md/raid1: avoid overflow in raid1 resync when bitmap is in use.
authorNeilBrown <neilb@suse.de>
Thu, 7 Oct 2010 00:54:46 +0000 (11:54 +1100)
committerNeilBrown <neilb@suse.de>
Thu, 7 Oct 2010 00:54:46 +0000 (11:54 +1100)
bitmap_start_sync returns - via a pass-by-reference variable - the
number of sectors before we need to check with the bitmap again.
Since commit ef4256733506f245 this number can be substantially larger,
2^27 is a common value.

Unfortunately it is an 'int' and so when raid1.c:sync_request shifts
it 9 places to the left it becomes 0.  This results in a zero-length
read which the scsi layer justifiably complains about.

This patch just removes the shift so the common case becomes safe with
a trivially-correct patch.

In the next merge window we will convert this 'int' to a 'sector_t'

Reported-by: "George Spelvin" <linux@horizon.com>
Signed-off-by: NeilBrown <neilb@suse.de>
drivers/md/raid1.c

index ad83a4dcadc3ed7cafa914d2e4dcb7ef1a939fdf..fba4d2feaeb4ae2f0bf56a4c097c653049915f14 100644 (file)
@@ -1912,7 +1912,7 @@ static sector_t sync_request(mddev_t *mddev, sector_t sector_nr, int *skipped, i
                            !test_bit(MD_RECOVERY_REQUESTED, &mddev->recovery))
                                break;
                        BUG_ON(sync_blocks < (PAGE_SIZE>>9));
-                       if (len > (sync_blocks<<9))
+                       if ((len >> 9) > sync_blocks)
                                len = sync_blocks<<9;
                }