diff options
author | Brian Foster <bfoster@redhat.com> | 2017-07-24 17:33:25 +0200 |
---|---|---|
committer | Darrick J. Wong <darrick.wong@oracle.com> | 2017-07-24 17:33:25 +0200 |
commit | cfaf2d034360166e569a4929dd83ae9698bed856 (patch) | |
tree | cc5ce3e05fd30ba3737fe59c03fc061876c08300 /fs/xfs/xfs_qm.c | |
parent | xfs: check _alloc_read_agf buffer pointer before using (diff) | |
download | linux-cfaf2d034360166e569a4929dd83ae9698bed856.tar.xz linux-cfaf2d034360166e569a4929dd83ae9698bed856.zip |
xfs: fix quotacheck dquot id overflow infinite loop
If a dquot has an id of U32_MAX, the next lookup index increment
overflows the uint32_t back to 0. This starts the lookup sequence
over from the beginning, repeats indefinitely and results in a
livelock.
Update xfs_qm_dquot_walk() to explicitly check for the lookup
overflow and exit the loop.
Signed-off-by: Brian Foster <bfoster@redhat.com>
Reviewed-by: Darrick J. Wong <darrick.wong@oracle.com>
Signed-off-by: Darrick J. Wong <darrick.wong@oracle.com>
Diffstat (limited to '')
-rw-r--r-- | fs/xfs/xfs_qm.c | 3 |
1 files changed, 3 insertions, 0 deletions
diff --git a/fs/xfs/xfs_qm.c b/fs/xfs/xfs_qm.c index 6ce948c436d5..15751dc2a27d 100644 --- a/fs/xfs/xfs_qm.c +++ b/fs/xfs/xfs_qm.c @@ -111,6 +111,9 @@ restart: skipped = 0; break; } + /* we're done if id overflows back to zero */ + if (!next_index) + break; } if (skipped) { |