From: David Howells <dhowells@redhat.com>
To: Christian Brauner <christian@brauner.io>
Cc: David Howells <dhowells@redhat.com>,
Paulo Alcantara <pc@manguebit.org>,
netfs@lists.linux.dev, linux-afs@lists.infradead.org,
linux-cifs@vger.kernel.org, ceph-devel@vger.kernel.org,
linux-fsdevel@vger.kernel.org, linux-kernel@vger.kernel.org,
Edward Adam Davis <eadavis@qq.com>,
syzbot+6a13fc77eb6f0802be2d@syzkaller.appspotmail.com
Subject: [PATCH v4 06/10] netfs: break unbuffered write when netfs_alloc_subrequest() fails
Date: Thu, 27 Aug 2026 14:42:59 +0100 [thread overview]
Message-ID: <20260827134304.2075713-7-dhowells@redhat.com> (raw)
In-Reply-To: <20260827134304.2075713-1-dhowells@redhat.com>
From: Edward Adam Davis <eadavis@qq.com>
syzbot reported a null-ptr-deref below [1] following a fault injection in
netfs_alloc_subrequest(). [0]
When netfs_alloc_subrequest() fails, subreq is NULL.
Later, netfs_prepare_write() tries to initialize members of
subreq(e.g., source), the issue in [1] is triggered.
Let's handle the error of netfs_prepare_write() properly.
[0]
FAULT_INJECTION: forcing a failure.
name failslab, interval 1, probability 0, space 0, times 0
Call Trace:
netfs_alloc_subrequest+0x116/0x3f0
netfs_prepare_write+0x76/0x7b0
netfs_unbuffered_write+0x75c/0x2020
netfs_unbuffered_write_iter_locked+0x7d6/0xa80
netfs_unbuffered_write_iter+0x442/0x720
v9fs_file_write_iter+0xbf/0x100
vfs_write+0x6ac/0x1050
[1]
KASAN: null-ptr-deref in range [0x00000000000000a8-0x00000000000000af]
RIP: 0010:netfs_prepare_write+0xbc/0x7b0 fs/netfs/write_issue.c:173
Call Trace:
netfs_unbuffered_write+0x75c/0x2020 fs/netfs/direct_write.c:111
netfs_unbuffered_write_iter_locked+0x7d6/0xa80 fs/netfs/direct_write.c:290
netfs_unbuffered_write_iter+0x442/0x720 fs/netfs/direct_write.c:382
v9fs_file_write_iter+0xbf/0x100 fs/9p/vfs_file.c:409
new_sync_write fs/read_write.c:595 [inline]
Fixes: 288ace2f57c9 ("netfs: New writeback implementation")
Reported-by: syzbot+6a13fc77eb6f0802be2d@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=6a13fc77eb6f0802be2d
Tested-by: syzbot+6a13fc77eb6f0802be2d@syzkaller.appspotmail.com
Signed-off-by: Edward Adam Davis <eadavis@qq.com>
Signed-off-by: David Howells <dhowells@redhat.com>
---
fs/netfs/direct_write.c | 5 +++++
fs/netfs/write_issue.c | 2 ++
2 files changed, 7 insertions(+)
diff --git a/fs/netfs/direct_write.c b/fs/netfs/direct_write.c
index fbcfadb232ee..2361277416c7 100644
--- a/fs/netfs/direct_write.c
+++ b/fs/netfs/direct_write.c
@@ -110,6 +110,11 @@ static int netfs_unbuffered_write(struct netfs_io_request *wreq)
if (!subreq) {
netfs_prepare_write(wreq, stream, wreq->start + wreq->transferred);
subreq = stream->construct;
+ if (!subreq) {
+ wreq->error = -ENOMEM;
+ ret = -ENOMEM;
+ break;
+ }
stream->construct = NULL;
}
diff --git a/fs/netfs/write_issue.c b/fs/netfs/write_issue.c
index 2d9cfcd43658..851f6f93ad45 100644
--- a/fs/netfs/write_issue.c
+++ b/fs/netfs/write_issue.c
@@ -170,6 +170,8 @@ void netfs_prepare_write(struct netfs_io_request *wreq,
rolling_buffer_make_space(&wreq->buffer, wreq->gfp);
subreq = netfs_alloc_subrequest(wreq);
+ if (!subreq)
+ return;
subreq->source = stream->source;
subreq->start = start;
subreq->stream_nr = stream->stream_nr;
next prev parent reply other threads:[~2026-08-27 13:43 UTC|newest]
Thread overview: 13+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-27 13:42 [PATCH v4 00/10] netfs, cachefiles: Miscellaneous fixes David Howells
2026-08-27 13:42 ` [PATCH v4 01/10] netfs: Fix uninitialized return value in netfs_unbuffered_write() David Howells
2026-08-27 13:42 ` [PATCH v4 02/10] netfs: Fix unbuffered/DIO write partial transfer error return David Howells
2026-08-27 13:42 ` [PATCH v4 03/10] netfs: Fix error vs transferred passed to ->ki_complete() David Howells
2026-08-27 13:42 ` [PATCH v4 04/10] netfs: Fix i_size update for partial transfer David Howells
2026-08-27 13:42 ` [PATCH v4 05/10] netfs: Fix subreq ref leak David Howells
2026-08-27 13:42 ` David Howells [this message]
2026-08-27 13:43 ` [PATCH v4 07/10] netfs: Fix readahead synchronisation issues by loading all folios upfront David Howells
2026-08-27 13:43 ` [PATCH v4 08/10] netfs: Mark folios with COPY_TO_CACHE whilst issuing subreqs David Howells
2026-08-27 13:43 ` [PATCH v4 09/10] netfs: Fix read progress reporting David Howells
2026-08-27 13:43 ` [PATCH v4 10/10] cachefiles: Fix potential UAF/KASAN warning David Howells
2026-08-27 22:59 ` [PATCH v4 00/10] netfs, cachefiles: Miscellaneous fixes Paulo Alcantara
2026-08-31 7:55 ` Christian Brauner
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260827134304.2075713-7-dhowells@redhat.com \
--to=dhowells@redhat.com \
--cc=ceph-devel@vger.kernel.org \
--cc=christian@brauner.io \
--cc=eadavis@qq.com \
--cc=linux-afs@lists.infradead.org \
--cc=linux-cifs@vger.kernel.org \
--cc=linux-fsdevel@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=netfs@lists.linux.dev \
--cc=pc@manguebit.org \
--cc=syzbot+6a13fc77eb6f0802be2d@syzkaller.appspotmail.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.