fs/jfs/jfs_dtree.c | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-)
Replace hardcoded value 127 with DTPAGEMAXSLOT constant in boundary
checks within jfs_readdir() and dtReadFirst(). This improves code
maintainability and ensures consistency with the defined maximum
slot value.
Fixes: ca84a2c9be48 ("jfs: array-index-out-of-bounds fix in dtReadFirst")
Fixes: 839f102efb16 ("jfs: fix array-index-out-of-bounds in jfs_readdir")
Signed-off-by: Zheng Yu <zheng.yu@northwestern.edu>
---
fs/jfs/jfs_dtree.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/fs/jfs/jfs_dtree.c b/fs/jfs/jfs_dtree.c
index ab11849cf9cc..0ab83bb7bbdf 100644
--- a/fs/jfs/jfs_dtree.c
+++ b/fs/jfs/jfs_dtree.c
@@ -2903,7 +2903,7 @@ int jfs_readdir(struct file *file, struct dir_context *ctx)
stbl = DT_GETSTBL(p);
for (i = index; i < p->header.nextindex; i++) {
- if (stbl[i] < 0 || stbl[i] > 127) {
+ if (stbl[i] < 0 || stbl[i] >= DTPAGEMAXSLOT) {
jfs_err("JFS: Invalid stbl[%d] = %d for inode %ld, block = %lld",
i, stbl[i], (long)ip->i_ino, (long long)bn);
free_page(dirent_buf);
@@ -3108,7 +3108,7 @@ static int dtReadFirst(struct inode *ip, struct btstack * btstack)
/* get the leftmost entry */
stbl = DT_GETSTBL(p);
- if (stbl[0] < 0 || stbl[0] > 127) {
+ if (stbl[0] < 0 || stbl[0] >= DTPAGEMAXSLOT) {
DT_PUTPAGE(mp);
jfs_error(ip->i_sb, "stbl[0] out of bound\n");
return -EIO;
--
2.43.0
Looks good. I'll apply and test this. I'm removing the Fixes: lines because this is cosmetic and not really a bug fix. There's no need to flag this for stable. Thanks, Shaggy On 7/29/25 1:28PM, Zheng Yu wrote: > Replace hardcoded value 127 with DTPAGEMAXSLOT constant in boundary > checks within jfs_readdir() and dtReadFirst(). This improves code > maintainability and ensures consistency with the defined maximum > slot value. > > Fixes: ca84a2c9be48 ("jfs: array-index-out-of-bounds fix in dtReadFirst") > Fixes: 839f102efb16 ("jfs: fix array-index-out-of-bounds in jfs_readdir") > Signed-off-by: Zheng Yu <zheng.yu@northwestern.edu> > --- > fs/jfs/jfs_dtree.c | 4 ++-- > 1 file changed, 2 insertions(+), 2 deletions(-) > > diff --git a/fs/jfs/jfs_dtree.c b/fs/jfs/jfs_dtree.c > index ab11849cf9cc..0ab83bb7bbdf 100644 > --- a/fs/jfs/jfs_dtree.c > +++ b/fs/jfs/jfs_dtree.c > @@ -2903,7 +2903,7 @@ int jfs_readdir(struct file *file, struct dir_context *ctx) > stbl = DT_GETSTBL(p); > > for (i = index; i < p->header.nextindex; i++) { > - if (stbl[i] < 0 || stbl[i] > 127) { > + if (stbl[i] < 0 || stbl[i] >= DTPAGEMAXSLOT) { > jfs_err("JFS: Invalid stbl[%d] = %d for inode %ld, block = %lld", > i, stbl[i], (long)ip->i_ino, (long long)bn); > free_page(dirent_buf); > @@ -3108,7 +3108,7 @@ static int dtReadFirst(struct inode *ip, struct btstack * btstack) > /* get the leftmost entry */ > stbl = DT_GETSTBL(p); > > - if (stbl[0] < 0 || stbl[0] > 127) { > + if (stbl[0] < 0 || stbl[0] >= DTPAGEMAXSLOT) { > DT_PUTPAGE(mp); > jfs_error(ip->i_sb, "stbl[0] out of bound\n"); > return -EIO; > -- > 2.43.0
© 2016 - 2025 Red Hat, Inc.