summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorHongling Zeng <zenghongling@kylinos.cn>2026-08-24 15:59:35 +0800
committerNamjae Jeon <linkinjeon@kernel.org>2026-08-27 21:50:45 +0900
commitacb1095fd2db884b417cb70808c886e4b615ff05 (patch)
tree9ca92f044a45976e1b62e8074fecfee8a71f8561
parent6faa235a649e78a82e3230b849607f446ba65ed5 (diff)
downloadlinux-acb1095fd2db884b417cb70808c886e4b615ff05.tar.gz
linux-acb1095fd2db884b417cb70808c886e4b615ff05.zip
ntfs: fix memmove overlap in ntfs_new_attr_flags
When the record shrinks while the payload offsets increase (e.g., enabling compression reduces padding, making arec_size < old_arec_size, but the header grows by 8 bytes), moving the name first can overwrite the old mapping_pairs before they are copied. Move mapping_pairs first in this case. Since mp_ofs is derived from name_ofs, they always change in the same direction. Checking name_ofs alone is sufficient. Fixes: fc053f05ca28 ("ntfs: add reparse and ea operations") Cc: stable@vger.kernel.org Signed-off-by: Hongling Zeng <zenghongling@kylinos.cn> Reviewed-by: Hyunchul Lee <hyc.lee@gmail.com> Signed-off-by: Namjae Jeon <linkinjeon@kernel.org>
-rw-r--r--fs/ntfs/ea.c33
1 files changed, 27 insertions, 6 deletions
diff --git a/fs/ntfs/ea.c b/fs/ntfs/ea.c
index 9f0222c172d9..0bc29bf1f050 100644
--- a/fs/ntfs/ea.c
+++ b/fs/ntfs/ea.c
@@ -753,15 +753,36 @@ static int ntfs_new_attr_flags(struct ntfs_inode *ni, __le32 fattr)
old_arec_size = le32_to_cpu(a->length);
/*
- * Move payloads before shrinking the record. Otherwise resizing moves
+ * Move payloads before shrinking the record. Otherwise resizing moves
* the following attribute over the old payload before it can be copied.
+ *
+ * When offsets increase, move mapping_pairs first to avoid name
+ * overwriting the start of mapping_pairs.
*/
if (arec_size < old_arec_size) {
- if (a->name_length && name_ofs != old_name_ofs)
- memmove((u8 *)a + name_ofs, (u8 *)a + old_name_ofs,
- a->name_length * sizeof(__le16));
- if (mp_ofs != old_mp_ofs)
- memmove((u8 *)a + mp_ofs, (u8 *)a + old_mp_ofs, mp_size);
+ if (name_ofs > old_name_ofs) {
+ /* Payload offsets increased: move mapping pairs first. */
+ if (mp_ofs != old_mp_ofs)
+ memmove((u8 *)a + mp_ofs,
+ (u8 *)a + old_mp_ofs,
+ mp_size);
+ if (a->name_length && name_ofs != old_name_ofs)
+ memmove((u8 *)a + name_ofs,
+ (u8 *)a + old_name_ofs,
+ a->name_length *
+ sizeof(__le16));
+ } else {
+ /* Payload offsets decreased or unchanged: move name first. */
+ if (a->name_length && name_ofs != old_name_ofs)
+ memmove((u8 *)a + name_ofs,
+ (u8 *)a + old_name_ofs,
+ a->name_length *
+ sizeof(__le16));
+ if (mp_ofs != old_mp_ofs)
+ memmove((u8 *)a + mp_ofs,
+ (u8 *)a + old_mp_ofs,
+ mp_size);
+ }
}
err = ntfs_attr_record_resize(ctx->mrec, a, arec_size);