All of lore.kernel.org
 help / color / mirror / Atom feed
From: kernel test robot <lkp@intel.com>
To: kbuild@lists.01.org
Subject: Re: [PATCH v4 2/5] virtio-crypto: use private buffer for control request
Date: Tue, 26 Apr 2022 15:49:31 +0800	[thread overview]
Message-ID: <202204261507.YSlYncSr-lkp@intel.com> (raw)

[-- Attachment #1: Type: text/plain, Size: 39851 bytes --]

CC: llvm(a)lists.linux.dev
CC: kbuild-all(a)lists.01.org
BCC: lkp(a)intel.com
In-Reply-To: <20220424104140.44841-3-pizhenwei@bytedance.com>
References: <20220424104140.44841-3-pizhenwei@bytedance.com>
TO: zhenwei pi <pizhenwei@bytedance.com>
TO: arei.gonglei(a)huawei.com
TO: mst(a)redhat.com
TO: jasowang(a)redhat.com
CC: herbert(a)gondor.apana.org.au
CC: linux-kernel(a)vger.kernel.org
CC: virtualization(a)lists.linux-foundation.org
CC: linux-crypto(a)vger.kernel.org
CC: helei.sig11(a)bytedance.com
CC: davem(a)davemloft.net
CC: zhenwei pi <pizhenwei@bytedance.com>

Hi zhenwei,

Thank you for the patch! Perhaps something to improve:

[auto build test WARNING on herbert-cryptodev-2.6/master]
[also build test WARNING on linus/master v5.18-rc4 next-20220422]
[cannot apply to herbert-crypto-2.6/master linux/master]
[If your patch is applied to the wrong git tree, kindly drop us a note.
And when submitting patch, we suggest to use '--base' as documented in
https://git-scm.com/docs/git-format-patch]

url:    https://github.com/intel-lab-lkp/linux/commits/zhenwei-pi/virtio-crypto-Improve-performance/20220424-184732
base:   https://git.kernel.org/pub/scm/linux/kernel/git/herbert/cryptodev-2.6.git master
:::::: branch date: 2 days ago
:::::: commit date: 2 days ago
config: arm-randconfig-c002-20220424 (https://download.01.org/0day-ci/archive/20220426/202204261507.YSlYncSr-lkp(a)intel.com/config)
compiler: clang version 15.0.0 (https://github.com/llvm/llvm-project 1cddcfdc3c683b393df1a5c9063252eb60e52818)
reproduce (this is a W=1 build):
        wget https://raw.githubusercontent.com/intel/lkp-tests/master/sbin/make.cross -O ~/bin/make.cross
        chmod +x ~/bin/make.cross
        # install arm cross compiling tool for clang build
        # apt-get install binutils-arm-linux-gnueabi
        # https://github.com/intel-lab-lkp/linux/commit/286da9ed04239c7036f247b3781249d84a387e23
        git remote add linux-review https://github.com/intel-lab-lkp/linux
        git fetch --no-tags linux-review zhenwei-pi/virtio-crypto-Improve-performance/20220424-184732
        git checkout 286da9ed04239c7036f247b3781249d84a387e23
        # save the config file
        COMPILER_INSTALL_PATH=$HOME/0day COMPILER=clang make.cross ARCH=arm clang-analyzer 

If you fix the issue, kindly add following tag as appropriate
Reported-by: kernel test robot <lkp@intel.com>


clang-analyzer warnings: (new ones prefixed by >>)
           ^~~~~~~~~~~~~~~~~~~
   include/linux/fortify-string.h:47:29: note: expanded from macro '__underlying_memset'
   #define __underlying_memset     __builtin_memset
                                   ^~~~~~~~~~~~~~~~
   drivers/media/mc/mc-device.c:565:9: warning: Call to function 'sprintf' is insecure as it does not provide security checks introduced in the C11 standard. Replace with analogous functions that support length arguments or provides boundary checks such as 'sprintf_s' in case of C11 [clang-analyzer-security.insecureAPI.DeprecatedOrUnsafeBufferHandling]
           return sprintf(buf, "%.*s\n", (int)sizeof(mdev->model), mdev->model);
                  ^~~~~~~
   drivers/media/mc/mc-device.c:565:9: note: Call to function 'sprintf' is insecure as it does not provide security checks introduced in the C11 standard. Replace with analogous functions that support length arguments or provides boundary checks such as 'sprintf_s' in case of C11
           return sprintf(buf, "%.*s\n", (int)sizeof(mdev->model), mdev->model);
                  ^~~~~~~
   Suppressed 38 warnings (38 in non-user code).
   Use -header-filter=.* to display errors from all non-system headers. Use -system-headers to display errors from system headers as well.
   15 warnings generated.
   Suppressed 15 warnings (15 in non-user code).
   Use -header-filter=.* to display errors from all non-system headers. Use -system-headers to display errors from system headers as well.
   15 warnings generated.
   Suppressed 15 warnings (15 in non-user code).
   Use -header-filter=.* to display errors from all non-system headers. Use -system-headers to display errors from system headers as well.
   50 warnings generated.
   drivers/crypto/virtio/virtio_crypto_skcipher_algs.c:452:2: warning: Call to function 'memcpy' is insecure as it does not provide security checks introduced in the C11 standard. Replace with analogous functions that support length arguments or provides boundary checks such as 'memcpy_s' in case of C11 [clang-analyzer-security.insecureAPI.DeprecatedOrUnsafeBufferHandling]
           memcpy(iv, req->iv, ivsize);
           ^
   include/linux/fortify-string.h:369:26: note: expanded from macro 'memcpy'
   #define memcpy(p, q, s)  __fortify_memcpy_chk(p, q, s,                  \
                            ^~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
   include/linux/fortify-string.h:362:2: note: expanded from macro '__fortify_memcpy_chk'
           __underlying_##op(p, q, __fortify_size);                        \
           ^~~~~~~~~~~~~~~~~
   note: expanded from here
   include/linux/fortify-string.h:45:29: note: expanded from macro '__underlying_memcpy'
   #define __underlying_memcpy     __builtin_memcpy
                                   ^~~~~~~~~~~~~~~~
   drivers/crypto/virtio/virtio_crypto_skcipher_algs.c:452:2: note: Call to function 'memcpy' is insecure as it does not provide security checks introduced in the C11 standard. Replace with analogous functions that support length arguments or provides boundary checks such as 'memcpy_s' in case of C11
           memcpy(iv, req->iv, ivsize);
           ^
   include/linux/fortify-string.h:369:26: note: expanded from macro 'memcpy'
   #define memcpy(p, q, s)  __fortify_memcpy_chk(p, q, s,                  \
                            ^~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
   include/linux/fortify-string.h:362:2: note: expanded from macro '__fortify_memcpy_chk'
           __underlying_##op(p, q, __fortify_size);                        \
           ^~~~~~~~~~~~~~~~~
   note: expanded from here
   include/linux/fortify-string.h:45:29: note: expanded from macro '__underlying_memcpy'
   #define __underlying_memcpy     __builtin_memcpy
                                   ^~~~~~~~~~~~~~~~
   Suppressed 49 warnings (49 in non-user code).
   Use -header-filter=.* to display errors from all non-system headers. Use -system-headers to display errors from system headers as well.
   56 warnings generated.
   drivers/crypto/virtio/virtio_crypto_akcipher_algs.c:124:2: warning: Call to function 'memcpy' is insecure as it does not provide security checks introduced in the C11 standard. Replace with analogous functions that support length arguments or provides boundary checks such as 'memcpy_s' in case of C11 [clang-analyzer-security.insecureAPI.DeprecatedOrUnsafeBufferHandling]
           memcpy(&ctrl->header, header, sizeof(ctrl->header));
           ^
   include/linux/fortify-string.h:369:26: note: expanded from macro 'memcpy'
   #define memcpy(p, q, s)  __fortify_memcpy_chk(p, q, s,                  \
                            ^~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
   include/linux/fortify-string.h:362:2: note: expanded from macro '__fortify_memcpy_chk'
           __underlying_##op(p, q, __fortify_size);                        \
           ^~~~~~~~~~~~~~~~~
   note: expanded from here
   include/linux/fortify-string.h:45:29: note: expanded from macro '__underlying_memcpy'
   #define __underlying_memcpy     __builtin_memcpy
                                   ^~~~~~~~~~~~~~~~
   drivers/crypto/virtio/virtio_crypto_akcipher_algs.c:124:2: note: Call to function 'memcpy' is insecure as it does not provide security checks introduced in the C11 standard. Replace with analogous functions that support length arguments or provides boundary checks such as 'memcpy_s' in case of C11
           memcpy(&ctrl->header, header, sizeof(ctrl->header));
           ^
   include/linux/fortify-string.h:369:26: note: expanded from macro 'memcpy'
   #define memcpy(p, q, s)  __fortify_memcpy_chk(p, q, s,                  \
                            ^~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
   include/linux/fortify-string.h:362:2: note: expanded from macro '__fortify_memcpy_chk'
           __underlying_##op(p, q, __fortify_size);                        \
           ^~~~~~~~~~~~~~~~~
   note: expanded from here
   include/linux/fortify-string.h:45:29: note: expanded from macro '__underlying_memcpy'
   #define __underlying_memcpy     __builtin_memcpy
                                   ^~~~~~~~~~~~~~~~
   drivers/crypto/virtio/virtio_crypto_akcipher_algs.c:125:2: warning: Call to function 'memcpy' is insecure as it does not provide security checks introduced in the C11 standard. Replace with analogous functions that support length arguments or provides boundary checks such as 'memcpy_s' in case of C11 [clang-analyzer-security.insecureAPI.DeprecatedOrUnsafeBufferHandling]
           memcpy(&ctrl->u, para, sizeof(ctrl->u));
           ^
   include/linux/fortify-string.h:369:26: note: expanded from macro 'memcpy'
   #define memcpy(p, q, s)  __fortify_memcpy_chk(p, q, s,                  \
                            ^~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
   include/linux/fortify-string.h:362:2: note: expanded from macro '__fortify_memcpy_chk'
           __underlying_##op(p, q, __fortify_size);                        \
           ^~~~~~~~~~~~~~~~~
   note: expanded from here
   include/linux/fortify-string.h:45:29: note: expanded from macro '__underlying_memcpy'
   #define __underlying_memcpy     __builtin_memcpy
                                   ^~~~~~~~~~~~~~~~
   drivers/crypto/virtio/virtio_crypto_akcipher_algs.c:125:2: note: Call to function 'memcpy' is insecure as it does not provide security checks introduced in the C11 standard. Replace with analogous functions that support length arguments or provides boundary checks such as 'memcpy_s' in case of C11
           memcpy(&ctrl->u, para, sizeof(ctrl->u));
           ^
   include/linux/fortify-string.h:369:26: note: expanded from macro 'memcpy'
   #define memcpy(p, q, s)  __fortify_memcpy_chk(p, q, s,                  \
                            ^~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
   include/linux/fortify-string.h:362:2: note: expanded from macro '__fortify_memcpy_chk'
           __underlying_##op(p, q, __fortify_size);                        \
           ^~~~~~~~~~~~~~~~~
   note: expanded from here
   include/linux/fortify-string.h:45:29: note: expanded from macro '__underlying_memcpy'
   #define __underlying_memcpy     __builtin_memcpy
                                   ^~~~~~~~~~~~~~~~
>> drivers/crypto/virtio/virtio_crypto_akcipher_algs.c:166:4: warning: Access to field 'status' results in a dereference of an undefined pointer value (loaded from variable 'input') [clang-analyzer-core.NullDereference]
                           le32_to_cpu(input->status));
                           ^
   drivers/crypto/virtio/virtio_crypto_akcipher_algs.c:480:9: note: Calling 'virtio_crypto_rsa_set_key'
           return virtio_crypto_rsa_set_key(tfm, key, keylen, 0,
                  ^~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
   drivers/crypto/virtio/virtio_crypto_akcipher_algs.c:405:6: note: 'private' is false
           if (private) {
               ^~~~~~~
   drivers/crypto/virtio/virtio_crypto_akcipher_algs.c:405:2: note: Taking false branch
           if (private) {
           ^
   drivers/crypto/virtio/virtio_crypto_akcipher_algs.c:413:6: note: Assuming 'ret' is 0
           if (ret)
               ^~~
   drivers/crypto/virtio/virtio_crypto_akcipher_algs.c:413:2: note: Taking false branch
           if (ret)
           ^
   drivers/crypto/virtio/virtio_crypto_akcipher_algs.c:417:6: note: Assuming field 'n' is non-null
           if (!rsa_ctx->n)
               ^~~~~~~~~~~
   drivers/crypto/virtio/virtio_crypto_akcipher_algs.c:417:2: note: Taking false branch
           if (!rsa_ctx->n)
           ^
   drivers/crypto/virtio/virtio_crypto_akcipher_algs.c:420:6: note: Assuming field 'vcrypto' is non-null
           if (!ctx->vcrypto) {
               ^~~~~~~~~~~~~
   drivers/crypto/virtio/virtio_crypto_akcipher_algs.c:420:2: note: Taking false branch
           if (!ctx->vcrypto) {
           ^
   drivers/crypto/virtio/virtio_crypto_akcipher_algs.c:445:9: note: Calling 'virtio_crypto_alg_akcipher_init_session'
           return virtio_crypto_alg_akcipher_init_session(ctx, &header, &para, key, keylen);
                  ^~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
   drivers/crypto/virtio/virtio_crypto_akcipher_algs.c:110:2: note: 'input' declared without an initial value
           struct virtio_crypto_session_input *input;
           ^~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
   drivers/crypto/virtio/virtio_crypto_akcipher_algs.c:113:9: note: Calling 'kmemdup'
           pkey = kmemdup(key, keylen, GFP_ATOMIC);
                  ^~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
   include/linux/fortify-string.h:436:33: note: Left side of '&&' is false
           if (__builtin_constant_p(size) && p_size < size)
                                          ^
   include/linux/fortify-string.h:438:6: note: Assuming 'p_size' is >= 'size'
           if (p_size < size)
               ^~~~~~~~~~~~~
   include/linux/fortify-string.h:438:2: note: Taking false branch
           if (p_size < size)
           ^
   include/linux/fortify-string.h:440:2: note: Returning pointer, which participates in a condition later
           return __real_kmemdup(p, size, gfp);
           ^~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
   drivers/crypto/virtio/virtio_crypto_akcipher_algs.c:113:9: note: Returning from 'kmemdup'
           pkey = kmemdup(key, keylen, GFP_ATOMIC);
                  ^~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
   drivers/crypto/virtio/virtio_crypto_akcipher_algs.c:114:6: note: Assuming 'pkey' is non-null
           if (!pkey)
               ^~~~~
   drivers/crypto/virtio/virtio_crypto_akcipher_algs.c:114:2: note: Taking false branch
           if (!pkey)
           ^
   drivers/crypto/virtio/virtio_crypto_akcipher_algs.c:118:6: note: Assuming 'vc_ctrl_req' is null
           if (!vc_ctrl_req) {
               ^~~~~~~~~~~~
   drivers/crypto/virtio/virtio_crypto_akcipher_algs.c:118:2: note: Taking true branch
           if (!vc_ctrl_req) {
           ^
   drivers/crypto/virtio/virtio_crypto_akcipher_algs.c:120:3: note: Control jumps to line 161
                   goto out;
                   ^
   drivers/crypto/virtio/virtio_crypto_akcipher_algs.c:164:6: note: 'err' is < 0
           if (err < 0)
               ^~~
   drivers/crypto/virtio/virtio_crypto_akcipher_algs.c:164:2: note: Taking true branch
           if (err < 0)
           ^
   drivers/crypto/virtio/virtio_crypto_akcipher_algs.c:165:3: note: Loop condition is false.  Exiting loop
                   pr_err("virtio_crypto: Create session failed status: %u\n",
                   ^
   include/linux/printk.h:489:2: note: expanded from macro 'pr_err'
           printk(KERN_ERR pr_fmt(fmt), ##__VA_ARGS__)
           ^
   include/linux/printk.h:446:26: note: expanded from macro 'printk'
   #define printk(fmt, ...) printk_index_wrap(_printk, fmt, ##__VA_ARGS__)
                            ^
   include/linux/printk.h:417:3: note: expanded from macro 'printk_index_wrap'
                   __printk_index_emit(_fmt, NULL, NULL);                  \
                   ^
   include/linux/printk.h:392:34: note: expanded from macro '__printk_index_emit'
   #define __printk_index_emit(...) do {} while (0)
                                    ^
   drivers/crypto/virtio/virtio_crypto_akcipher_algs.c:166:4: note: Access to field 'status' results in a dereference of an undefined pointer value (loaded from variable 'input')
                           le32_to_cpu(input->status));
                           ^
   include/linux/printk.h:489:33: note: expanded from macro 'pr_err'
           printk(KERN_ERR pr_fmt(fmt), ##__VA_ARGS__)
                                          ^~~~~~~~~~~
   include/linux/printk.h:446:60: note: expanded from macro 'printk'
   #define printk(fmt, ...) printk_index_wrap(_printk, fmt, ##__VA_ARGS__)
                                                              ^~~~~~~~~~~
   include/linux/printk.h:418:19: note: expanded from macro 'printk_index_wrap'
                   _p_func(_fmt, ##__VA_ARGS__);                           \
                                   ^~~~~~~~~~~
   include/linux/byteorder/generic.h:89:21: note: expanded from macro 'le32_to_cpu'
   #define le32_to_cpu __le32_to_cpu
                       ^
   include/uapi/linux/byteorder/little_endian.h:35:50: note: expanded from macro '__le32_to_cpu'
   #define __le32_to_cpu(x) ((__force __u32)(__le32)(x))
                                                    ^~
>> drivers/crypto/virtio/virtio_crypto_akcipher_algs.c:166:4: warning: Use of memory after it is freed [clang-analyzer-unix.Malloc]
                           le32_to_cpu(input->status));
                           ^
   drivers/crypto/virtio/virtio_crypto_akcipher_algs.c:480:9: note: Calling 'virtio_crypto_rsa_set_key'
           return virtio_crypto_rsa_set_key(tfm, key, keylen, 0,
                  ^~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
   drivers/crypto/virtio/virtio_crypto_akcipher_algs.c:405:6: note: 'private' is false
           if (private) {
               ^~~~~~~
   drivers/crypto/virtio/virtio_crypto_akcipher_algs.c:405:2: note: Taking false branch
           if (private) {
           ^
   drivers/crypto/virtio/virtio_crypto_akcipher_algs.c:413:6: note: Assuming 'ret' is 0
           if (ret)
               ^~~
   drivers/crypto/virtio/virtio_crypto_akcipher_algs.c:413:2: note: Taking false branch
           if (ret)
           ^
   drivers/crypto/virtio/virtio_crypto_akcipher_algs.c:417:6: note: Assuming field 'n' is non-null
           if (!rsa_ctx->n)
               ^~~~~~~~~~~
   drivers/crypto/virtio/virtio_crypto_akcipher_algs.c:417:2: note: Taking false branch
           if (!rsa_ctx->n)
           ^
   drivers/crypto/virtio/virtio_crypto_akcipher_algs.c:420:6: note: Assuming field 'vcrypto' is non-null
           if (!ctx->vcrypto) {
               ^~~~~~~~~~~~~
   drivers/crypto/virtio/virtio_crypto_akcipher_algs.c:420:2: note: Taking false branch
           if (!ctx->vcrypto) {
           ^
   drivers/crypto/virtio/virtio_crypto_akcipher_algs.c:445:9: note: Calling 'virtio_crypto_alg_akcipher_init_session'
           return virtio_crypto_alg_akcipher_init_session(ctx, &header, &para, key, keylen);
                  ^~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
   drivers/crypto/virtio/virtio_crypto_akcipher_algs.c:114:6: note: Assuming 'pkey' is non-null
           if (!pkey)
               ^~~~~
   drivers/crypto/virtio/virtio_crypto_akcipher_algs.c:114:2: note: Taking false branch
           if (!pkey)
           ^
   drivers/crypto/virtio/virtio_crypto_akcipher_algs.c:118:6: note: Assuming 'vc_ctrl_req' is non-null
           if (!vc_ctrl_req) {
               ^~~~~~~~~~~~
   drivers/crypto/virtio/virtio_crypto_akcipher_algs.c:118:2: note: Taking false branch
           if (!vc_ctrl_req) {
           ^
   drivers/crypto/virtio/virtio_crypto_akcipher_algs.c:140:6: note: Assuming 'err' is < 0
           if (err < 0) {
               ^~~~~~~
   drivers/crypto/virtio/virtio_crypto_akcipher_algs.c:140:2: note: Taking true branch
           if (err < 0) {
           ^
   drivers/crypto/virtio/virtio_crypto_akcipher_algs.c:142:3: note: Control jumps to line 161
                   goto out;
                   ^
   drivers/crypto/virtio/virtio_crypto_akcipher_algs.c:161:2: note: Memory is released
           kfree(vc_ctrl_req);
           ^~~~~~~~~~~~~~~~~~
   drivers/crypto/virtio/virtio_crypto_akcipher_algs.c:164:6: note: 'err' is < 0
           if (err < 0)
               ^~~
   drivers/crypto/virtio/virtio_crypto_akcipher_algs.c:164:2: note: Taking true branch
           if (err < 0)
           ^
   drivers/crypto/virtio/virtio_crypto_akcipher_algs.c:165:3: note: Loop condition is false.  Exiting loop
                   pr_err("virtio_crypto: Create session failed status: %u\n",
                   ^
   include/linux/printk.h:489:2: note: expanded from macro 'pr_err'
           printk(KERN_ERR pr_fmt(fmt), ##__VA_ARGS__)
           ^
   include/linux/printk.h:446:26: note: expanded from macro 'printk'
   #define printk(fmt, ...) printk_index_wrap(_printk, fmt, ##__VA_ARGS__)
                            ^
   include/linux/printk.h:417:3: note: expanded from macro 'printk_index_wrap'
                   __printk_index_emit(_fmt, NULL, NULL);                  \
                   ^
   include/linux/printk.h:392:34: note: expanded from macro '__printk_index_emit'
   #define __printk_index_emit(...) do {} while (0)
                                    ^
   drivers/crypto/virtio/virtio_crypto_akcipher_algs.c:166:4: note: Use of memory after it is freed
                           le32_to_cpu(input->status));
                           ^
   include/linux/printk.h:489:33: note: expanded from macro 'pr_err'
           printk(KERN_ERR pr_fmt(fmt), ##__VA_ARGS__)
                                          ^~~~~~~~~~~
   include/linux/printk.h:446:60: note: expanded from macro 'printk'
   #define printk(fmt, ...) printk_index_wrap(_printk, fmt, ##__VA_ARGS__)
                                                              ^~~~~~~~~~~
   include/linux/printk.h:418:19: note: expanded from macro 'printk_index_wrap'
                   _p_func(_fmt, ##__VA_ARGS__);                           \
                                   ^~~~~~~~~~~
   include/linux/byteorder/generic.h:89:21: note: expanded from macro 'le32_to_cpu'
   #define le32_to_cpu __le32_to_cpu
                       ^
   include/uapi/linux/byteorder/little_endian.h:35:50: note: expanded from macro '__le32_to_cpu'
   #define __le32_to_cpu(x) ((__force __u32)(__le32)(x))
                                                    ^~~
   drivers/crypto/virtio/virtio_crypto_akcipher_algs.c:230:2: warning: 1st function call argument is an uninitialized value [clang-analyzer-core.CallAndMessage]
           kfree(vc_ctrl_req);
           ^
   drivers/crypto/virtio/virtio_crypto_akcipher_algs.c:510:2: note: Calling 'virtio_crypto_alg_akcipher_close_session'
           virtio_crypto_alg_akcipher_close_session(ctx);
           ^~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
   drivers/crypto/virtio/virtio_crypto_akcipher_algs.c:180:2: note: 'vc_ctrl_req' declared without an initial value
           struct virtio_crypto_ctrl_request *vc_ctrl_req;
           ^~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
   drivers/crypto/virtio/virtio_crypto_akcipher_algs.c:182:6: note: Assuming field 'session_valid' is false
           if (!ctx->session_valid) {
               ^~~~~~~~~~~~~~~~~~~
   drivers/crypto/virtio/virtio_crypto_akcipher_algs.c:182:2: note: Taking true branch
           if (!ctx->session_valid) {
           ^
   drivers/crypto/virtio/virtio_crypto_akcipher_algs.c:184:3: note: Control jumps to line 230
                   goto out;
                   ^
   drivers/crypto/virtio/virtio_crypto_akcipher_algs.c:230:2: note: 1st function call argument is an uninitialized value
           kfree(vc_ctrl_req);
           ^     ~~~~~~~~~~~
>> drivers/crypto/virtio/virtio_crypto_akcipher_algs.c:233:4: warning: Access to field 'status' results in a dereference of an undefined pointer value (loaded from variable 'ctrl_status') [clang-analyzer-core.NullDereference]
                           ctrl_status->status, destroy_session->session_id);
                           ^
   drivers/crypto/virtio/virtio_crypto_akcipher_algs.c:510:2: note: Calling 'virtio_crypto_alg_akcipher_close_session'
           virtio_crypto_alg_akcipher_close_session(ctx);
           ^~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
   drivers/crypto/virtio/virtio_crypto_akcipher_algs.c:179:2: note: 'ctrl_status' declared without an initial value
           struct virtio_crypto_inhdr *ctrl_status;
           ^~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
   drivers/crypto/virtio/virtio_crypto_akcipher_algs.c:182:6: note: Assuming field 'session_valid' is true
           if (!ctx->session_valid) {
               ^~~~~~~~~~~~~~~~~~~
   drivers/crypto/virtio/virtio_crypto_akcipher_algs.c:182:2: note: Taking false branch
           if (!ctx->session_valid) {
           ^
   drivers/crypto/virtio/virtio_crypto_akcipher_algs.c:188:6: note: Assuming 'vc_ctrl_req' is null
           if (!vc_ctrl_req) {
               ^~~~~~~~~~~~
   drivers/crypto/virtio/virtio_crypto_akcipher_algs.c:188:2: note: Taking true branch
           if (!vc_ctrl_req) {
           ^
   drivers/crypto/virtio/virtio_crypto_akcipher_algs.c:190:3: note: Control jumps to line 230
                   goto out;
                   ^
   drivers/crypto/virtio/virtio_crypto_akcipher_algs.c:231:6: note: 'err' is < 0
           if (err < 0) {
               ^~~
   drivers/crypto/virtio/virtio_crypto_akcipher_algs.c:231:2: note: Taking true branch
           if (err < 0) {
           ^
   drivers/crypto/virtio/virtio_crypto_akcipher_algs.c:232:3: note: Loop condition is false.  Exiting loop
                   pr_err("virtio_crypto: Close session failed status: %u, session_id: 0x%llx\n",
                   ^
   include/linux/printk.h:489:2: note: expanded from macro 'pr_err'
           printk(KERN_ERR pr_fmt(fmt), ##__VA_ARGS__)
           ^
   include/linux/printk.h:446:26: note: expanded from macro 'printk'
   #define printk(fmt, ...) printk_index_wrap(_printk, fmt, ##__VA_ARGS__)
                            ^
   include/linux/printk.h:417:3: note: expanded from macro 'printk_index_wrap'
                   __printk_index_emit(_fmt, NULL, NULL);                  \
                   ^
   include/linux/printk.h:392:34: note: expanded from macro '__printk_index_emit'
   #define __printk_index_emit(...) do {} while (0)
                                    ^
   drivers/crypto/virtio/virtio_crypto_akcipher_algs.c:233:4: note: Access to field 'status' results in a dereference of an undefined pointer value (loaded from variable 'ctrl_status')
                           ctrl_status->status, destroy_session->session_id);
                           ^
   include/linux/printk.h:489:33: note: expanded from macro 'pr_err'
           printk(KERN_ERR pr_fmt(fmt), ##__VA_ARGS__)
                                          ^~~~~~~~~~~
   include/linux/printk.h:446:60: note: expanded from macro 'printk'
   #define printk(fmt, ...) printk_index_wrap(_printk, fmt, ##__VA_ARGS__)
                                                              ^~~~~~~~~~~
   include/linux/printk.h:418:19: note: expanded from macro 'printk_index_wrap'
                   _p_func(_fmt, ##__VA_ARGS__);                           \
                                   ^~~~~~~~~~~
   drivers/crypto/virtio/virtio_crypto_akcipher_algs.c:233:4: warning: Use of memory after it is freed [clang-analyzer-unix.Malloc]
                           ctrl_status->status, destroy_session->session_id);
                           ^
   drivers/crypto/virtio/virtio_crypto_akcipher_algs.c:510:2: note: Calling 'virtio_crypto_alg_akcipher_close_session'
           virtio_crypto_alg_akcipher_close_session(ctx);
           ^~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
   drivers/crypto/virtio/virtio_crypto_akcipher_algs.c:182:6: note: Assuming field 'session_valid' is true
           if (!ctx->session_valid) {
               ^~~~~~~~~~~~~~~~~~~
   drivers/crypto/virtio/virtio_crypto_akcipher_algs.c:182:2: note: Taking false branch
           if (!ctx->session_valid) {
           ^
   drivers/crypto/virtio/virtio_crypto_akcipher_algs.c:188:6: note: Assuming 'vc_ctrl_req' is non-null
           if (!vc_ctrl_req) {
               ^~~~~~~~~~~~
   drivers/crypto/virtio/virtio_crypto_akcipher_algs.c:188:2: note: Taking false branch
           if (!vc_ctrl_req) {
           ^
   drivers/crypto/virtio/virtio_crypto_akcipher_algs.c:210:6: note: Assuming 'err' is < 0
           if (err < 0) {
               ^~~~~~~
   drivers/crypto/virtio/virtio_crypto_akcipher_algs.c:210:2: note: Taking true branch
           if (err < 0) {
           ^
   drivers/crypto/virtio/virtio_crypto_akcipher_algs.c:212:3: note: Control jumps to line 230
                   goto out;
                   ^
   drivers/crypto/virtio/virtio_crypto_akcipher_algs.c:230:2: note: Memory is released
           kfree(vc_ctrl_req);
           ^~~~~~~~~~~~~~~~~~
   drivers/crypto/virtio/virtio_crypto_akcipher_algs.c:231:6: note: 'err' is < 0
           if (err < 0) {
               ^~~
   drivers/crypto/virtio/virtio_crypto_akcipher_algs.c:231:2: note: Taking true branch
           if (err < 0) {
           ^
   drivers/crypto/virtio/virtio_crypto_akcipher_algs.c:232:3: note: Loop condition is false.  Exiting loop
                   pr_err("virtio_crypto: Close session failed status: %u, session_id: 0x%llx\n",
                   ^
   include/linux/printk.h:489:2: note: expanded from macro 'pr_err'
           printk(KERN_ERR pr_fmt(fmt), ##__VA_ARGS__)
           ^
   include/linux/printk.h:446:26: note: expanded from macro 'printk'
   #define printk(fmt, ...) printk_index_wrap(_printk, fmt, ##__VA_ARGS__)

vim +166 drivers/crypto/virtio/virtio_crypto_akcipher_algs.c

59ca6c93387d32 zhenwei pi 2022-03-02   98  
59ca6c93387d32 zhenwei pi 2022-03-02   99  static int virtio_crypto_alg_akcipher_init_session(struct virtio_crypto_akcipher_ctx *ctx,
59ca6c93387d32 zhenwei pi 2022-03-02  100  		struct virtio_crypto_ctrl_header *header, void *para,
59ca6c93387d32 zhenwei pi 2022-03-02  101  		const uint8_t *key, unsigned int keylen)
59ca6c93387d32 zhenwei pi 2022-03-02  102  {
59ca6c93387d32 zhenwei pi 2022-03-02  103  	struct scatterlist outhdr_sg, key_sg, inhdr_sg, *sgs[3];
59ca6c93387d32 zhenwei pi 2022-03-02  104  	struct virtio_crypto *vcrypto = ctx->vcrypto;
59ca6c93387d32 zhenwei pi 2022-03-02  105  	uint8_t *pkey;
59ca6c93387d32 zhenwei pi 2022-03-02  106  	unsigned int inlen;
59ca6c93387d32 zhenwei pi 2022-03-02  107  	int err;
59ca6c93387d32 zhenwei pi 2022-03-02  108  	unsigned int num_out = 0, num_in = 0;
bb26cab9a7c25d zhenwei pi 2022-04-24  109  	struct virtio_crypto_op_ctrl_req *ctrl;
bb26cab9a7c25d zhenwei pi 2022-04-24  110  	struct virtio_crypto_session_input *input;
286da9ed04239c zhenwei pi 2022-04-24  111  	struct virtio_crypto_ctrl_request *vc_ctrl_req;
59ca6c93387d32 zhenwei pi 2022-03-02  112  
59ca6c93387d32 zhenwei pi 2022-03-02  113  	pkey = kmemdup(key, keylen, GFP_ATOMIC);
59ca6c93387d32 zhenwei pi 2022-03-02  114  	if (!pkey)
59ca6c93387d32 zhenwei pi 2022-03-02  115  		return -ENOMEM;
59ca6c93387d32 zhenwei pi 2022-03-02  116  
286da9ed04239c zhenwei pi 2022-04-24  117  	vc_ctrl_req = kzalloc(sizeof(*vc_ctrl_req), GFP_KERNEL);
286da9ed04239c zhenwei pi 2022-04-24  118  	if (!vc_ctrl_req) {
286da9ed04239c zhenwei pi 2022-04-24  119  		err = -ENOMEM;
286da9ed04239c zhenwei pi 2022-04-24  120  		goto out;
286da9ed04239c zhenwei pi 2022-04-24  121  	}
286da9ed04239c zhenwei pi 2022-04-24  122  
286da9ed04239c zhenwei pi 2022-04-24  123  	ctrl = &vc_ctrl_req->ctrl;
bb26cab9a7c25d zhenwei pi 2022-04-24  124  	memcpy(&ctrl->header, header, sizeof(ctrl->header));
bb26cab9a7c25d zhenwei pi 2022-04-24  125  	memcpy(&ctrl->u, para, sizeof(ctrl->u));
286da9ed04239c zhenwei pi 2022-04-24  126  	input = &vc_ctrl_req->input;
bb26cab9a7c25d zhenwei pi 2022-04-24  127  	input->status = cpu_to_le32(VIRTIO_CRYPTO_ERR);
59ca6c93387d32 zhenwei pi 2022-03-02  128  
bb26cab9a7c25d zhenwei pi 2022-04-24  129  	sg_init_one(&outhdr_sg, ctrl, sizeof(*ctrl));
59ca6c93387d32 zhenwei pi 2022-03-02  130  	sgs[num_out++] = &outhdr_sg;
59ca6c93387d32 zhenwei pi 2022-03-02  131  
59ca6c93387d32 zhenwei pi 2022-03-02  132  	sg_init_one(&key_sg, pkey, keylen);
59ca6c93387d32 zhenwei pi 2022-03-02  133  	sgs[num_out++] = &key_sg;
59ca6c93387d32 zhenwei pi 2022-03-02  134  
bb26cab9a7c25d zhenwei pi 2022-04-24  135  	sg_init_one(&inhdr_sg, input, sizeof(*input));
59ca6c93387d32 zhenwei pi 2022-03-02  136  	sgs[num_out + num_in++] = &inhdr_sg;
59ca6c93387d32 zhenwei pi 2022-03-02  137  
286da9ed04239c zhenwei pi 2022-04-24  138  	spin_lock(&vcrypto->ctrl_lock);
59ca6c93387d32 zhenwei pi 2022-03-02  139  	err = virtqueue_add_sgs(vcrypto->ctrl_vq, sgs, num_out, num_in, vcrypto, GFP_ATOMIC);
286da9ed04239c zhenwei pi 2022-04-24  140  	if (err < 0) {
286da9ed04239c zhenwei pi 2022-04-24  141  		spin_unlock(&vcrypto->ctrl_lock);
59ca6c93387d32 zhenwei pi 2022-03-02  142  		goto out;
286da9ed04239c zhenwei pi 2022-04-24  143  	}
59ca6c93387d32 zhenwei pi 2022-03-02  144  
59ca6c93387d32 zhenwei pi 2022-03-02  145  	virtqueue_kick(vcrypto->ctrl_vq);
59ca6c93387d32 zhenwei pi 2022-03-02  146  	while (!virtqueue_get_buf(vcrypto->ctrl_vq, &inlen) &&
59ca6c93387d32 zhenwei pi 2022-03-02  147  	       !virtqueue_is_broken(vcrypto->ctrl_vq))
59ca6c93387d32 zhenwei pi 2022-03-02  148  		cpu_relax();
286da9ed04239c zhenwei pi 2022-04-24  149  	spin_unlock(&vcrypto->ctrl_lock);
59ca6c93387d32 zhenwei pi 2022-03-02  150  
bb26cab9a7c25d zhenwei pi 2022-04-24  151  	if (le32_to_cpu(input->status) != VIRTIO_CRYPTO_OK) {
59ca6c93387d32 zhenwei pi 2022-03-02  152  		err = -EINVAL;
59ca6c93387d32 zhenwei pi 2022-03-02  153  		goto out;
59ca6c93387d32 zhenwei pi 2022-03-02  154  	}
59ca6c93387d32 zhenwei pi 2022-03-02  155  
bb26cab9a7c25d zhenwei pi 2022-04-24  156  	ctx->session_id = le64_to_cpu(input->session_id);
59ca6c93387d32 zhenwei pi 2022-03-02  157  	ctx->session_valid = true;
59ca6c93387d32 zhenwei pi 2022-03-02  158  	err = 0;
59ca6c93387d32 zhenwei pi 2022-03-02  159  
59ca6c93387d32 zhenwei pi 2022-03-02  160  out:
286da9ed04239c zhenwei pi 2022-04-24  161  	kfree(vc_ctrl_req);
59ca6c93387d32 zhenwei pi 2022-03-02  162  	kfree_sensitive(pkey);
59ca6c93387d32 zhenwei pi 2022-03-02  163  
59ca6c93387d32 zhenwei pi 2022-03-02  164  	if (err < 0)
59ca6c93387d32 zhenwei pi 2022-03-02  165  		pr_err("virtio_crypto: Create session failed status: %u\n",
bb26cab9a7c25d zhenwei pi 2022-04-24 @166  			le32_to_cpu(input->status));
59ca6c93387d32 zhenwei pi 2022-03-02  167  
59ca6c93387d32 zhenwei pi 2022-03-02  168  	return err;
59ca6c93387d32 zhenwei pi 2022-03-02  169  }
59ca6c93387d32 zhenwei pi 2022-03-02  170  
59ca6c93387d32 zhenwei pi 2022-03-02  171  static int virtio_crypto_alg_akcipher_close_session(struct virtio_crypto_akcipher_ctx *ctx)
59ca6c93387d32 zhenwei pi 2022-03-02  172  {
59ca6c93387d32 zhenwei pi 2022-03-02  173  	struct scatterlist outhdr_sg, inhdr_sg, *sgs[2];
59ca6c93387d32 zhenwei pi 2022-03-02  174  	struct virtio_crypto_destroy_session_req *destroy_session;
59ca6c93387d32 zhenwei pi 2022-03-02  175  	struct virtio_crypto *vcrypto = ctx->vcrypto;
59ca6c93387d32 zhenwei pi 2022-03-02  176  	unsigned int num_out = 0, num_in = 0, inlen;
59ca6c93387d32 zhenwei pi 2022-03-02  177  	int err;
bb26cab9a7c25d zhenwei pi 2022-04-24  178  	struct virtio_crypto_op_ctrl_req *ctrl;
bb26cab9a7c25d zhenwei pi 2022-04-24  179  	struct virtio_crypto_inhdr *ctrl_status;
286da9ed04239c zhenwei pi 2022-04-24  180  	struct virtio_crypto_ctrl_request *vc_ctrl_req;
59ca6c93387d32 zhenwei pi 2022-03-02  181  
59ca6c93387d32 zhenwei pi 2022-03-02  182  	if (!ctx->session_valid) {
59ca6c93387d32 zhenwei pi 2022-03-02  183  		err = 0;
59ca6c93387d32 zhenwei pi 2022-03-02  184  		goto out;
59ca6c93387d32 zhenwei pi 2022-03-02  185  	}
286da9ed04239c zhenwei pi 2022-04-24  186  
286da9ed04239c zhenwei pi 2022-04-24  187  	vc_ctrl_req = kzalloc(sizeof(*vc_ctrl_req), GFP_KERNEL);
286da9ed04239c zhenwei pi 2022-04-24  188  	if (!vc_ctrl_req) {
286da9ed04239c zhenwei pi 2022-04-24  189  		err = -ENOMEM;
286da9ed04239c zhenwei pi 2022-04-24  190  		goto out;
286da9ed04239c zhenwei pi 2022-04-24  191  	}
286da9ed04239c zhenwei pi 2022-04-24  192  
286da9ed04239c zhenwei pi 2022-04-24  193  	ctrl_status = &vc_ctrl_req->ctrl_status;
bb26cab9a7c25d zhenwei pi 2022-04-24  194  	ctrl_status->status = VIRTIO_CRYPTO_ERR;
286da9ed04239c zhenwei pi 2022-04-24  195  	ctrl = &vc_ctrl_req->ctrl;
bb26cab9a7c25d zhenwei pi 2022-04-24  196  	ctrl->header.opcode = cpu_to_le32(VIRTIO_CRYPTO_AKCIPHER_DESTROY_SESSION);
bb26cab9a7c25d zhenwei pi 2022-04-24  197  	ctrl->header.queue_id = 0;
59ca6c93387d32 zhenwei pi 2022-03-02  198  
bb26cab9a7c25d zhenwei pi 2022-04-24  199  	destroy_session = &ctrl->u.destroy_session;
59ca6c93387d32 zhenwei pi 2022-03-02  200  	destroy_session->session_id = cpu_to_le64(ctx->session_id);
59ca6c93387d32 zhenwei pi 2022-03-02  201  
bb26cab9a7c25d zhenwei pi 2022-04-24  202  	sg_init_one(&outhdr_sg, ctrl, sizeof(*ctrl));
59ca6c93387d32 zhenwei pi 2022-03-02  203  	sgs[num_out++] = &outhdr_sg;
59ca6c93387d32 zhenwei pi 2022-03-02  204  
bb26cab9a7c25d zhenwei pi 2022-04-24  205  	sg_init_one(&inhdr_sg, &ctrl_status->status, sizeof(ctrl_status->status));
59ca6c93387d32 zhenwei pi 2022-03-02  206  	sgs[num_out + num_in++] = &inhdr_sg;
59ca6c93387d32 zhenwei pi 2022-03-02  207  
286da9ed04239c zhenwei pi 2022-04-24  208  	spin_lock(&vcrypto->ctrl_lock);
59ca6c93387d32 zhenwei pi 2022-03-02  209  	err = virtqueue_add_sgs(vcrypto->ctrl_vq, sgs, num_out, num_in, vcrypto, GFP_ATOMIC);
286da9ed04239c zhenwei pi 2022-04-24  210  	if (err < 0) {
286da9ed04239c zhenwei pi 2022-04-24  211  		spin_unlock(&vcrypto->ctrl_lock);
59ca6c93387d32 zhenwei pi 2022-03-02  212  		goto out;
286da9ed04239c zhenwei pi 2022-04-24  213  	}
59ca6c93387d32 zhenwei pi 2022-03-02  214  
59ca6c93387d32 zhenwei pi 2022-03-02  215  	virtqueue_kick(vcrypto->ctrl_vq);
59ca6c93387d32 zhenwei pi 2022-03-02  216  	while (!virtqueue_get_buf(vcrypto->ctrl_vq, &inlen) &&
59ca6c93387d32 zhenwei pi 2022-03-02  217  	       !virtqueue_is_broken(vcrypto->ctrl_vq))
59ca6c93387d32 zhenwei pi 2022-03-02  218  		cpu_relax();
286da9ed04239c zhenwei pi 2022-04-24  219  	spin_unlock(&vcrypto->ctrl_lock);
59ca6c93387d32 zhenwei pi 2022-03-02  220  
bb26cab9a7c25d zhenwei pi 2022-04-24  221  	if (ctrl_status->status != VIRTIO_CRYPTO_OK) {
59ca6c93387d32 zhenwei pi 2022-03-02  222  		err = -EINVAL;
59ca6c93387d32 zhenwei pi 2022-03-02  223  		goto out;
59ca6c93387d32 zhenwei pi 2022-03-02  224  	}
59ca6c93387d32 zhenwei pi 2022-03-02  225  
59ca6c93387d32 zhenwei pi 2022-03-02  226  	err = 0;
59ca6c93387d32 zhenwei pi 2022-03-02  227  	ctx->session_valid = false;
59ca6c93387d32 zhenwei pi 2022-03-02  228  
59ca6c93387d32 zhenwei pi 2022-03-02  229  out:
286da9ed04239c zhenwei pi 2022-04-24  230  	kfree(vc_ctrl_req);
59ca6c93387d32 zhenwei pi 2022-03-02  231  	if (err < 0) {
59ca6c93387d32 zhenwei pi 2022-03-02  232  		pr_err("virtio_crypto: Close session failed status: %u, session_id: 0x%llx\n",
bb26cab9a7c25d zhenwei pi 2022-04-24 @233  			ctrl_status->status, destroy_session->session_id);
59ca6c93387d32 zhenwei pi 2022-03-02  234  	}
59ca6c93387d32 zhenwei pi 2022-03-02  235  
59ca6c93387d32 zhenwei pi 2022-03-02  236  	return err;
59ca6c93387d32 zhenwei pi 2022-03-02  237  }
59ca6c93387d32 zhenwei pi 2022-03-02  238  

-- 
0-DAY CI Kernel Test Service
https://01.org/lkp

             reply	other threads:[~2022-04-26  7:49 UTC|newest]

Thread overview: 7+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2022-04-26  7:49 kernel test robot [this message]
  -- strict thread matches above, loose matches on Subject: below --
2022-04-24 15:51 [PATCH v4 2/5] virtio-crypto: use private buffer for control request kernel test robot
2022-04-25 13:27 ` Dan Carpenter
2022-04-25 13:27 ` Dan Carpenter
2022-04-25 13:27 ` Dan Carpenter
2022-04-24 10:41 [PATCH v4 0/5] virtio-crypto: Improve performance zhenwei pi
2022-04-24 10:41 ` [PATCH v4 2/5] virtio-crypto: use private buffer for control request zhenwei pi
2022-04-24 10:41   ` zhenwei pi

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=202204261507.YSlYncSr-lkp@intel.com \
    --to=lkp@intel.com \
    --cc=kbuild@lists.01.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.