Skip to content

Commit

Permalink
fs/ntfs3: Correct function is_rst_area_valid
Browse files Browse the repository at this point in the history
[ Upstream commit 1b7dd28 ]

Reported-by: Robert Morris <rtm@csail.mit.edu>
Signed-off-by: Konstantin Komarov <almaz.alexandrovich@paragon-software.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
  • Loading branch information
aalexandrovich authored and gregkh committed Mar 1, 2024
1 parent f4cf29c commit eac2e00
Showing 1 changed file with 8 additions and 6 deletions.
14 changes: 8 additions & 6 deletions fs/ntfs3/fslog.c
Original file line number Diff line number Diff line change
Expand Up @@ -465,7 +465,7 @@ static inline bool is_rst_area_valid(const struct RESTART_HDR *rhdr)
{
const struct RESTART_AREA *ra;
u16 cl, fl, ul;
u32 off, l_size, file_dat_bits, file_size_round;
u32 off, l_size, seq_bits;
u16 ro = le16_to_cpu(rhdr->ra_off);
u32 sys_page = le32_to_cpu(rhdr->sys_page_size);

Expand Down Expand Up @@ -511,13 +511,15 @@ static inline bool is_rst_area_valid(const struct RESTART_HDR *rhdr)
/* Make sure the sequence number bits match the log file size. */
l_size = le64_to_cpu(ra->l_size);

file_dat_bits = sizeof(u64) * 8 - le32_to_cpu(ra->seq_num_bits);
file_size_round = 1u << (file_dat_bits + 3);
if (file_size_round != l_size &&
(file_size_round < l_size || (file_size_round / 2) > l_size)) {
return false;
seq_bits = sizeof(u64) * 8 + 3;
while (l_size) {
l_size >>= 1;
seq_bits -= 1;
}

if (seq_bits != ra->seq_num_bits)
return false;

/* The log page data offset and record header length must be quad-aligned. */
if (!IS_ALIGNED(le16_to_cpu(ra->data_off), 8) ||
!IS_ALIGNED(le16_to_cpu(ra->rec_hdr_len), 8))
Expand Down

0 comments on commit eac2e00

Please sign in to comment.