提交 48706d0a 编写于 作者: M Miklos Szeredi

fuse: fix fuse_retrieve

Fix two bugs in fuse_retrieve():

 - retrieving more than one page would yield repeated instances of the
   first page

 - if more than FUSE_MAX_PAGES_PER_REQ pages were requested than the
   request page array would overflow

fuse_retrieve() was added in 2.6.36 and these bugs had been there since the
beginning.
Signed-off-by: NMiklos Szeredi <mszeredi@suse.cz>
CC: stable@vger.kernel.org
上级 dc47ce90
...@@ -1512,7 +1512,7 @@ static int fuse_retrieve(struct fuse_conn *fc, struct inode *inode, ...@@ -1512,7 +1512,7 @@ static int fuse_retrieve(struct fuse_conn *fc, struct inode *inode,
else if (outarg->offset + num > file_size) else if (outarg->offset + num > file_size)
num = file_size - outarg->offset; num = file_size - outarg->offset;
while (num) { while (num && req->num_pages < FUSE_MAX_PAGES_PER_REQ) {
struct page *page; struct page *page;
unsigned int this_num; unsigned int this_num;
...@@ -1526,6 +1526,7 @@ static int fuse_retrieve(struct fuse_conn *fc, struct inode *inode, ...@@ -1526,6 +1526,7 @@ static int fuse_retrieve(struct fuse_conn *fc, struct inode *inode,
num -= this_num; num -= this_num;
total_len += this_num; total_len += this_num;
index++;
} }
req->misc.retrieve_in.offset = outarg->offset; req->misc.retrieve_in.offset = outarg->offset;
req->misc.retrieve_in.size = total_len; req->misc.retrieve_in.size = total_len;
......
Markdown is supported
0% .
You are about to add 0 people to the discussion. Proceed with caution.
先完成此消息的编辑!
想要评论请 注册