f2fs: fix overflow due to condition check order
authorJaegeuk Kim <jaegeuk@kernel.org>
Wed, 23 Nov 2016 18:51:17 +0000 (10:51 -0800)
committerGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Fri, 6 Jan 2017 09:40:14 +0000 (10:40 +0100)
commit e87f7329bbd6760c2acc4f1eb423362b08851a71 upstream.

In the last ilen case, i was already increased, resulting in accessing out-
of-boundary entry of do_replace and blkaddr.
Fix to check ilen first to exit the loop.

Fixes: 2aa8fbb9693020 ("f2fs: refactor __exchange_data_block for speed up")
Signed-off-by: Jaegeuk Kim <jaegeuk@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
fs/f2fs/file.c

index 4d6fbdb..801111e 100644 (file)
@@ -967,7 +967,7 @@ static int __clone_blkaddrs(struct inode *src_inode, struct inode *dst_inode,
                                new_size = (dst + i) << PAGE_SHIFT;
                                if (dst_inode->i_size < new_size)
                                        f2fs_i_size_write(dst_inode, new_size);
-                       } while ((do_replace[i] || blkaddr[i] == NULL_ADDR) && --ilen);
+                       } while (--ilen && (do_replace[i] || blkaddr[i] == NULL_ADDR));
 
                        f2fs_put_dnode(&dn);
                } else {