both the bounds check and the length > calculation, eliminating the TOCTOU and 32-bit torn-read risk. Reject > off > src_size with -EINVAL. Treat off == src_size as a no-op, > consistent with __generic_remap_file_range_prep(). > > Fixes: 04b38d601239 ("vfs: pull btrfs clone API to vfs layer") > Cc: [email protected] > Signed-off-by: Frank Sorenson <[email protected]> Reviewed-by: Namjae Jeon <[email protected]> Thanks.