| From ff030338f2187c52d4c9da481e63ad7c7db682e0 Mon Sep 17 00:00:00 2001 |
| From: Sasha Levin <sashal@kernel.org> |
| Date: Mon, 8 Oct 2018 14:28:52 -0700 |
| Subject: nvmet: avoid integer overflow in the discard code |
| |
| From: Bart Van Assche <bvanassche@acm.org> |
| |
| [ Upstream commit 8eacd1bd21d6913ec27e6120e9a8733352e191d3 ] |
| |
| Although I'm not sure whether it is a good idea to support large discard |
| commands, I think integer overflow for discard ranges larger than 4 GB |
| should be avoided. This patch avoids that smatch reports the following: |
| |
| drivers/nvme/target/io-cmd-file.c:249:1 nvmet_file_execute_discard() warn: should '((range.nlb)) << req->ns->blksize_shift' be a 64 bit type? |
| |
| Fixes: d5eff33ee6f8 ("nvmet: add simple file backed ns support") |
| Signed-off-by: Bart Van Assche <bvanassche@acm.org> |
| Reviewed-by: Chaitanya Kulkarni <chaitanya.kulkarni@wdc.com> |
| Signed-off-by: Christoph Hellwig <hch@lst.de> |
| Signed-off-by: Sasha Levin <sashal@kernel.org> |
| --- |
| drivers/nvme/target/io-cmd-file.c | 3 ++- |
| 1 file changed, 2 insertions(+), 1 deletion(-) |
| |
| diff --git a/drivers/nvme/target/io-cmd-file.c b/drivers/nvme/target/io-cmd-file.c |
| index 81a9dc5290a87..39d972e2595f0 100644 |
| --- a/drivers/nvme/target/io-cmd-file.c |
| +++ b/drivers/nvme/target/io-cmd-file.c |
| @@ -246,7 +246,8 @@ static void nvmet_file_execute_discard(struct nvmet_req *req) |
| break; |
| |
| offset = le64_to_cpu(range.slba) << req->ns->blksize_shift; |
| - len = le32_to_cpu(range.nlb) << req->ns->blksize_shift; |
| + len = le32_to_cpu(range.nlb); |
| + len <<= req->ns->blksize_shift; |
| if (offset + len > req->ns->size) { |
| ret = NVME_SC_LBA_RANGE | NVME_SC_DNR; |
| break; |
| -- |
| 2.20.1 |
| |