All of lore.kernel.org
 help / color / mirror / Atom feed
* drivers/infiniband/hw/mlx5/devx.c:2544 deliver_event() error: __builtin_memcpy() 'event_data->hdr.out_data' too small (8 vs 64)
@ 2026-09-09 11:48 kernel test robot
  0 siblings, 0 replies; only message in thread
From: kernel test robot @ 2026-09-09 11:48 UTC (permalink / raw)
  To: oe-kbuild; +Cc: lkp, Dan Carpenter

BCC: lkp@intel.com
CC: oe-kbuild-all@lists.linux.dev
CC: linux-kernel@vger.kernel.org
TO: Marco Elver <elver@google.com>
CC: "Vlastimil Babka (SUSE)" <vbabka@kernel.org>
CC: "Harry Yoo (Oracle)" <harry@kernel.org>

tree:   https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git master
head:   893e11787f78e43b534e252249ac3fff4d1333f8
commit: feb662d9168b63e1d4c02671ec96005410c6f3ce slab: support for compiler-assisted type-based slab cache partitioning
date:   4 months ago
:::::: branch date: 16 hours ago
:::::: commit date: 4 months ago
config: m68k-randconfig-r072-20260909 (https://download.01.org/0day-ci/archive/20260909/202609091953.6LeOXTCj-lkp@intel.com/config)
compiler: m68k-linux-gcc (GCC) 12.5.0
smatch: v0.5.0-9187-g5189e3fb

If you fix the issue in a separate patch/commit (i.e. not just a new version of
the same patch/commit), kindly add following tags
| Fixes: feb662d9168b ("slab: support for compiler-assisted type-based slab cache partitioning")
| Reported-by: kernel test robot <lkp@intel.com>
| Reported-by: Dan Carpenter <error27@gmail.com>
| Closes: https://lore.kernel.org/r/202609091953.6LeOXTCj-lkp@intel.com/

New smatch warnings:
drivers/infiniband/hw/mlx5/devx.c:2544 deliver_event() error: __builtin_memcpy() 'event_data->hdr.out_data' too small (8 vs 64)

Old smatch warnings:
drivers/infiniband/hw/mlx5/devx.c:2890 devx_async_event_read() error: copy_to_user() 'event_data' too small (8 vs 72)

vim +2544 drivers/infiniband/hw/mlx5/devx.c

5ec9d8ee87c627 Yishai Hadas    2019-06-30  2510  
5ec9d8ee87c627 Yishai Hadas    2019-06-30  2511  static int deliver_event(struct devx_event_subscription *event_sub,
5ec9d8ee87c627 Yishai Hadas    2019-06-30  2512  			 const void *data)
5ec9d8ee87c627 Yishai Hadas    2019-06-30  2513  {
5ec9d8ee87c627 Yishai Hadas    2019-06-30  2514  	struct devx_async_event_file *ev_file;
5ec9d8ee87c627 Yishai Hadas    2019-06-30  2515  	struct devx_async_event_data *event_data;
5ec9d8ee87c627 Yishai Hadas    2019-06-30  2516  	unsigned long flags;
5ec9d8ee87c627 Yishai Hadas    2019-06-30  2517  
5ec9d8ee87c627 Yishai Hadas    2019-06-30  2518  	ev_file = event_sub->ev_file;
5ec9d8ee87c627 Yishai Hadas    2019-06-30  2519  
5ec9d8ee87c627 Yishai Hadas    2019-06-30  2520  	if (ev_file->omit_data) {
5ec9d8ee87c627 Yishai Hadas    2019-06-30  2521  		spin_lock_irqsave(&ev_file->lock, flags);
a8af8694a5e8dd Yishai Hadas    2020-02-12  2522  		if (!list_empty(&event_sub->event_list) ||
a8af8694a5e8dd Yishai Hadas    2020-02-12  2523  		    ev_file->is_destroyed) {
5ec9d8ee87c627 Yishai Hadas    2019-06-30  2524  			spin_unlock_irqrestore(&ev_file->lock, flags);
5ec9d8ee87c627 Yishai Hadas    2019-06-30  2525  			return 0;
5ec9d8ee87c627 Yishai Hadas    2019-06-30  2526  		}
5ec9d8ee87c627 Yishai Hadas    2019-06-30  2527  
5ec9d8ee87c627 Yishai Hadas    2019-06-30  2528  		list_add_tail(&event_sub->event_list, &ev_file->event_list);
5ec9d8ee87c627 Yishai Hadas    2019-06-30  2529  		spin_unlock_irqrestore(&ev_file->lock, flags);
5ec9d8ee87c627 Yishai Hadas    2019-06-30  2530  		wake_up_interruptible(&ev_file->poll_wait);
5ec9d8ee87c627 Yishai Hadas    2019-06-30  2531  		return 0;
5ec9d8ee87c627 Yishai Hadas    2019-06-30  2532  	}
5ec9d8ee87c627 Yishai Hadas    2019-06-30  2533  
5ec9d8ee87c627 Yishai Hadas    2019-06-30  2534  	event_data = kzalloc(sizeof(*event_data) + sizeof(struct mlx5_eqe),
5ec9d8ee87c627 Yishai Hadas    2019-06-30  2535  			     GFP_ATOMIC);
5ec9d8ee87c627 Yishai Hadas    2019-06-30  2536  	if (!event_data) {
5ec9d8ee87c627 Yishai Hadas    2019-06-30  2537  		spin_lock_irqsave(&ev_file->lock, flags);
5ec9d8ee87c627 Yishai Hadas    2019-06-30  2538  		ev_file->is_overflow_err = 1;
5ec9d8ee87c627 Yishai Hadas    2019-06-30  2539  		spin_unlock_irqrestore(&ev_file->lock, flags);
5ec9d8ee87c627 Yishai Hadas    2019-06-30  2540  		return -ENOMEM;
5ec9d8ee87c627 Yishai Hadas    2019-06-30  2541  	}
5ec9d8ee87c627 Yishai Hadas    2019-06-30  2542  
5ec9d8ee87c627 Yishai Hadas    2019-06-30  2543  	event_data->hdr.cookie = event_sub->cookie;
5ec9d8ee87c627 Yishai Hadas    2019-06-30 @2544  	memcpy(event_data->hdr.out_data, data, sizeof(struct mlx5_eqe));
5ec9d8ee87c627 Yishai Hadas    2019-06-30  2545  
5ec9d8ee87c627 Yishai Hadas    2019-06-30  2546  	spin_lock_irqsave(&ev_file->lock, flags);
f7c8416ccea52b Jason Gunthorpe 2020-01-08  2547  	if (!ev_file->is_destroyed)
5ec9d8ee87c627 Yishai Hadas    2019-06-30  2548  		list_add_tail(&event_data->list, &ev_file->event_list);
f7c8416ccea52b Jason Gunthorpe 2020-01-08  2549  	else
f7c8416ccea52b Jason Gunthorpe 2020-01-08  2550  		kfree(event_data);
5ec9d8ee87c627 Yishai Hadas    2019-06-30  2551  	spin_unlock_irqrestore(&ev_file->lock, flags);
5ec9d8ee87c627 Yishai Hadas    2019-06-30  2552  	wake_up_interruptible(&ev_file->poll_wait);
5ec9d8ee87c627 Yishai Hadas    2019-06-30  2553  
5ec9d8ee87c627 Yishai Hadas    2019-06-30  2554  	return 0;
5ec9d8ee87c627 Yishai Hadas    2019-06-30  2555  }
5ec9d8ee87c627 Yishai Hadas    2019-06-30  2556  

:::::: The code at line 2544 was first introduced by commit
:::::: 5ec9d8ee87c627a2c981d871e41f6e2a942f53fd IB/mlx5: Implement DEVX dispatching event

:::::: TO: Yishai Hadas <yishaih@mellanox.com>
:::::: CC: Jason Gunthorpe <jgg@mellanox.com>

--
0-DAY CI Kernel Test Service
https://github.com/intel/lkp-tests/wiki

^ permalink raw reply	[flat|nested] only message in thread

only message in thread, other threads:[~2026-09-09 11:48 UTC | newest]

Thread overview: (only message) (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-09 11:48 drivers/infiniband/hw/mlx5/devx.c:2544 deliver_event() error: __builtin_memcpy() 'event_data->hdr.out_data' too small (8 vs 64) kernel test robot

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.