From: "David Hildenbrand (Arm)" <david@kernel.org>
To: Anshuman <anshumantewari123@gmail.com>,
Andrew Morton <akpm@linux-foundation.org>,
Lorenzo Stoakes <ljs@kernel.org>
Cc: Shuah Khan <shuah@kernel.org>, Zi Yan <ziy@nvidia.com>,
Baolin Wang <baolin.wang@linux.alibaba.com>,
"Liam R . Howlett" <liam@infradead.org>,
Nico Pache <nico.pache@linux.dev>,
Ryan Roberts <ryan.roberts@arm.com>, Dev Jain <dev.jain@arm.com>,
Barry Song <baohua@kernel.org>, Lance Yang <lance.yang@linux.dev>,
Usama Arif <usama.arif@linux.dev>,
Vlastimil Babka <vbabka@kernel.org>,
Mike Rapoport <rppt@kernel.org>,
Suren Baghdasaryan <surenb@google.com>,
Michal Hocko <mhocko@suse.com>,
linux-mm@kvack.org, linux-kselftest@vger.kernel.org,
linux-kernel@vger.kernel.org
Subject: Re: [PATCH] selftests/mm: check strdup() and fix buf leak in parse_test_type()
Date: Fri, 21 Aug 2026 16:18:57 +0200 [thread overview]
Message-ID: <7bb2d581-924e-4a59-9955-b8afa2b51268@kernel.org> (raw)
In-Reply-To: <20260821114416.12255-1-anshumantewari123@gmail.com>
On 8/21/26 13:44, Anshuman wrote:
> The return value of strdup() is never checked before being passed to
> strsep() and strcmp(). If strdup() fails and returns NULL, strsep()
> returns NULL as well, and the subsequent strcmp(NULL, "all") is
> undefined behavior, likely causing a crash.
In practice this is extraordinarily unlikely to ever fail. :)
So I don't think we would ever experience this.
>
> Additionally, buf is never freed. strsep() advances the buf pointer
> past the first token, so by the time buf would normally be freed,
> the original pointer returned by strdup() has already been
> overwritten and is no longer available.
Given that parse_test_type() is called only once, nobody cares.
>
> Check strdup()'s return value and fail cleanly on allocation failure.
> Keep a separate pointer to the original allocation so it can be
> freed once buf is done being used, after all parsing has completed
> successfully.
>
> Signed-off-by: Anshuman <anshumantewari123@gmail.com>
> ---
[...]
That's too much churn for something that is irrelevant in practice and
makes the code more complicated.
So the following is better I think:
From 36d525409eb16f56e667b2f979f2c6ef112ff235 Mon Sep 17 00:00:00 2001
From: "David Hildenbrand (Arm)" <david@kernel.org>
Date: Fri, 21 Aug 2026 15:57:57 +0200
Subject: [PATCH] selftests/mm: khugepaged: remove str_dup() usage
We don't check str_dup() return value and never free it. While both
things are irrelevant in practice, let's just work on argv[0] directly
and avoid the str_dup().
Nobody after us needs these parts of the argv[0] string.
Signed-off-by: David Hildenbrand (Arm) <david@kernel.org>
---
tools/testing/selftests/mm/khugepaged.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/tools/testing/selftests/mm/khugepaged.c
b/tools/testing/selftests/mm/khugepaged.c
index d3a53673e1f9..7520fc0483ac 100644
--- a/tools/testing/selftests/mm/khugepaged.c
+++ b/tools/testing/selftests/mm/khugepaged.c
@@ -1226,7 +1226,7 @@ static void parse_test_type(int argc, char **argv)
return;
}
- buf = strdup(argv[0]);
+ buf = argv[0];
token = strsep(&buf, ":");
if (!strcmp(token, "all")) {
--
2.43.0
--
Cheers,
David
next prev parent reply other threads:[~2026-08-21 14:19 UTC|newest]
Thread overview: 8+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-21 11:44 [PATCH] selftests/mm: check strdup() and fix buf leak in parse_test_type() Anshuman
2026-08-21 14:18 ` David Hildenbrand (Arm) [this message]
2026-08-21 16:09 ` Anshuman Tewari
2026-08-21 16:18 ` David Hildenbrand (Arm)
2026-08-21 20:14 ` Anshuman Tewari
2026-08-25 11:03 ` David Hildenbrand (Arm)
2026-08-25 18:20 ` Anshuman Tewari
2026-08-25 18:32 ` David Hildenbrand (Arm)
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=7bb2d581-924e-4a59-9955-b8afa2b51268@kernel.org \
--to=david@kernel.org \
--cc=akpm@linux-foundation.org \
--cc=anshumantewari123@gmail.com \
--cc=baohua@kernel.org \
--cc=baolin.wang@linux.alibaba.com \
--cc=dev.jain@arm.com \
--cc=lance.yang@linux.dev \
--cc=liam@infradead.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-kselftest@vger.kernel.org \
--cc=linux-mm@kvack.org \
--cc=ljs@kernel.org \
--cc=mhocko@suse.com \
--cc=nico.pache@linux.dev \
--cc=rppt@kernel.org \
--cc=ryan.roberts@arm.com \
--cc=shuah@kernel.org \
--cc=surenb@google.com \
--cc=usama.arif@linux.dev \
--cc=vbabka@kernel.org \
--cc=ziy@nvidia.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.