btrfs: fix wrong max system array size check in kernel space
authorGui Hecheng <guihc.fnst@cn.fujitsu.com>
Mon, 21 Apr 2014 12:13:11 +0000 (20:13 +0800)
committerChris Mason <clm@fb.com>
Tue, 10 Jun 2014 00:20:36 +0000 (17:20 -0700)
For system chunk array,
We copy a "disk_key" and an chunk item each time,
so there should be enough space to hold both of them,
not only the chunk item.

Signed-off-by: Gui Hecheng <guihc.fnst@cn.fujitsu.com>
Signed-off-by: Chris Mason <clm@fb.com>
fs/btrfs/volumes.c

index ad8e342c4b7843b0260fa2e92677d703c61e4b9e..5864f05243c21cfa53079f5f2137d528093fc279 100644 (file)
@@ -3921,7 +3921,8 @@ static int btrfs_add_system_chunk(struct btrfs_root *root,
        u8 *ptr;
 
        array_size = btrfs_super_sys_array_size(super_copy);
-       if (array_size + item_size > BTRFS_SYSTEM_CHUNK_ARRAY_SIZE)
+       if (array_size + item_size + sizeof(disk_key)
+                       > BTRFS_SYSTEM_CHUNK_ARRAY_SIZE)
                return -EFBIG;
 
        ptr = super_copy->sys_chunk_array + array_size;