All of lore.kernel.org
 help / color / mirror / Atom feed
* [PATCH 6.12.y] mm/damon/vaddr-kunit: check region count in three_regions test
       [not found] <2026090819-haiku-machinist-83fa@gregkh>
@ 2026-09-09  3:45 ` SJ Park
  2026-09-09  3:56   ` sashiko-bot
  2026-09-09 20:26   ` Sasha Levin
  0 siblings, 2 replies; 3+ messages in thread
From: SJ Park @ 2026-09-09  3:45 UTC (permalink / raw)
  To: stable; +Cc: damon, SJ Park, Brendan Higgins, Andrew Morton

damon_do_test_apply_three_regions() iterates regions after
damon_set_regions() call assuming the function would succeed at setting
the number of regions the same to the expected one.  It might have failed.
In this case, __nth_region_of() in the iteration could return NULL and
NULL dereference can happen in the test.

The consequent user impact (NULL dereference) is quite bad.  The realistic
user impact would be limited, though.  It would affect only test run
setups.

Fix it by testing if the number of regions was also changed as expected
and exit early for the failure.

The issue was discovered [1] by Sashiko.

Link: https://lore.kernel.org/20260718001442.87129-4-sj@kernel.org
Link: https://lore.kernel.org/20260713144757.39740-1-sj@kernel.org [1]
Fixes: 17ccae8bb5c9 ("mm/damon: add kunit tests")
Signed-off-by: SJ Park <sj@kernel.org>
Cc: Brendan Higgins <brendan.higgins@linux.dev>
Cc: <stable@vger.kernel.org> # 5.15.x
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
(cherry picked from commit 5fea07e460874c8c7cf00f728efbe22abc62c8d8)
Signed-off-by: SJ Park <sj@kernel.org>
---
 mm/damon/tests/vaddr-kunit.h | 5 +++++
 1 file changed, 5 insertions(+)

diff --git a/mm/damon/tests/vaddr-kunit.h b/mm/damon/tests/vaddr-kunit.h
index ed2845d9f9a95..9eead9882dcce 100644
--- a/mm/damon/tests/vaddr-kunit.h
+++ b/mm/damon/tests/vaddr-kunit.h
@@ -149,12 +149,17 @@ static void damon_do_test_apply_three_regions(struct kunit *test,
 
 	damon_set_regions(t, three_regions, 3);
 
+	KUNIT_EXPECT_EQ(test, damon_nr_regions(t), nr_expected / 2);
+	if (damon_nr_regions(t) != nr_expected / 2)
+		goto out;
+
 	for (i = 0; i < nr_expected / 2; i++) {
 		r = __nth_region_of(t, i);
 		KUNIT_EXPECT_EQ(test, r->ar.start, expected[i * 2]);
 		KUNIT_EXPECT_EQ(test, r->ar.end, expected[i * 2 + 1]);
 	}
 
+out:
 	damon_destroy_target(t);
 }
 
-- 
2.47.3


^ permalink raw reply related	[flat|nested] 3+ messages in thread

* Re: [PATCH 6.12.y] mm/damon/vaddr-kunit: check region count in three_regions test
  2026-09-09  3:45 ` [PATCH 6.12.y] mm/damon/vaddr-kunit: check region count in three_regions test SJ Park
@ 2026-09-09  3:56   ` sashiko-bot
  2026-09-09 20:26   ` Sasha Levin
  1 sibling, 0 replies; 3+ messages in thread
From: sashiko-bot @ 2026-09-09  3:56 UTC (permalink / raw)
  To: SJ Park; +Cc: damon

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:

Pre-existing issues:
- [High] Incomplete fix: The same vulnerable test pattern fixed by this patch in `vaddr-kunit.h` also exists in `mm/damon/tests/core-kunit.h` within `damon_test_merge_regions_of()`, where a hardcoded loop accesses regions via `__nth_region_of()` after an unchecked operation.
--

commit 95900378d75f76847738ad9f2040d727e3455432
Author: SJ Park <sj@kernel.org>

    mm/damon/vaddr-kunit: check region count in three_regions test

This commit adds a check in damon_do_test_apply_three_regions() to verify
that damon_set_regions() updated the region count as expected. If the count
is wrong, it exits early to prevent a potential NULL pointer dereference
when accessing the regions.

Link: https://lore.kernel.org/20260718001442.87129-4-sj@kernel.org
Link: https://lore.kernel.org/20260713144757.39740-1-sj@kernel.org [1]

> diff --git a/mm/damon/tests/vaddr-kunit.h b/mm/damon/tests/vaddr-kunit.h
> index ed2845d9f9a95..9eead9882dcce 100644
> --- a/mm/damon/tests/vaddr-kunit.h
> +++ b/mm/damon/tests/vaddr-kunit.h
> @@ -149,12 +149,17 @@ static void damon_do_test_apply_three_regions(struct kunit *test,
>  
>  	damon_set_regions(t, three_regions, 3);
>  
> +	KUNIT_EXPECT_EQ(test, damon_nr_regions(t), nr_expected / 2);
> +	if (damon_nr_regions(t) != nr_expected / 2)
> +		goto out;
> +
>  	for (i = 0; i < nr_expected / 2; i++) {
>  		r = __nth_region_of(t, i);
>  		KUNIT_EXPECT_EQ(test, r->ar.start, expected[i * 2]);
>  		KUNIT_EXPECT_EQ(test, r->ar.end, expected[i * 2 + 1]);
>  	}

[Severity: High]
This is a pre-existing issue, but should a similar fix also be applied to
mm/damon/tests/core-kunit.h?

Looking at damon_test_merge_regions_of() in mm/damon/tests/core-kunit.h,
there is an identical vulnerable pattern:

	KUNIT_EXPECT_EQ(test, damon_nr_regions(t), 5u);
	for (i = 0; i < 5; i++) {
		r = __nth_region_of(t, i);
		KUNIT_EXPECT_EQ(test, r->ar.start, saddrs[i]);

If a regression causes damon_merge_regions_of() to return fewer than 5
regions, the KUNIT_EXPECT_EQ() check will log a failure but will not abort
execution.

Will the subsequent loop continue executing past the actual number of
regions, causing __nth_region_of(t, i) to return NULL? Does this result
in a NULL pointer dereference when accessing r->ar.start that crashes the
test execution environment?

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260909034509.142303-1-sj@kernel.org?part=1

^ permalink raw reply	[flat|nested] 3+ messages in thread

* Re: [PATCH 6.12.y] mm/damon/vaddr-kunit: check region count in three_regions test
  2026-09-09  3:45 ` [PATCH 6.12.y] mm/damon/vaddr-kunit: check region count in three_regions test SJ Park
  2026-09-09  3:56   ` sashiko-bot
@ 2026-09-09 20:26   ` Sasha Levin
  1 sibling, 0 replies; 3+ messages in thread
From: Sasha Levin @ 2026-09-09 20:26 UTC (permalink / raw)
  To: stable; +Cc: Sasha Levin, damon, SJ Park, Brendan Higgins, Andrew Morton

> damon_do_test_apply_three_regions() iterates regions after
> damon_set_regions() call assuming the function would succeed at setting
> the number of regions the same to the expected one.  It might have failed.

Queued for 6.12, thanks.

-- 
Thanks,
Sasha

^ permalink raw reply	[flat|nested] 3+ messages in thread

end of thread, other threads:[~2026-09-09 20:26 UTC | newest]

Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
     [not found] <2026090819-haiku-machinist-83fa@gregkh>
2026-09-09  3:45 ` [PATCH 6.12.y] mm/damon/vaddr-kunit: check region count in three_regions test SJ Park
2026-09-09  3:56   ` sashiko-bot
2026-09-09 20:26   ` Sasha Levin

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.