diff options
author | Li Zefan <lizf@cn.fujitsu.com> | 2011-09-06 04:55:34 -0400 |
---|---|---|
committer | David Sterba <dsterba@suse.cz> | 2011-10-20 12:10:41 -0400 |
commit | a05a9bb18ae0abec0b513b5fde876c47905fa13e (patch) | |
tree | 80a74076bdbb86da8f02a209603526e5c0f524bb /fs/btrfs/ctree.c | |
parent | f4c697e6406da5dd445eda8d923c53e1138793dd (diff) |
Btrfs: fix array bound checking
Otherwise we can execced the array bound of path->slots[].
Signed-off-by: Li Zefan <lizf@cn.fujitsu.com>
Diffstat (limited to 'fs/btrfs/ctree.c')
-rw-r--r-- | fs/btrfs/ctree.c | 10 |
1 files changed, 6 insertions, 4 deletions
diff --git a/fs/btrfs/ctree.c b/fs/btrfs/ctree.c index 011cab3aca8d..0fe615e4ea38 100644 --- a/fs/btrfs/ctree.c +++ b/fs/btrfs/ctree.c | |||
@@ -902,9 +902,10 @@ static noinline int balance_level(struct btrfs_trans_handle *trans, | |||
902 | 902 | ||
903 | orig_ptr = btrfs_node_blockptr(mid, orig_slot); | 903 | orig_ptr = btrfs_node_blockptr(mid, orig_slot); |
904 | 904 | ||
905 | if (level < BTRFS_MAX_LEVEL - 1) | 905 | if (level < BTRFS_MAX_LEVEL - 1) { |
906 | parent = path->nodes[level + 1]; | 906 | parent = path->nodes[level + 1]; |
907 | pslot = path->slots[level + 1]; | 907 | pslot = path->slots[level + 1]; |
908 | } | ||
908 | 909 | ||
909 | /* | 910 | /* |
910 | * deal with the case where there is only one pointer in the root | 911 | * deal with the case where there is only one pointer in the root |
@@ -1107,9 +1108,10 @@ static noinline int push_nodes_for_insert(struct btrfs_trans_handle *trans, | |||
1107 | mid = path->nodes[level]; | 1108 | mid = path->nodes[level]; |
1108 | WARN_ON(btrfs_header_generation(mid) != trans->transid); | 1109 | WARN_ON(btrfs_header_generation(mid) != trans->transid); |
1109 | 1110 | ||
1110 | if (level < BTRFS_MAX_LEVEL - 1) | 1111 | if (level < BTRFS_MAX_LEVEL - 1) { |
1111 | parent = path->nodes[level + 1]; | 1112 | parent = path->nodes[level + 1]; |
1112 | pslot = path->slots[level + 1]; | 1113 | pslot = path->slots[level + 1]; |
1114 | } | ||
1113 | 1115 | ||
1114 | if (!parent) | 1116 | if (!parent) |
1115 | return 1; | 1117 | return 1; |