btrfs: Check if item pointer overlaps with the item itself
authorQu Wenruo <quwenruo.btrfs@gmx.com>
Wed, 23 Aug 2017 07:57:57 +0000 (16:57 +0900)
committerDavid Sterba <dsterba@suse.com>
Mon, 30 Oct 2017 11:27:58 +0000 (12:27 +0100)
Function check_leaf() checks if any item pointer points outside of the
leaf, but it doesn't check if the pointer overlaps with the item itself.

Normally only the last item may be the victim, but adding such check is
never a bad idea anyway.

Signed-off-by: Qu Wenruo <quwenruo.btrfs@gmx.com>
Reviewed-by: Nikolay Borisov <nborisov@suse.com>
Reviewed-by: David Sterba <dsterba@suse.com>
Signed-off-by: David Sterba <dsterba@suse.com>
fs/btrfs/disk-io.c

index 6c97ae1e7288e7349833eb16fce3901b2f8c367a..d1770b3e0385e6b090bae2dfd65fd956917a384b 100644 (file)
@@ -643,6 +643,13 @@ static noinline int check_leaf(struct btrfs_root *root,
                        return -EUCLEAN;
                }
 
+               /* Also check if the item pointer overlaps with btrfs item. */
+               if (btrfs_item_nr_offset(slot) + sizeof(struct btrfs_item) >
+                   btrfs_item_ptr_offset(leaf, slot)) {
+                       CORRUPT("slot overlap with its data", leaf, root, slot);
+                       return -EUCLEAN;
+               }
+
                prev_key.objectid = key.objectid;
                prev_key.type = key.type;
                prev_key.offset = key.offset;