summaryrefslogtreecommitdiff
path: root/drivers/md/dm-pcache/cache_dev.c
diff options
context:
space:
mode:
authorLinus Torvalds <torvalds@linux-foundation.org>2026-08-19 12:35:15 -0700
committerLinus Torvalds <torvalds@linux-foundation.org>2026-08-19 12:35:15 -0700
commit7fa7d4c6038bb4b394478ba1b31a6e8d89ed4f60 (patch)
treeecc0fbcf2d4190389535bf37058ba09d17b3dcdb /drivers/md/dm-pcache/cache_dev.c
parentfaabe2db712e8310dbe38fb81d33e5313ff0f059 (diff)
parent39c5aa3bd8ec3912d2cd0b3fe092642b0d2b0713 (diff)
downloadlinux-next-7fa7d4c6038bb4b394478ba1b31a6e8d89ed4f60.tar.gz
linux-next-7fa7d4c6038bb4b394478ba1b31a6e8d89ed4f60.zip
Merge tag 'for-7.3/dm-changes' of git://git.kernel.org/pub/scm/linux/kernel/git/device-mapper/linux-dm
Pull device mapper updates from Mikulas Patocka: - minor cleanups found by Claude Opus 4.6 - small cleanups in dm core, dm-cache, dm-switch, dm-inlinecrypt, dm-vdo - improve validation of metadata in dm-pcache - fix resume-vs-remove ioctl race condition - fix race condition when issuing table load ioctls concurrently - fix dm-raid1 and dm-io, so that they work with unaligned bio vectors - dm-integrity: use keyed markers as discard fillers - improve metadata validation in dm-array - fix dm-stats crash on memory allocation failure - fix dm-dust, so that it works if it is not the first target in a table - dm-era: fix superblock refcount leak on snapshot failure * tag 'for-7.3/dm-changes' of git://git.kernel.org/pub/scm/linux/kernel/git/device-mapper/linux-dm: (46 commits) dm-era: fix shadowed superblock leak on take-snap failure dm dust: make badblock messages target-relative dm-stats: fix a crash if allocation of per-cpu data fails dm array: reject an array block whose value size is not the caller's dm array: validate array block headers on read dm-integrity: replace forgeable discard filler with a keyed sector marker dm vdo indexer: embed geometry in parent structures dm vdo indexer: simplify sub-index parameter calculations dm-pcache: remove unused 'cache' parameter from cache_key_gc() docs: device-mapper: dm-inlinecrypt: fix 'bellow' spelling dm-pcache: remove unused miss_read_end_work_fn declaration dm-io: report non-retryable errors separatedly dm-io: clone the source bio instead of copying its biovec dm: fix race when loading and unloading a table dm: fix resume-vs-remove race dm-pcache: remove unused 'allocated' variable in cache_data_alloc() dm-pcache: replace tabs with spaces in comments to fix ASCII diagram alignment dm-pcache: fix use-after-free and invalid seg operations in kset_replay() dm-pcache: fix implicit u8 truncation of gc_percent in message handler dm raid1: reserve space for NUL-terminator in build_constructor_string() ...
Diffstat (limited to 'drivers/md/dm-pcache/cache_dev.c')
-rw-r--r--drivers/md/dm-pcache/cache_dev.c22
1 files changed, 21 insertions, 1 deletions
diff --git a/drivers/md/dm-pcache/cache_dev.c b/drivers/md/dm-pcache/cache_dev.c
index ece689e6ce59..f0259353ee39 100644
--- a/drivers/md/dm-pcache/cache_dev.c
+++ b/drivers/md/dm-pcache/cache_dev.c
@@ -242,6 +242,8 @@ int cache_dev_start(struct dm_pcache *pcache)
struct pcache_cache_dev *cache_dev = &pcache->cache_dev;
struct pcache_sb sb;
bool format = false;
+ u32 seg_num;
+ u64 max_segs;
int ret;
mutex_init(&cache_dev->seg_lock);
@@ -269,7 +271,25 @@ int cache_dev_start(struct dm_pcache *pcache)
goto dax_release;
cache_dev->sb_flags = le32_to_cpu(sb.flags);
- ret = cache_dev_init(cache_dev, le32_to_cpu(sb.seg_num));
+
+ /*
+ * seg_num is read from the crc32c-only superblock, so whoever supplies
+ * the cache device controls it. It is the ceiling every later on-media
+ * segment id is validated against, so bound it against what the device
+ * physically holds before it is trusted, or a forged seg_num lets a
+ * segment id address past the DAX mapping.
+ */
+ seg_num = le32_to_cpu(sb.seg_num);
+ max_segs = (bdev_nr_bytes(cache_dev->dm_dev->bdev) - PCACHE_SEGMENTS_OFF) /
+ PCACHE_SEG_SIZE;
+ if (seg_num == 0 || seg_num > max_segs || seg_num > PCACHE_CACHE_SEGS_MAX) {
+ pcache_dev_err(pcache, "invalid seg_num %u from cache device (device holds %llu, max %u)\n",
+ seg_num, max_segs, (u32)PCACHE_CACHE_SEGS_MAX);
+ ret = -EIO;
+ goto dax_release;
+ }
+
+ ret = cache_dev_init(cache_dev, seg_num);
if (ret)
goto dax_release;