Skip to content

Commit

Permalink
filemap: Fix bounds checking in filemap_read()
Browse files Browse the repository at this point in the history
[ Upstream commit ace149e ]

If the caller supplies an iocb->ki_pos value that is close to the
filesystem upper limit, and an iterator with a count that causes us to
overflow that limit, then filemap_read() enters an infinite loop.

This behaviour was discovered when testing xfstests generic/525 with the
"localio" optimisation for loopback NFS mounts.

Reported-by: Mike Snitzer <snitzer@kernel.org>
Fixes: c2a9737 ("vfs,mm: fix a dead loop in truncate_inode_pages_range()")
Tested-by: Mike Snitzer <snitzer@kernel.org>
Signed-off-by: Trond Myklebust <trond.myklebust@hammerspace.com>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
(cherry picked from commit ace149e)
[Harshit: Minor conflict resolved due to missing commit: 25d6a23
("filemap: Convert filemap_get_read_batch() to use a folio_batch") in
5.15.y]
Signed-off-by: Harshit Mogalapalli <harshit.m.mogalapalli@oracle.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
  • Loading branch information
Trond Myklebust authored and Greg Kroah-Hartman committed May 2, 2025
1 parent 90c8482 commit 6cc52df
Showing 1 changed file with 1 addition and 1 deletion.
2 changes: 1 addition & 1 deletion mm/filemap.c
Original file line number Diff line number Diff line change
Expand Up @@ -2617,7 +2617,7 @@ ssize_t filemap_read(struct kiocb *iocb, struct iov_iter *iter,
if (unlikely(!iov_iter_count(iter)))
return 0;

iov_iter_truncate(iter, inode->i_sb->s_maxbytes);
iov_iter_truncate(iter, inode->i_sb->s_maxbytes - iocb->ki_pos);
pagevec_init(&pvec);

do {
Expand Down

0 comments on commit 6cc52df

Please sign in to comment.