From: kernel test robot <lkp@intel.com>
To: <oe-kbuild@lists.linux.dev>
Cc: <lkp@intel.com>, Dan Carpenter <error27@gmail.com>
Subject: [android-common:android14-kiwi-6.1 226/226] drivers/dma-buf/heaps/system_heap.c:347 system_heap_dma_buf_release() error: buffer overflow 'pools' 3 <= 3 (assuming for loop doesn't break)
Date: Sun, 23 Aug 2026 20:30:32 +0800 [thread overview]
Message-ID: <202608222036.kBCUE80j-lkp@intel.com> (raw)
BCC: lkp@intel.com
CC: oe-kbuild-all@lists.linux.dev
TO: cros-kernel-buildreports@googlegroups.com
tree: https://android.googlesource.com/kernel/common android14-kiwi-6.1
head: 3d2b0075700eab3a7aa5b384a24ed78ffedc1c24
commit: b882b8502c3496eb2520d2d03fa94f7e6fa23075 [226/226] ANDROID: dma-buf: system_heap: Add pagepool support to system heap
:::::: branch date: 22 hours ago
:::::: commit date: 3 years, 5 months ago
config: x86_64-randconfig-161-20260822 (https://download.01.org/0day-ci/archive/20260822/202608222036.kBCUE80j-lkp@intel.com/config)
compiler: clang version 22.1.3 (https://github.com/llvm/llvm-project e9846648fd6183ee6d8cbdb4502213fcf902a211)
smatch: v0.5.0-9187-g5189e3fb
If you fix the issue in a separate patch/commit (i.e. not just a new version of
the same patch/commit), kindly add following tags
| Reported-by: kernel test robot <lkp@intel.com>
| Reported-by: Dan Carpenter <error27@gmail.com>
| Closes: https://lore.kernel.org/r/202608222036.kBCUE80j-lkp@intel.com/
smatch warnings:
drivers/dma-buf/heaps/system_heap.c:347 system_heap_dma_buf_release() error: buffer overflow 'pools' 3 <= 3 (assuming for loop doesn't break)
vim +347 drivers/dma-buf/heaps/system_heap.c
b882b8502c3496e John Stultz 2019-06-06 328
5f9d15ca7993a69 John Stultz 2020-09-25 329 static void system_heap_dma_buf_release(struct dma_buf *dmabuf)
5f9d15ca7993a69 John Stultz 2020-09-25 330 {
5f9d15ca7993a69 John Stultz 2020-09-25 331 struct system_heap_buffer *buffer = dmabuf->priv;
5f9d15ca7993a69 John Stultz 2020-09-25 332 struct sg_table *table;
5f9d15ca7993a69 John Stultz 2020-09-25 333 struct scatterlist *sg;
b882b8502c3496e John Stultz 2019-06-06 334 int i, j;
b882b8502c3496e John Stultz 2019-06-06 335
b882b8502c3496e John Stultz 2019-06-06 336 /* Zero the buffer pages before adding back to the pool */
b882b8502c3496e John Stultz 2019-06-06 337 system_heap_zero_buffer(buffer);
5f9d15ca7993a69 John Stultz 2020-09-25 338
5f9d15ca7993a69 John Stultz 2020-09-25 339 table = &buffer->sg_table;
679d94cd7d90087 Guangming 2021-11-26 340 for_each_sgtable_sg(table, sg, i) {
0597bca8783840b John Stultz 2020-09-26 341 struct page *page = sg_page(sg);
0597bca8783840b John Stultz 2020-09-26 342
b882b8502c3496e John Stultz 2019-06-06 343 for (j = 0; j < NUM_ORDERS; j++) {
b882b8502c3496e John Stultz 2019-06-06 344 if (compound_order(page) == orders[j])
b882b8502c3496e John Stultz 2019-06-06 345 break;
b882b8502c3496e John Stultz 2019-06-06 346 }
b882b8502c3496e John Stultz 2019-06-06 @347 dmabuf_page_pool_free(pools[j], page);
0597bca8783840b John Stultz 2020-09-26 348 }
5f9d15ca7993a69 John Stultz 2020-09-25 349 sg_free_table(table);
efa04fefebbd724 John Stultz 2019-12-03 350 kfree(buffer);
efa04fefebbd724 John Stultz 2019-12-03 351 }
efa04fefebbd724 John Stultz 2019-12-03 352
--
0-DAY CI Kernel Test Service
https://github.com/intel/lkp-tests/wiki
reply other threads:[~2026-08-23 12:30 UTC|newest]
Thread overview: [no followups] expand[flat|nested] mbox.gz Atom feed
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=202608222036.kBCUE80j-lkp@intel.com \
--to=lkp@intel.com \
--cc=error27@gmail.com \
--cc=oe-kbuild@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.