Commit b11a05b5 authored by Baokun Li's avatar Baokun Li Committed by ZhaoLong Wang
Browse files

ext4: avoid allocating blocks from corrupted group in ext4_mb_find_by_goal()

mainline inclusion
from mainline-v6.8-rc3
commit 832698373a25950942c04a512daa652c18a9b513
category: bugfix
bugzilla: https://gitee.com/src-openeuler/kernel/issues/I9E2MF
CVE: CVE-2024-26772

Reference: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=832698373a25950942c04a512daa652c18a9b513



--------------------------------

Places the logic for checking if the group's block bitmap is corrupt under
the protection of the group lock to avoid allocating blocks from the group
with a corrupted block bitmap.

Signed-off-by: default avatarBaokun Li <libaokun1@huawei.com>
Reviewed-by: default avatarJan Kara <jack@suse.cz>
Link: https://lore.kernel.org/r/20240104142040.2835097-8-libaokun1@huawei.com


Signed-off-by: default avatarTheodore Ts'o <tytso@mit.edu>
Signed-off-by: default avatarZhaoLong Wang <wangzhaolong1@huawei.com>
parent 1ed85cbd
Loading
Loading
Loading
Loading
+4 −5
Original line number Diff line number Diff line
@@ -1836,12 +1836,10 @@ int ext4_mb_find_by_goal(struct ext4_allocation_context *ac,
	if (err)
		return err;

	if (unlikely(EXT4_MB_GRP_BBITMAP_CORRUPT(e4b->bd_info))) {
		ext4_mb_unload_buddy(e4b);
		return 0;
	}

	ext4_lock_group(ac->ac_sb, group);
	if (unlikely(EXT4_MB_GRP_BBITMAP_CORRUPT(e4b->bd_info)))
		goto out;

	max = mb_find_extent(e4b, ac->ac_g_ex.fe_start,
			     ac->ac_g_ex.fe_len, &ex);
	ex.fe_logical = 0xDEADFA11; /* debug value */
@@ -1874,6 +1872,7 @@ int ext4_mb_find_by_goal(struct ext4_allocation_context *ac,
		ac->ac_b_ex = ex;
		ext4_mb_use_best_found(ac, e4b);
	}
out:
	ext4_unlock_group(ac->ac_sb, group);
	ext4_mb_unload_buddy(e4b);