Skip to content

Commit 684c9aa

Browse files
committed
vfs: fix O_DIRECT read past end of block device
The direct-IO write path already had the i_size checks in mm/filemap.c, but it turns out the read path did not, and removing the block size checks in fs/block_dev.c (commit bbec027: "blkdev_max_block: make private to fs/buffer.c") removed the magic "shrink IO to past the end of the device" code there. Fix it by truncating the IO to the size of the block device, like the write path already does. NOTE! I suspect the write path would be *much* better off doing it this way in fs/block_dev.c, rather than hidden deep in mm/filemap.c. The mm/filemap.c code is extremely hard to follow, and has various conditionals on the target being a block device (ie the flag passed in to 'generic_write_checks()', along with a conditional update of the inode timestamp etc). It is also quite possible that we should treat this whole block device size as a "s_maxbytes" issue, and try to make the logic even more generic. However, in the meantime this is the fairly minimal targeted fix. Noted by Milan Broz thanks to a regression test for the cryptsetup reencrypt tool. Reported-and-tested-by: Milan Broz <mbroz@redhat.com> Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
1 parent 1b3c393 commit 684c9aa

File tree

1 file changed

+17
-1
lines changed

1 file changed

+17
-1
lines changed

fs/block_dev.c

Lines changed: 17 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1544,6 +1544,22 @@ ssize_t blkdev_aio_write(struct kiocb *iocb, const struct iovec *iov,
15441544
}
15451545
EXPORT_SYMBOL_GPL(blkdev_aio_write);
15461546

1547+
static ssize_t blkdev_aio_read(struct kiocb *iocb, const struct iovec *iov,
1548+
unsigned long nr_segs, loff_t pos)
1549+
{
1550+
struct file *file = iocb->ki_filp;
1551+
struct inode *bd_inode = file->f_mapping->host;
1552+
loff_t size = i_size_read(bd_inode);
1553+
1554+
if (pos >= size)
1555+
return 0;
1556+
1557+
size -= pos;
1558+
if (size < INT_MAX)
1559+
nr_segs = iov_shorten((struct iovec *)iov, nr_segs, size);
1560+
return generic_file_aio_read(iocb, iov, nr_segs, pos);
1561+
}
1562+
15471563
/*
15481564
* Try to release a page associated with block device when the system
15491565
* is under memory pressure.
@@ -1574,7 +1590,7 @@ const struct file_operations def_blk_fops = {
15741590
.llseek = block_llseek,
15751591
.read = do_sync_read,
15761592
.write = do_sync_write,
1577-
.aio_read = generic_file_aio_read,
1593+
.aio_read = blkdev_aio_read,
15781594
.aio_write = blkdev_aio_write,
15791595
.mmap = generic_file_mmap,
15801596
.fsync = blkdev_fsync,

0 commit comments

Comments
 (0)