| From c403c3a2fbe24d4ed33e10cabad048583ebd4edf Mon Sep 17 00:00:00 2001 |
| From: "Matthew Wilcox (Oracle)" <willy@infradead.org> |
| Date: Sun, 4 Oct 2020 19:04:24 +0100 |
| Subject: ceph: promote to unsigned long long before shifting |
| |
| From: Matthew Wilcox (Oracle) <willy@infradead.org> |
| |
| commit c403c3a2fbe24d4ed33e10cabad048583ebd4edf upstream. |
| |
| On 32-bit systems, this shift will overflow for files larger than 4GB. |
| |
| Cc: stable@vger.kernel.org |
| Fixes: 61f68816211e ("ceph: check caps in filemap_fault and page_mkwrite") |
| Signed-off-by: Matthew Wilcox (Oracle) <willy@infradead.org> |
| Reviewed-by: Jeff Layton <jlayton@kernel.org> |
| Signed-off-by: Ilya Dryomov <idryomov@gmail.com> |
| Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org> |
| |
| --- |
| fs/ceph/addr.c | 2 +- |
| 1 file changed, 1 insertion(+), 1 deletion(-) |
| |
| --- a/fs/ceph/addr.c |
| +++ b/fs/ceph/addr.c |
| @@ -1522,7 +1522,7 @@ static vm_fault_t ceph_filemap_fault(str |
| struct ceph_inode_info *ci = ceph_inode(inode); |
| struct ceph_file_info *fi = vma->vm_file->private_data; |
| struct page *pinned_page = NULL; |
| - loff_t off = vmf->pgoff << PAGE_SHIFT; |
| + loff_t off = (loff_t)vmf->pgoff << PAGE_SHIFT; |
| int want, got, err; |
| sigset_t oldset; |
| vm_fault_t ret = VM_FAULT_SIGBUS; |