From: sashiko-bot@kernel.org
To: ghuicao@163.com
Cc: linux-raid@vger.kernel.org, yukuai@fygo.io
Subject: Re: [PATCH] md/raid5: set pool_size before extra_page allocation to fix leak on error path
Date: Thu, 27 Aug 2026 02:53:59 +0000 [thread overview]
Message-ID: <20260827025359.EF0E21F00A3D@smtp.kernel.org> (raw)
In-Reply-To: <20260827023803.36602-1-ghuicao@163.com>
Thank you for your contribution! Sashiko AI review found 2 potential issue(s) to consider:
Pre-existing issues:
- [High] Memory leak of extra_page and stripe pages during raid5 reshape error path.
- [High] Kernel panic due to NULL pointer dereference in `raid5_free_percpu()` when handling hotplug callback allocation failures.
--
commit e2a9b5ec799de7e8af41dc93ccf252fa2539b0d8
Author: Cao Guanghui <caoguanghui@kylinos.cn>
md/raid5: set pool_size before extra_page allocation to fix leak on error path
Sets conf->pool_size right after the conf->disks array is allocated in
setup_conf(). This ensures that if subsequent initialization fails and
jumps to the abort label, free_conf() uses the correct pool size to clean
up the allocated extra_page entries, preventing a memory leak.
Cc: stable@vger.kernel.org
> diff --git a/drivers/md/raid5.c b/drivers/md/raid5.c
> index b91545ce090de..4efaef622fc05 100644
> --- a/drivers/md/raid5.c
> +++ b/drivers/md/raid5.c
> @@ -7733,6 +7733,7 @@ static struct r5conf *setup_conf(struct mddev *mddev)
>
> if (!conf->disks)
> goto abort;
> + conf->pool_size = max_disks;
>
> for (i = 0; i < max_disks; i++) {
> conf->disks[i].extra_page = alloc_page(GFP_KERNEL);
[Severity: High]
This isn't a bug introduced by this patch, but it exists in the surrounding
reshape logic. Does this same stale conf->pool_size issue leak memory in
resize_stripes()?
If alloc_page(GFP_NOIO) fails in step 4 of resize_stripes(), the function
returns -ENOMEM but fails to update conf->pool_size because it is gated by
if (!err).
However, conf->disks was already permanently replaced in step 3, and new
pages were already allocated for the newly added slots:
drivers/md/raid5.c:resize_stripes()
} else {
kfree(conf->disks);
conf->disks = ndisks;
}
Later in the function:
if (!p)
err = -ENOMEM;
}
if (!err)
conf->pool_size = newsize;
mutex_unlock(&conf->cache_size_mutex);
return err;
Because conf->pool_size is not updated on error, subsequent teardown paths
like free_conf() and shrink_stripes() will use the old boundary and fail to
free the memory allocated for the new slots. Could this exhaust kernel
memory over multiple failed reshape attempts?
[Severity: High]
This is a pre-existing issue on the setup_conf() error path, but could
the abort path trigger a kernel panic due to a null pointer dereference
in raid5_free_percpu()?
If cpuhp_state_add_instance() fails in raid5_alloc_percpu(), the function
returns the error without cleaning up conf->percpu:
drivers/md/raid5.c:raid5_alloc_percpu()
err = cpuhp_state_add_instance(CPUHP_MD_RAID5_PREPARE, &conf->node);
if (!err) {
When setup_conf() receives the error and jumps to the abort label, free_conf()
calls raid5_free_percpu(). Because conf->percpu is not null, it incorrectly
assumes the hotplug node was hashed:
drivers/md/raid5.c:raid5_free_percpu()
if (!conf->percpu)
return;
cpuhp_state_remove_instance(CPUHP_MD_RAID5_PREPARE, &conf->node);
Since the node was never actually added, hlist_del() in the hotplug state
removal blindly unlinks the node, dereferencing node->pprev which is null:
kernel/cpu.c:__cpuhp_state_remove_instance()
remove:
hlist_del(node);
Can this crash the kernel during raid array initialization or hotplug events
if memory allocation fails in the hotplug subsystem?
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260827023803.36602-1-ghuicao@163.com?part=1
next prev parent reply other threads:[~2026-08-27 2:54 UTC|newest]
Thread overview: 17+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-27 2:38 [PATCH] md/raid5: set pool_size before extra_page allocation to fix leak on error path ghuicao
2026-08-27 2:53 ` sashiko-bot [this message]
2026-08-27 6:05 ` [PATCH v2 1/3] " ghuicao
2026-08-27 6:05 ` [PATCH v2 2/3] md/raid5: fix leak and use-after-free in resize_stripes " ghuicao
2026-08-27 6:27 ` sashiko-bot
2026-08-27 6:05 ` [PATCH v2 3/3] md/raid5: fix NULL pointer dereference in raid5_free_percpu ghuicao
2026-08-27 6:18 ` sashiko-bot
2026-08-27 6:27 ` [PATCH v2 1/3] md/raid5: set pool_size before extra_page allocation to fix leak on error path sashiko-bot
2026-08-27 6:32 ` [PATCH v3 " ghuicao
2026-08-27 6:32 ` [PATCH v3 2/3] md/raid5: fix leak and use-after-free in resize_stripes " ghuicao
2026-08-27 7:02 ` sashiko-bot
2026-08-27 6:32 ` [PATCH v3 3/3] md/raid5: fix NULL pointer dereference in raid5_free_percpu ghuicao
2026-08-27 7:17 ` sashiko-bot
2026-08-27 8:03 ` [PATCH v4 1/2] md/raid5: track disks array size to fix extra_page leak on error paths ghuicao
2026-08-27 8:03 ` [PATCH v4 2/2] md/raid5: fix NULL pointer dereference in raid5_free_percpu ghuicao
2026-08-27 8:19 ` [PATCH v4 1/2] md/raid5: track disks array size to fix extra_page leak on error paths sashiko-bot
2026-09-05 2:34 ` yu kuai
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260827025359.EF0E21F00A3D@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=ghuicao@163.com \
--cc=linux-raid@vger.kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
--cc=yukuai@fygo.io \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.