All of lore.kernel.org
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Chandradhar Kumar" <chandradhar.2003@gmail.com>
Cc: linux-raid@vger.kernel.org, yukuai@fygo.io
Subject: Re: [PATCH v2] md/raid0: validate device count before allocating devlist
Date: Sun, 06 Sep 2026 18:55:32 +0000	[thread overview]
Message-ID: <20260906185532.E26CC1F00A3A@smtp.kernel.org> (raw)
In-Reply-To: <20260906184406.2141-1-chandradhar.2003@gmail.com>

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:

Pre-existing issues:
- [High] Integer overflow in `chunk_size` sysfs handler allows a zero-division kernel panic in `map_sector()`.
--

commit ff4c12b29e562bce41f4e75365704e1e7f8e00b2
Author: Chandradhar Kumar <chandradhar.2003@gmail.com>

md/raid0: validate device count before allocating devlist

create_strip_zones() allocates conf->devlist based on mddev->raid_disks
before verifying that enough devices are present. Validate the number of
member devices before allocating devlist to reject invalid
configurations early.

Reported-by: syzbot+a32ff75e417c0f49a8e9@syzkaller.appspotmail.com
Closes: https://syzbot.org/bug?extid=a32ff75e417c0f49a8e9

> diff --git a/drivers/md/raid0.c b/drivers/md/raid0.c
> index 35e103f0c2c3e..8eaf078606d6f 100644
> --- a/drivers/md/raid0.c
> +++ b/drivers/md/raid0.c
[ ... ]
> @@ -144,6 +147,21 @@ static int create_strip_zones(struct mddev *mddev, struct r0conf **private_conf)
>  	}
>  
>  	err = -ENOMEM;
> +
> +	if (mddev->raid_disks <= 0) {
> +		pr_warn("md/raid0:%s: invalid number of disks %d - aborting!\n",
> +			mdname(mddev), mddev->raid_disks);
> +		err = -EINVAL;
> +		goto abort;
> +	}
> +
> +	if (nr_devs < mddev->raid_disks) {
> +		pr_warn("md/raid0:%s: too few disks (%d of %d) - aborting!\n",
> +			mdname(mddev), nr_devs, mddev->raid_disks);
> +		err = -EINVAL;
> +		goto abort;
> +	}
> +
>  	conf->strip_zone = kvzalloc_objs(struct strip_zone, conf->nr_strip_zones);

[Severity: High]
This is a pre-existing issue, but does this code allow an integer overflow
in mddev->chunk_sectors that leads to a division-by-zero kernel panic in
map_sector()?

In drivers/md/md.c:chunk_size_store(), the chunk size is parsed with no
upper bounds checking:

	err = kstrtoul(buf, 10, &n);
	...
	mddev->chunk_sectors = n >> 9;

A large value written to the chunk_size sysfs node of a non-running RAID0
array is bitshifted and truncated into the 32-bit signed integer
mddev->chunk_sectors.

When the array is started and I/O is submitted, the code in map_sector()
can overflow:

drivers/md/raid0.c:map_sector() {
	...
		sector_div(chunk, zone->nb_dev << chunksect_bits);
	} else{
		sect_in_chunk = sector_div(sector, chunk_sects);
		chunk = *sector_offset;
		sector_div(chunk, chunk_sects * zone->nb_dev);
	}
	...
}

If chunk_sects is a power of 2 (e.g., 0x80000000) and nb_dev = 2,
zone->nb_dev << chunksect_bits evaluates to 2 << 31, which overflows to 0
in 32-bit math.

If chunk_sects is not a power of 2 (e.g., 0xC0000000) and nb_dev = 4,
chunk_sects * zone->nb_dev evaluates to 0xC0000000 * 4, which also overflows
to 0.

In both branches, sector_div(chunk, 0) executes and panics the kernel. Can
chunk_size_store() be updated to validate the upper bounds of chunk_size to
prevent this crash?

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260906184406.2141-1-chandradhar.2003@gmail.com?part=1

  reply	other threads:[~2026-09-06 18:55 UTC|newest]

Thread overview: 4+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-06 18:44 [PATCH v2] md/raid0: validate device count before allocating devlist Chandradhar Kumar
2026-09-06 18:55 ` sashiko-bot [this message]
2026-09-07  6:49 ` yu kuai
  -- strict thread matches above, loose matches on Subject: below --
2026-09-06 14:39 [PATCH] " Chandradhar Kumar
2026-09-06 17:37 ` [PATCH v2] " Chandradhar Kumar

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260906185532.E26CC1F00A3A@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=chandradhar.2003@gmail.com \
    --cc=linux-raid@vger.kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    --cc=yukuai@fygo.io \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.