bcache: fix input overflow to journal_delay_ms
authorColy Li <colyli@suse.de>
Sat, 9 Feb 2019 04:53:08 +0000 (12:53 +0800)
committerJens Axboe <axboe@kernel.dk>
Sat, 9 Feb 2019 14:18:32 +0000 (07:18 -0700)
c->journal_delay_ms is in type unsigned short, it is set via sysfs
interface and converted by sysfs_strtoul() from input string to
unsigned short value. Therefore overflow to unsigned short might be
happen when the converted value exceed USHRT_MAX. e.g. writing
65536 into sysfs file journal_delay_ms, c->journal_delay_ms is set to
0.

This patch uses sysfs_strtoul_clamp() to convert the input string and
limit value range in [0, USHRT_MAX], to avoid the input overflow.

Signed-off-by: Coly Li <colyli@suse.de>
Signed-off-by: Jens Axboe <axboe@kernel.dk>
drivers/md/bcache/sysfs.c

index d292eb757ac49b5b8d9f55a7dbb9af48c6737b03..201e85bbe3ebe1d92401864b6622251bdd32f415 100644 (file)
@@ -821,7 +821,9 @@ STORE(__bch_cache_set)
                }
        }
 
-       sysfs_strtoul(journal_delay_ms,         c->journal_delay_ms);
+       sysfs_strtoul_clamp(journal_delay_ms,
+                           c->journal_delay_ms,
+                           0, USHRT_MAX);
        sysfs_strtoul_bool(verify,              c->verify);
        sysfs_strtoul_bool(key_merging_disabled, c->key_merging_disabled);
        sysfs_strtoul(expensive_debug_checks,   c->expensive_debug_checks);