ext4: set type of ac_groups_linear_remaining to __u32 to avoid overflow
authorBaokun Li <libaokun1@huawei.com>
Tue, 19 Mar 2024 11:33:23 +0000 (19:33 +0800)
committerTheodore Ts'o <tytso@mit.edu>
Fri, 3 May 2024 03:48:31 +0000 (23:48 -0400)
Now ac_groups_linear_remaining is of type __u16 and s_mb_max_linear_groups
is of type unsigned int, so an overflow occurs when setting a value above
65535 through the mb_max_linear_groups sysfs interface. Therefore, the
type of ac_groups_linear_remaining is set to __u32 to avoid overflow.

Fixes: 196e402adf2e ("ext4: improve cr 0 / cr 1 group scanning")
CC: stable@kernel.org
Signed-off-by: Baokun Li <libaokun1@huawei.com>
Reviewed-by: Zhang Yi <yi.zhang@huawei.com>
Reviewed-by: Jan Kara <jack@suse.cz>
Link: https://lore.kernel.org/r/20240319113325.3110393-8-libaokun1@huawei.com
Signed-off-by: Theodore Ts'o <tytso@mit.edu>
fs/ext4/mballoc.h

index 56938532b4ce258e210178d2406e187eec5ef8cc..7bfc5fb5a1285b3c5e9998fd4413723986784bc7 100644 (file)
@@ -193,8 +193,8 @@ struct ext4_allocation_context {
        ext4_grpblk_t   ac_orig_goal_len;
 
        __u32 ac_flags;         /* allocation hints */
+       __u32 ac_groups_linear_remaining;
        __u16 ac_groups_scanned;
-       __u16 ac_groups_linear_remaining;
        __u16 ac_found;
        __u16 ac_cX_found[EXT4_MB_NUM_CRS];
        __u16 ac_tail;