Skip to content

Commit 40a7487

Browse files
tititiou36hubcapsc
authored andcommitted
orangefs: Fix the size of a memory allocation in orangefs_bufmap_alloc()
'buffer_index_array' really looks like a bitmap. So it should be allocated as such. When kzalloc is called, a number of bytes is expected, but a number of longs is passed instead. In get(), if not enough memory is allocated, un-allocated memory may be read or written. So use bitmap_zalloc() to safely allocate the correct memory size and avoid un-expected behavior. While at it, change the corresponding kfree() into bitmap_free() to keep the semantic. Fixes: ea2c9c9 ("orangefs: bufmap rewrite") Signed-off-by: Christophe JAILLET <christophe.jaillet@wanadoo.fr> Signed-off-by: Mike Marshall <hubcap@omnibond.com>
1 parent 063e458 commit 40a7487

File tree

1 file changed

+3
-4
lines changed

1 file changed

+3
-4
lines changed

fs/orangefs/orangefs-bufmap.c

Lines changed: 3 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -176,7 +176,7 @@ orangefs_bufmap_free(struct orangefs_bufmap *bufmap)
176176
{
177177
kfree(bufmap->page_array);
178178
kfree(bufmap->desc_array);
179-
kfree(bufmap->buffer_index_array);
179+
bitmap_free(bufmap->buffer_index_array);
180180
kfree(bufmap);
181181
}
182182

@@ -226,8 +226,7 @@ orangefs_bufmap_alloc(struct ORANGEFS_dev_map_desc *user_desc)
226226
bufmap->desc_size = user_desc->size;
227227
bufmap->desc_shift = ilog2(bufmap->desc_size);
228228

229-
bufmap->buffer_index_array =
230-
kzalloc(DIV_ROUND_UP(bufmap->desc_count, BITS_PER_LONG), GFP_KERNEL);
229+
bufmap->buffer_index_array = bitmap_zalloc(bufmap->desc_count, GFP_KERNEL);
231230
if (!bufmap->buffer_index_array)
232231
goto out_free_bufmap;
233232

@@ -250,7 +249,7 @@ orangefs_bufmap_alloc(struct ORANGEFS_dev_map_desc *user_desc)
250249
out_free_desc_array:
251250
kfree(bufmap->desc_array);
252251
out_free_index_array:
253-
kfree(bufmap->buffer_index_array);
252+
bitmap_free(bufmap->buffer_index_array);
254253
out_free_bufmap:
255254
kfree(bufmap);
256255
out:

0 commit comments

Comments
 (0)