Re: [PATCH] cifs: fix loff_t underflow in cifs_remap_file_range() when len == 0
Paulo Alcantara <[email protected]>
| Newsgroups | org.kernel.vger.stable,org.kernel.vger.linux-cifs |
|---|---|
| Message-ID | <[email protected]> |
Frank Sorenson <[email protected]> writes: > With len == 0 (clone to EOF), the effective length is computed as: > > len = src_inode->i_size - off; > > If off > i_size, this is a negative loff_t, corrupting the ByteCount > in the FSCTL_DUPLICATE_EXTENTS_TO_FILE request and inverting the range > in filemap_write_and_wait_range(). The existing off >= i_size check > fires only after the ioctl has already been sent. > > Snapshot i_size_read() once for both the bounds check and the length > calculation, eliminating the TOCTOU and 32-bit torn-read risk. Reject > off > src_size with -EINVAL. Treat off == src_size as a no-op, > consistent with __generic_remap_file_range_prep(). > ... Applied.