fs/erofs/zmap.c | 2 ++ 1 file changed, 2 insertions(+)
Sometimes, the on-disk metadata might be invalid due to storage
failure or other unknown issues.
In that case, z_erofs_map_blocks_iter() may still return a valid
m_llen while other fields remain invalid (e.g., m_plen can be 0).
Due to the return value of z_erofs_scan_folio() in some path will
be ignored on purpose, the following z_erofs_scan_folio() could
then use the invalid value by accident.
Let's reset m_llen to 0 to prevent this.
Signed-off-by: Gao Xiang <hsiangkao@linux.alibaba.com>
---
fs/erofs/zmap.c | 2 ++
1 file changed, 2 insertions(+)
diff --git a/fs/erofs/zmap.c b/fs/erofs/zmap.c
index 9b248ee5fef2..74d3d7bffcf3 100644
--- a/fs/erofs/zmap.c
+++ b/fs/erofs/zmap.c
@@ -711,6 +711,8 @@ int z_erofs_map_blocks_iter(struct inode *inode, struct erofs_map_blocks *map,
err = z_erofs_do_map_blocks(inode, map, flags);
out:
+ if (err)
+ map->m_llen = 0;
trace_z_erofs_map_blocks_iter_exit(inode, map, flags, err);
return err;
}
--
2.43.5
On 2024/6/30 02:57, Gao Xiang wrote: > Sometimes, the on-disk metadata might be invalid due to storage > failure or other unknown issues. user interrupts, storage failures, or other unknown causes. > > In that case, z_erofs_map_blocks_iter() may still return a valid > m_llen while other fields remain invalid (e.g., m_plen can be 0). > > Due to the return value of z_erofs_scan_folio() in some path will > be ignored on purpose, the following z_erofs_scan_folio() could > then use the invalid value by accident. > > Let's reset m_llen to 0 to prevent this. > > Signed-off-by: Gao Xiang <hsiangkao@linux.alibaba.com> > --- > fs/erofs/zmap.c | 2 ++ > 1 file changed, 2 insertions(+) > > diff --git a/fs/erofs/zmap.c b/fs/erofs/zmap.c > index 9b248ee5fef2..74d3d7bffcf3 100644 > --- a/fs/erofs/zmap.c > +++ b/fs/erofs/zmap.c > @@ -711,6 +711,8 @@ int z_erofs_map_blocks_iter(struct inode *inode, struct erofs_map_blocks *map, > > err = z_erofs_do_map_blocks(inode, map, flags); > out: > + if (err) > + map->m_llen = 0; > trace_z_erofs_map_blocks_iter_exit(inode, map, flags, err); > return err; > }
© 2016 - 2025 Red Hat, Inc.