[PATCH v2] mtd: block2mtd: Fix divide error when erase_size is zero

Pei Xiao <[email protected]>
Newsgroups org.kernel.vger.stable,org.infradead.lists.linux-mtd,org.kernel.vger.linux-kernel
Message-ID <48230456575d27aa83ce8640de8fc07cc62e8efb.1786499433.git.xiaopei01@kylinos.cn>
The erase size is parsed from the "block2mtd" module parameter and can
be set to zero. add_device() then evaluates

        if (size % erase_size)

with a zero divisor, which triggers a divide error:

        divide error: 0000 [#1] PREEMPT SMP PTI
        RIP: 0010:add_device drivers/mtd/devices/block2mtd.c:296 [inline]
        RIP: 0010:block2mtd_setup2+0x592/0xda0 drivers/mtd/devices/block2mtd.c:459
        Call Trace:
         block2mtd_setup+0x27/0xe0 drivers/mtd/devices/block2mtd.c:476
         param_attr_store+0x214/0x310 kernel/params.c:589
         module_attr_store+0x65/0x90 kernel/params.c:904
         kernfs_fop_write_iter+0x3a4/0x540 fs/kernfs/file.c:345
         ...

Reject a zero erase size before performing the modulo operation so the
existing "erasesize must be a divisor of device size" error path
reports the invalid argument and frees the device.

While at it, drop the unnecessary (long) cast from the size operand of
the modulo.

Fixes: ea6d833a3fdd ("mtd: block2mtd: check device size")
Reported-by: [email protected]
Closes: https://lore.kernel.org/lkml/[email protected]/
Suggested-by: Jörn Engel <[email protected]>
Cc: [email protected]
Signed-off-by: Pei Xiao <[email protected]>
---
changlogs in v2:
1.Add Suggested-by tag
2.remove unnecessary (long) cast from the size
---
 drivers/mtd/devices/block2mtd.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/drivers/mtd/devices/block2mtd.c b/drivers/mtd/devices/block2mtd.c
index 03e80b2c4f5a..3e2367dfff88 100644
--- a/drivers/mtd/devices/block2mtd.c
+++ b/drivers/mtd/devices/block2mtd.c
@@ -293,7 +293,7 @@ static struct block2mtd_dev *add_device(char *devname, int erase_size,
 	}
 
 	size = bdev_nr_bytes(bdev);
-	if ((long)size % erase_size) {
+	if (!erase_size || size % erase_size) {
 		pr_err("erasesize must be a divisor of device size\n");
 		goto err_free_block2mtd;
 	}
-- 
2.25.1
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.