From: kernel test robot <lkp@intel.com>
To: oe-kbuild@lists.linux.dev
Cc: lkp@intel.com, Dan Carpenter <error27@gmail.com>
Subject: [android-common:android16-6.12-kminext 4/4] fs/jfs/jfs_dtree.c:3090 dtReadFirst() warn: impossible condition '(stbl[0] > 127) => (0-127 > 127)'
Date: Sat, 08 Aug 2026 16:36:28 +0800 [thread overview]
Message-ID: <202608081637.KNSd6oSL-lkp@intel.com> (raw)
BCC: lkp@intel.com
CC: oe-kbuild-all@lists.linux.dev
TO: cros-kernel-buildreports@googlegroups.com
tree: https://android.googlesource.com/kernel/common android16-6.12-kminext
head: 3709fda36866cd4468d65d7e3988ea70bf52fbde
commit: 22dcbf7661c6ffc3247978c254dc40b833a0d429 [4/4] jfs: array-index-out-of-bounds fix in dtReadFirst
:::::: branch date: 2 days ago
:::::: commit date: 1 year, 8 months ago
config: x86_64-randconfig-161-20260808 (https://download.01.org/0day-ci/archive/20260808/202608081637.KNSd6oSL-lkp@intel.com/config)
compiler: gcc-14 (Debian 14.2.0-19) 14.2.0
smatch: v0.5.0-9187-g5189e3fb
If you fix the issue in a separate patch/commit (i.e. not just a new version of
the same patch/commit), kindly add following tags
| Reported-by: kernel test robot <lkp@intel.com>
| Reported-by: Dan Carpenter <error27@gmail.com>
| Closes: https://lore.kernel.org/r/202608081637.KNSd6oSL-lkp@intel.com/
smatch warnings:
fs/jfs/jfs_dtree.c:3090 dtReadFirst() warn: impossible condition '(stbl[0] > 127) => (0-127 > 127)'
vim +3090 fs/jfs/jfs_dtree.c
^1da177e4c3f415 Linus Torvalds 2005-04-16 3032
^1da177e4c3f415 Linus Torvalds 2005-04-16 3033
^1da177e4c3f415 Linus Torvalds 2005-04-16 3034 /*
^1da177e4c3f415 Linus Torvalds 2005-04-16 3035 * dtReadFirst()
^1da177e4c3f415 Linus Torvalds 2005-04-16 3036 *
^1da177e4c3f415 Linus Torvalds 2005-04-16 3037 * function: get the leftmost page of the directory
^1da177e4c3f415 Linus Torvalds 2005-04-16 3038 */
^1da177e4c3f415 Linus Torvalds 2005-04-16 3039 static int dtReadFirst(struct inode *ip, struct btstack * btstack)
^1da177e4c3f415 Linus Torvalds 2005-04-16 3040 {
^1da177e4c3f415 Linus Torvalds 2005-04-16 3041 int rc = 0;
^1da177e4c3f415 Linus Torvalds 2005-04-16 3042 s64 bn;
^1da177e4c3f415 Linus Torvalds 2005-04-16 3043 int psize = 288; /* initial in-line directory */
^1da177e4c3f415 Linus Torvalds 2005-04-16 3044 struct metapage *mp;
^1da177e4c3f415 Linus Torvalds 2005-04-16 3045 dtpage_t *p;
^1da177e4c3f415 Linus Torvalds 2005-04-16 3046 s8 *stbl;
^1da177e4c3f415 Linus Torvalds 2005-04-16 3047 struct btframe *btsp;
^1da177e4c3f415 Linus Torvalds 2005-04-16 3048 pxd_t *xd;
^1da177e4c3f415 Linus Torvalds 2005-04-16 3049
^1da177e4c3f415 Linus Torvalds 2005-04-16 3050 BT_CLR(btstack); /* reset stack */
^1da177e4c3f415 Linus Torvalds 2005-04-16 3051
^1da177e4c3f415 Linus Torvalds 2005-04-16 3052 /*
^1da177e4c3f415 Linus Torvalds 2005-04-16 3053 * descend leftmost path of the tree
^1da177e4c3f415 Linus Torvalds 2005-04-16 3054 *
^1da177e4c3f415 Linus Torvalds 2005-04-16 3055 * by convention, root bn = 0.
^1da177e4c3f415 Linus Torvalds 2005-04-16 3056 */
^1da177e4c3f415 Linus Torvalds 2005-04-16 3057 for (bn = 0;;) {
^1da177e4c3f415 Linus Torvalds 2005-04-16 3058 DT_GETPAGE(ip, bn, mp, psize, p, rc);
^1da177e4c3f415 Linus Torvalds 2005-04-16 3059 if (rc)
^1da177e4c3f415 Linus Torvalds 2005-04-16 3060 return rc;
^1da177e4c3f415 Linus Torvalds 2005-04-16 3061
^1da177e4c3f415 Linus Torvalds 2005-04-16 3062 /*
^1da177e4c3f415 Linus Torvalds 2005-04-16 3063 * leftmost leaf page
^1da177e4c3f415 Linus Torvalds 2005-04-16 3064 */
^1da177e4c3f415 Linus Torvalds 2005-04-16 3065 if (p->header.flag & BT_LEAF) {
^1da177e4c3f415 Linus Torvalds 2005-04-16 3066 /* return leftmost entry */
^1da177e4c3f415 Linus Torvalds 2005-04-16 3067 btsp = btstack->top;
^1da177e4c3f415 Linus Torvalds 2005-04-16 3068 btsp->bn = bn;
^1da177e4c3f415 Linus Torvalds 2005-04-16 3069 btsp->index = 0;
^1da177e4c3f415 Linus Torvalds 2005-04-16 3070 btsp->mp = mp;
^1da177e4c3f415 Linus Torvalds 2005-04-16 3071
^1da177e4c3f415 Linus Torvalds 2005-04-16 3072 return 0;
^1da177e4c3f415 Linus Torvalds 2005-04-16 3073 }
^1da177e4c3f415 Linus Torvalds 2005-04-16 3074
^1da177e4c3f415 Linus Torvalds 2005-04-16 3075 /*
^1da177e4c3f415 Linus Torvalds 2005-04-16 3076 * descend down to leftmost child page
^1da177e4c3f415 Linus Torvalds 2005-04-16 3077 */
^1da177e4c3f415 Linus Torvalds 2005-04-16 3078 if (BT_STACK_FULL(btstack)) {
^1da177e4c3f415 Linus Torvalds 2005-04-16 3079 DT_PUTPAGE(mp);
eb8630d7d2fd135 Joe Perches 2013-06-04 3080 jfs_error(ip->i_sb, "btstack overrun\n");
^1da177e4c3f415 Linus Torvalds 2005-04-16 3081 BT_STACK_DUMP(btstack);
^1da177e4c3f415 Linus Torvalds 2005-04-16 3082 return -EIO;
^1da177e4c3f415 Linus Torvalds 2005-04-16 3083 }
^1da177e4c3f415 Linus Torvalds 2005-04-16 3084 /* push (bn, index) of the parent page/entry */
^1da177e4c3f415 Linus Torvalds 2005-04-16 3085 BT_PUSH(btstack, bn, 0);
^1da177e4c3f415 Linus Torvalds 2005-04-16 3086
^1da177e4c3f415 Linus Torvalds 2005-04-16 3087 /* get the leftmost entry */
^1da177e4c3f415 Linus Torvalds 2005-04-16 3088 stbl = DT_GETSTBL(p);
22dcbf7661c6ffc Ghanshyam Agrawal 2024-09-28 3089
22dcbf7661c6ffc Ghanshyam Agrawal 2024-09-28 @3090 if (stbl[0] < 0 || stbl[0] > 127) {
22dcbf7661c6ffc Ghanshyam Agrawal 2024-09-28 3091 DT_PUTPAGE(mp);
22dcbf7661c6ffc Ghanshyam Agrawal 2024-09-28 3092 jfs_error(ip->i_sb, "stbl[0] out of bound\n");
22dcbf7661c6ffc Ghanshyam Agrawal 2024-09-28 3093 return -EIO;
22dcbf7661c6ffc Ghanshyam Agrawal 2024-09-28 3094 }
22dcbf7661c6ffc Ghanshyam Agrawal 2024-09-28 3095
^1da177e4c3f415 Linus Torvalds 2005-04-16 3096 xd = (pxd_t *) & p->slot[stbl[0]];
^1da177e4c3f415 Linus Torvalds 2005-04-16 3097
^1da177e4c3f415 Linus Torvalds 2005-04-16 3098 /* get the child page block address */
^1da177e4c3f415 Linus Torvalds 2005-04-16 3099 bn = addressPXD(xd);
^1da177e4c3f415 Linus Torvalds 2005-04-16 3100 psize = lengthPXD(xd) << JFS_SBI(ip->i_sb)->l2bsize;
^1da177e4c3f415 Linus Torvalds 2005-04-16 3101
^1da177e4c3f415 Linus Torvalds 2005-04-16 3102 /* unpin the parent page */
^1da177e4c3f415 Linus Torvalds 2005-04-16 3103 DT_PUTPAGE(mp);
^1da177e4c3f415 Linus Torvalds 2005-04-16 3104 }
^1da177e4c3f415 Linus Torvalds 2005-04-16 3105 }
^1da177e4c3f415 Linus Torvalds 2005-04-16 3106
--
0-DAY CI Kernel Test Service
https://github.com/intel/lkp-tests/wiki
reply other threads:[~2026-08-08 8:36 UTC|newest]
Thread overview: [no followups] expand[flat|nested] mbox.gz Atom feed
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=202608081637.KNSd6oSL-lkp@intel.com \
--to=lkp@intel.com \
--cc=error27@gmail.com \
--cc=oe-kbuild@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.