The patch adds strict checks of buffer head overflow
for IAM dx blocks.
HPE-bug-id: LUS-10178
Signed-off-by: Alexander Boyko <alexander.boyko@hpe.com>
Change-Id: I1608f6cbf00b5120fbc36d0c65fcfe37c43e375f
Reviewed-on: https://review.whamcloud.com/45072
Tested-by: jenkins <devops@whamcloud.com>
Tested-by: Maloo <maloo@whamcloud.com>
Reviewed-by: Andreas Dilger <adilger@whamcloud.com>
Reviewed-by: Artem Blagodarenko <artem.blagodarenko@hpe.com>
Reviewed-by: Oleg Drokin <green@whamcloud.com>
assert_corr(count < dx_get_limit(entries));
assert_corr(frame->at < iam_entry_shift(path, entries, count));
assert_inv(dx_node_check(path, frame));
assert_corr(count < dx_get_limit(entries));
assert_corr(frame->at < iam_entry_shift(path, entries, count));
assert_inv(dx_node_check(path, frame));
+ /* Prevent memory corruption outside of buffer_head */
+ BUG_ON(count >= dx_get_limit(entries));
+ BUG_ON((char *)iam_entry_shift(path, entries, count + 1) >
+ (frame->bh->b_data + frame->bh->b_size));
memmove(iam_entry_shift(path, new, 1), new,
(char *)iam_entry_shift(path, entries, count) - (char *)new);
dx_set_ikey(path, new, key);
dx_set_block(path, new, ptr);
dx_set_count(entries, count + 1);
memmove(iam_entry_shift(path, new, 1), new,
(char *)iam_entry_shift(path, entries, count) - (char *)new);
dx_set_ikey(path, new, key);
dx_set_block(path, new, ptr);
dx_set_count(entries, count + 1);
+
+ BUG_ON(count > dx_get_limit(entries));
assert_inv(dx_node_check(path, frame));
}
assert_inv(dx_node_check(path, frame));
}