mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* [PATCH] rbd: check snap_count against RBD_MAX_SNAP_COUNT
@ 2026-05-30  1:12 Rosen Penev
  2026-05-30  1:44 ` Alex Elder
  2026-06-01 14:23 ` Jens Axboe
  0 siblings, 2 replies; 3+ messages in thread
From: Rosen Penev @ 2026-05-30  1:12 UTC (permalink / raw)
  To: linux-block
  Cc: Ilya Dryomov, Dongsheng Yang, Jens Axboe, Nathan Chancellor,
	Nick Desaulniers, Bill Wendling, Justin Stitt,
	open list:RADOS BLOCK DEVICE (RBD),
	open list,
	open list:CLANG/LLVM BUILD SUPPORT:Keyword:b(?i:clang|llvm)b

snap_count is u32 but the comparison is against a SIZE_MAX-derived value
(~2^61 on 64-bit), which clang flags as always false with
-Wtautological-constant-out-of-range-compare.

The proper check here should be that snap_count does not go over
RBD_MAX_SNAP_COUNT.

Assisted-by: Opencode:Big-pickle
Signed-off-by: Rosen Penev <rosenp@gmail.com>
---
 drivers/block/rbd.c | 7 ++-----
 1 file changed, 2 insertions(+), 5 deletions(-)

diff --git a/drivers/block/rbd.c b/drivers/block/rbd.c
index 94709466ad19..25215c209484 100644
--- a/drivers/block/rbd.c
+++ b/drivers/block/rbd.c
@@ -6075,12 +6075,9 @@ static int rbd_dev_v2_snap_context(struct rbd_device *rbd_dev,
 
 	/*
 	 * Make sure the reported number of snapshot ids wouldn't go
-	 * beyond the end of our buffer.  But before checking that,
-	 * make sure the computed size of the snapshot context we
-	 * allocate is representable in a size_t.
+	 * beyond the end of our buffer.
 	 */
-	if (snap_count > (SIZE_MAX - sizeof (struct ceph_snap_context))
-				 / sizeof (u64)) {
+	if (snap_count > RBD_MAX_SNAP_COUNT) {
 		ret = -EINVAL;
 		goto out;
 	}
-- 
2.54.0


^ permalink raw reply	[flat|nested] 3+ messages in thread

end of thread, other threads:[~2026-06-01 14:24 UTC | newest]

Thread overview: 3+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-05-30  1:12 [PATCH] rbd: check snap_count against RBD_MAX_SNAP_COUNT Rosen Penev
2026-05-30  1:44 ` Alex Elder
2026-06-01 14:23 ` Jens Axboe

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®