xfs: fix integer overflow in busy extent sort comparator

xfs_extent_busy_ag_cmp() subtracts two uint32_t values (group
numbers and block numbers) and returns the result as s32. When
the difference exceeds INT_MAX, the result overflows and the sort
order is corrupted.

Use cmp_int() instead, as was done in commit 362c490980 ("xfs:
fix integer overflow in bmap intent sort comparator").

Fixes: 4a137e0915 ("xfs: keep a reference to the pag for busy extents")
Signed-off-by: Yuto Ohnuki <ytohnuki@amazon.com>
Reviewed-by: Christoph Hellwig <hch@lst.de>
Reviewed-by: Carlos Maiolino <cmaiolino@redhat.com>
Signed-off-by: Carlos Maiolino <cem@kernel.org>
This commit is contained in:
Yuto Ohnuki
2026-04-07 13:08:27 +02:00
committed by Carlos Maiolino
parent 59e586d7dc
commit 553a13e207
+2 -2
View File
@@ -690,9 +690,9 @@ xfs_extent_busy_ag_cmp(
container_of(l2, struct xfs_extent_busy, list);
s32 diff;
diff = b1->group->xg_gno - b2->group->xg_gno;
diff = cmp_int(b1->group->xg_gno, b2->group->xg_gno);
if (!diff)
diff = b1->bno - b2->bno;
diff = cmp_int(b1->bno, b2->bno);
return diff;
}