From owner-svn-src-head@freebsd.org Mon Jun 11 19:32:37 2018 Return-Path: Delivered-To: svn-src-head@mailman.ysv.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mailman.ysv.freebsd.org (Postfix) with ESMTP id 5FCB8100D9DB; Mon, 11 Jun 2018 19:32:37 +0000 (UTC) (envelope-from imp@FreeBSD.org) Received: from mxrelay.nyi.freebsd.org (mxrelay.nyi.freebsd.org [IPv6:2610:1c1:1:606c::19:3]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (Client CN "mxrelay.nyi.freebsd.org", Issuer "Let's Encrypt Authority X3" (verified OK)) by mx1.freebsd.org (Postfix) with ESMTPS id CF5A878AAF; Mon, 11 Jun 2018 19:32:36 +0000 (UTC) (envelope-from imp@FreeBSD.org) Received: from repo.freebsd.org (repo.freebsd.org [IPv6:2610:1c1:1:6068::e6a:0]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (Client did not present a certificate) by mxrelay.nyi.freebsd.org (Postfix) with ESMTPS id B1CA81FCEE; Mon, 11 Jun 2018 19:32:36 +0000 (UTC) (envelope-from imp@FreeBSD.org) Received: from repo.freebsd.org ([127.0.1.37]) by repo.freebsd.org (8.15.2/8.15.2) with ESMTP id w5BJWaHO045927; Mon, 11 Jun 2018 19:32:36 GMT (envelope-from imp@FreeBSD.org) Received: (from imp@localhost) by repo.freebsd.org (8.15.2/8.15.2/Submit) id w5BJWaL4045925; Mon, 11 Jun 2018 19:32:36 GMT (envelope-from imp@FreeBSD.org) Message-Id: <201806111932.w5BJWaL4045925@repo.freebsd.org> X-Authentication-Warning: repo.freebsd.org: imp set sender to imp@FreeBSD.org using -f From: Warner Losh Date: Mon, 11 Jun 2018 19:32:36 +0000 (UTC) To: src-committers@freebsd.org, svn-src-all@freebsd.org, svn-src-head@freebsd.org Subject: svn commit: r334969 - head/sbin/dump X-SVN-Group: head X-SVN-Commit-Author: imp X-SVN-Commit-Paths: head/sbin/dump X-SVN-Commit-Revision: 334969 X-SVN-Commit-Repository: base MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit X-BeenThere: svn-src-head@freebsd.org X-Mailman-Version: 2.1.26 Precedence: list List-Id: SVN commit messages for the src tree for head/-current List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Mon, 11 Jun 2018 19:32:37 -0000 Author: imp Date: Mon Jun 11 19:32:36 2018 New Revision: 334969 URL: https://svnweb.freebsd.org/changeset/base/334969 Log: Add asserts to prevent overflows of c_addr. Add some asserts that prevents the overflows of c_addr. This can't happen, absent bugs. However, certain large filesystems can cause problems. These have been prevented by r334968, but a solution is needed. These asserts will help assure that solution is correct. PR: 228807 Reviewed by: db Modified: head/sbin/dump/tape.c head/sbin/dump/traverse.c Modified: head/sbin/dump/tape.c ============================================================================== --- head/sbin/dump/tape.c Mon Jun 11 19:12:50 2018 (r334968) +++ head/sbin/dump/tape.c Mon Jun 11 19:32:36 2018 (r334969) @@ -47,6 +47,7 @@ static const char rcsid[] = #include +#include #include #include #include @@ -279,6 +280,7 @@ flushtape(void) blks = 0; if (spcl.c_type != TS_END) { + assert(spcl.c_count <= TP_NINDIR); for (i = 0; i < spcl.c_count; i++) if (spcl.c_addr[i] != 0) blks++; Modified: head/sbin/dump/traverse.c ============================================================================== --- head/sbin/dump/traverse.c Mon Jun 11 19:12:50 2018 (r334968) +++ head/sbin/dump/traverse.c Mon Jun 11 19:32:36 2018 (r334969) @@ -46,6 +46,7 @@ static const char rcsid[] = #include +#include #include #include #include @@ -637,6 +638,7 @@ ufs1_blksout(ufs1_daddr_t *blkp, int frags, ino_t ino) count = blks; else count = i + TP_NINDIR; + assert(count <= TP_NINDIR + i); for (j = i; j < count; j++) if (blkp[j / tbperdb] != 0) spcl.c_addr[j - i] = 1; @@ -689,6 +691,7 @@ ufs2_blksout(union dinode *dp, ufs2_daddr_t *blkp, int count = blks; else count = i + TP_NINDIR; + assert(count <= TP_NINDIR + i); for (j = i; j < count; j++) if (blkp[j / tbperdb] != 0) spcl.c_addr[j - i] = 1; @@ -753,6 +756,7 @@ appendextdata(union dinode *dp) * data by the writeextdata() routine. */ tbperdb = sblock->fs_bsize >> tp_bshift; + assert(spcl.c_count + blks < TP_NINDIR); for (i = 0; i < blks; i++) if (&dp->dp2.di_extb[i / tbperdb] != 0) spcl.c_addr[spcl.c_count + i] = 1;