All of lore.kernel.org
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Chandradhar Kumar" <chandradhar.2003@gmail.com>
Cc: linux-raid@vger.kernel.org, yukuai@fygo.io
Subject: Re: [PATCH] md/raid0: validate device count before allocating devlist
Date: Sun, 06 Sep 2026 14:55:17 +0000	[thread overview]
Message-ID: <20260906145518.7FA711F00A3A@smtp.kernel.org> (raw)
In-Reply-To: <20260906143928.105165-1-chandradhar.2003@gmail.com>

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [Medium] The newly added validation `if (nr_devs < mddev->raid_disks)` uses signed integer comparison, which can be bypassed if `mddev->raid_disks` is set to a negative value from user-space, resulting in an incomplete fix.
--

commit b0e2bd0b0a05bf7824ef3d801efa4d7542d36bbc
Author: Chandradhar Kumar <chandradhar.2003@gmail.com>

md/raid0: validate device count before allocating devlist

This commit adds early validation to check if there are enough member
devices before allocating the device list. It aims to prevent excessive
allocations that trigger warnings on invalid configurations.

Link: https://syzbot.org/bug?extid=a32ff75e417c0f49a8e9

> diff --git a/drivers/md/raid0.c b/drivers/md/raid0.c
> index 35e103f0c2c3e..586e3411f24c1 100644
> --- a/drivers/md/raid0.c
> +++ b/drivers/md/raid0.c
[ ... ]
> @@ -147,6 +150,14 @@ static int create_strip_zones(struct mddev *mddev, struct r0conf **private_conf)
>  	conf->strip_zone = kvzalloc_objs(struct strip_zone, conf->nr_strip_zones);
>  	if (!conf->strip_zone)
>  		goto abort;
> +
> +	if (nr_devs < mddev->raid_disks) {
        ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
[Severity: Medium]
Does this signed comparison allow bypassing the early abort if a negative
value is provided from user-space?

If a user issues the SET_ARRAY_INFO ioctl with a negative value for
raid_disks, it gets assigned directly without validation:

drivers/md/md.c:md_set_array_info() {
    ...
    mddev->raid_disks    = info->raid_disks;
    ...
}

When followed by the RUN_ARRAY ioctl, this validation check in
create_strip_zones() evaluates to false (e.g., 1 < -1). This bypasses the
check and allows the negative value to be cast to SIZE_MAX in array3_size()
which is then passed to kvzalloc().

Could this trigger the exact same warning for huge memory allocations that
this patch was explicitly intended to fix?

> +		pr_warn("md/raid0:%s: too few disks (%d of %d) - aborting!\n",
> +			mdname(mddev), nr_devs, mddev->raid_disks);
> +		err = -EINVAL;
> +		goto abort;
> +	}
> +
>  	conf->devlist = kvzalloc(array3_size(sizeof(struct md_rdev *),
>  					     conf->nr_strip_zones,
>  					     mddev->raid_disks),

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260906143928.105165-1-chandradhar.2003@gmail.com?part=1

  reply	other threads:[~2026-09-06 14:55 UTC|newest]

Thread overview: 3+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-06 14:39 [PATCH] md/raid0: validate device count before allocating devlist Chandradhar Kumar
2026-09-06 14:55 ` sashiko-bot [this message]
2026-09-06 17:37 ` [PATCH v2] " Chandradhar Kumar

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260906145518.7FA711F00A3A@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=chandradhar.2003@gmail.com \
    --cc=linux-raid@vger.kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    --cc=yukuai@fygo.io \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.