summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorZhao Zhang <zzhan461@ucr.edu>2026-06-19 15:40:03 +0800
committerIlya Dryomov <idryomov@gmail.com>2026-07-23 20:29:41 +0200
commitbbeae12fda3384a90fbebc8a19ba9d33f85b5361 (patch)
tree9bd83cc7093c19cf89618073d3df9daa14f4b652
parente4c804726c4afce3ba648b982d564f6af2cfa328 (diff)
downloadlinux-bbeae12fda3384a90fbebc8a19ba9d33f85b5361.tar.gz
linux-bbeae12fda3384a90fbebc8a19ba9d33f85b5361.tar.bz2
linux-bbeae12fda3384a90fbebc8a19ba9d33f85b5361.zip
libceph: guard missing CRUSH type name lookup
Localized read selection can walk a parent bucket whose name exists in the CRUSH map while its type has no matching entry in type_names. get_immediate_parent() then dereferences a NULL type_cn and passes an invalid pointer into strcmp(), causing a null-ptr-deref. Skip such malformed parent buckets unless both the bucket name and type name metadata are present. This keeps malformed hierarchy data from crashing locality lookup and safely falls back to "not local". [ idryomov: add WARN_ON_ONCE ] Cc: stable@vger.kernel.org Fixes: 117d96a04f00 ("libceph: support for balanced and localized reads") Reported-by: Yuan Tan <yuantan098@gmail.com> Reported-by: Zhengchuan Liang <zcliangcn@gmail.com> Reported-by: Xin Liu <bird@lzu.edu.cn> Assisted-by: Codex:GPT-5.4 Signed-off-by: Zhao Zhang <zzhan461@ucr.edu> Signed-off-by: Ren Wei <n05ec@lzu.edu.cn> Reviewed-by: Viacheslav Dubeyko <slava@dubeyko.com> Signed-off-by: Ilya Dryomov <idryomov@gmail.com>
-rw-r--r--net/ceph/osdmap.c5
1 files changed, 4 insertions, 1 deletions
diff --git a/net/ceph/osdmap.c b/net/ceph/osdmap.c
index 3c87f4b24e51..04036c047b8c 100644
--- a/net/ceph/osdmap.c
+++ b/net/ceph/osdmap.c
@@ -3060,8 +3060,11 @@ static int get_immediate_parent(struct crush_map *c, int id,
if (b->items[j] != id)
continue;
- *parent_type_id = b->type;
type_cn = lookup_crush_name(&c->type_names, b->type);
+ if (WARN_ON_ONCE(!type_cn))
+ continue;
+
+ *parent_type_id = b->type;
parent_loc->cl_type_name = type_cn->cn_name;
parent_loc->cl_name = cn->cn_name;
return b->id;