From: Xin Li Date: Fri, 21 Oct 2011 23:39:53 +0000 (-0700) Subject: Illumos #1661: Fix flaw in sa_find_sizes() calculation X-Git-Tag: zfs-0.6.0-rc7~75 X-Git-Url: https://granicus.if.org/sourcecode?a=commitdiff_plain;h=c47516762758c989a443c0a6a9e38ae8fb46e6f1;p=zfs Illumos #1661: Fix flaw in sa_find_sizes() calculation When calculating space needed for SA_BONUS buffers, hdrsize is always rounded up to next 8-aligned boundary. However, in two places the round up was done against sum of 'total' plus hdrsize. On the other hand, hdrsize increments by 4 each time, which means in certain conditions, we would end up returning with will_spill == 0 and (total + hdrsize) larger than full_space, leading to a failed assertion because it's invalid for dmu_set_bonus. Reviewed by: Matthew Ahrens Reviewed by: Dan McDonald Approved by: Gordon Ross References to Illumos issue: https://www.illumos.org/issues/1661 Signed-off-by: Brian Behlendorf Closes #426 --- diff --git a/module/zfs/sa.c b/module/zfs/sa.c index 8acbb0cbb..4278ed7e4 100644 --- a/module/zfs/sa.c +++ b/module/zfs/sa.c @@ -607,14 +607,14 @@ sa_find_sizes(sa_os_t *sa, sa_bulk_attr_t *attr_desc, int attr_count, * and spill buffer. */ if (buftype == SA_BONUS && *index == -1 && - P2ROUNDUP(*total + hdrsize, 8) > + (*total + P2ROUNDUP(hdrsize, 8)) > (full_space - sizeof (blkptr_t))) { *index = i; done = B_TRUE; } next: - if (P2ROUNDUP(*total + hdrsize, 8) > full_space && + if ((*total + P2ROUNDUP(hdrsize, 8)) > full_space && buftype == SA_BONUS) *will_spill = B_TRUE; }