drivers/block/rbd.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-)
snap_count is u32 but the comparison is against a SIZE_MAX-derived value
(~2^61 on 64-bit), which clang flags as always false with
-Wtautological-constant-out-of-range-compare. Cast to size_t so the
comparison is done in the correct width.
Assisted-by: Opencode:Big-pickle
Signed-off-by: Rosen Penev <rosenp@gmail.com>
---
drivers/block/rbd.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/block/rbd.c b/drivers/block/rbd.c
index 94709466ad19..b4ba51db9a28 100644
--- a/drivers/block/rbd.c
+++ b/drivers/block/rbd.c
@@ -6079,7 +6079,7 @@ static int rbd_dev_v2_snap_context(struct rbd_device *rbd_dev,
* make sure the computed size of the snapshot context we
* allocate is representable in a size_t.
*/
- if (snap_count > (SIZE_MAX - sizeof (struct ceph_snap_context))
+ if ((size_t)snap_count > (SIZE_MAX - sizeof (struct ceph_snap_context))
/ sizeof (u64)) {
ret = -EINVAL;
goto out;
--
2.54.0
On Thu, 28 May 2026 13:21:51 -0700
Rosen Penev <rosenp@gmail.com> wrote:
> snap_count is u32 but the comparison is against a SIZE_MAX-derived value
> (~2^61 on 64-bit), which clang flags as always false with
> -Wtautological-constant-out-of-range-compare. Cast to size_t so the
> comparison is done in the correct width.
If that warning makes any sense then the cast shouldn't make any difference.
Why not check against RBD_MAX_SNAP_COUNT - the buffer isn't big enough
to hold any more than that.
-- David
>
> Assisted-by: Opencode:Big-pickle
> Signed-off-by: Rosen Penev <rosenp@gmail.com>
> ---
> drivers/block/rbd.c | 2 +-
> 1 file changed, 1 insertion(+), 1 deletion(-)
>
> diff --git a/drivers/block/rbd.c b/drivers/block/rbd.c
> index 94709466ad19..b4ba51db9a28 100644
> --- a/drivers/block/rbd.c
> +++ b/drivers/block/rbd.c
> @@ -6079,7 +6079,7 @@ static int rbd_dev_v2_snap_context(struct rbd_device *rbd_dev,
> * make sure the computed size of the snapshot context we
> * allocate is representable in a size_t.
> */
> - if (snap_count > (SIZE_MAX - sizeof (struct ceph_snap_context))
> + if ((size_t)snap_count > (SIZE_MAX - sizeof (struct ceph_snap_context))
> / sizeof (u64)) {
> ret = -EINVAL;
> goto out;
On 5/28/26 4:05 PM, David Laight wrote:
> On Thu, 28 May 2026 13:21:51 -0700
> Rosen Penev <rosenp@gmail.com> wrote:
>
>> snap_count is u32 but the comparison is against a SIZE_MAX-derived value
>> (~2^61 on 64-bit), which clang flags as always false with
>> -Wtautological-constant-out-of-range-compare. Cast to size_t so the
>> comparison is done in the correct width.
>
> If that warning makes any sense then the cast shouldn't make any difference.
>
> Why not check against RBD_MAX_SNAP_COUNT - the buffer isn't big enough
> to hold any more than that.
I like that better. Please do that instead (despite my
Reviewed-by provided earlier).
-Alex
>
> -- David
>
>>
>> Assisted-by: Opencode:Big-pickle
>> Signed-off-by: Rosen Penev <rosenp@gmail.com>
>> ---
>> drivers/block/rbd.c | 2 +-
>> 1 file changed, 1 insertion(+), 1 deletion(-)
>>
>> diff --git a/drivers/block/rbd.c b/drivers/block/rbd.c
>> index 94709466ad19..b4ba51db9a28 100644
>> --- a/drivers/block/rbd.c
>> +++ b/drivers/block/rbd.c
>> @@ -6079,7 +6079,7 @@ static int rbd_dev_v2_snap_context(struct rbd_device *rbd_dev,
>> * make sure the computed size of the snapshot context we
>> * allocate is representable in a size_t.
>> */
>> - if (snap_count > (SIZE_MAX - sizeof (struct ceph_snap_context))
>> + if ((size_t)snap_count > (SIZE_MAX - sizeof (struct ceph_snap_context))
>> / sizeof (u64)) {
>> ret = -EINVAL;
>> goto out;
>
>
On 5/28/26 3:21 PM, Rosen Penev wrote:
> snap_count is u32 but the comparison is against a SIZE_MAX-derived value
> (~2^61 on 64-bit), which clang flags as always false with
> -Wtautological-constant-out-of-range-compare. Cast to size_t so the
> comparison is done in the correct width.
>
> Assisted-by: Opencode:Big-pickle
> Signed-off-by: Rosen Penev <rosenp@gmail.com>
This is a simple fix.
You might consider doing something similar for this code in
rbd_dev_ondisk_valid():
snap_count = le32_to_cpu(ondisk->snap_count);
size = SIZE_MAX - sizeof (struct ceph_snap_context);
if (snap_count > size / sizeof (__le64))
return false;
Reviewed-by: Alex Elder <elder@riscstar.com>
> ---
> drivers/block/rbd.c | 2 +-
> 1 file changed, 1 insertion(+), 1 deletion(-)
>
> diff --git a/drivers/block/rbd.c b/drivers/block/rbd.c
> index 94709466ad19..b4ba51db9a28 100644
> --- a/drivers/block/rbd.c
> +++ b/drivers/block/rbd.c
> @@ -6079,7 +6079,7 @@ static int rbd_dev_v2_snap_context(struct rbd_device *rbd_dev,
> * make sure the computed size of the snapshot context we
> * allocate is representable in a size_t.
> */
> - if (snap_count > (SIZE_MAX - sizeof (struct ceph_snap_context))
> + if ((size_t)snap_count > (SIZE_MAX - sizeof (struct ceph_snap_context))
> / sizeof (u64)) {
> ret = -EINVAL;
> goto out;
© 2016 - 2026 Red Hat, Inc.