When tr->allocated_snapshot is true, resize_buffer_duplicate_size() is
called to update the snapshot buffer size. However, its return value was
not checked. In case of a failed resize this could lead next snapshot
being incomplete.

Add resize_buffer_duplicate_size() result check and return error if
resize fails.

Compile tested only.

Found by Linux Verification Center (linuxtesting.org) with SVACE.

Fixes: 180e4e390978 ("tracing: Add snapshot refcount")
Signed-off-by: Dmitry Kandybka <[email protected]>
---
 kernel/trace/trace_snapshot.c | 5 ++++-
 1 file changed, 4 insertions(+), 1 deletion(-)

diff --git a/kernel/trace/trace_snapshot.c b/kernel/trace/trace_snapshot.c
index 07b43c9863a2..4731ef7325a5 100644
--- a/kernel/trace/trace_snapshot.c
+++ b/kernel/trace/trace_snapshot.c
@@ -675,9 +675,12 @@ tracing_snapshot_write(struct file *filp, const char 
__user *ubuf, size_t cnt,
                if (iter->cpu_file != RING_BUFFER_ALL_CPUS)
                        return -EINVAL;
 #endif
-               if (tr->allocated_snapshot)
+               if (tr->allocated_snapshot) {
                        ret = resize_buffer_duplicate_size(&tr->snapshot_buffer,
                                        &tr->array_buffer, iter->cpu_file);
+                       if (ret < 0)
+                               return ret;
+               }
 
                ret = tracing_arm_snapshot_locked(tr);
                if (ret)
-- 
2.54.0


Reply via email to