From: Dan Carpenter <dan.carpenter@linaro.org>
To: Joanne Koong <joannelkoong@gmail.com>
Cc: linux-fsdevel@vger.kernel.org
Subject: Re: [bug report] fuse: support copying large folios
Date: Fri, 23 May 2025 21:51:36 +0300 [thread overview]
Message-ID: <aDDDuMjF55MV-EZo@stanley.mountain> (raw)
In-Reply-To: <CAJnrk1ZBOw4RwrGRZk8Qd+vDXUEF=O9NC-TSpS3Cs9rhNDAf=w@mail.gmail.com>
On Fri, May 23, 2025 at 10:32:29AM -0700, Joanne Koong wrote:
> On Fri, May 23, 2025 at 8:59 AM Dan Carpenter <dan.carpenter@linaro.org> wrote:
> >
> > Hello Joanne Koong,
> >
> > This is a semi-automatic email about new static checker warnings.
> >
> > Commit f008a4390bde ("fuse: support copying large folios") from May
> > 12, 2025, leads to the following Smatch complaint:
> >
> > fs/fuse/dev.c:1103 fuse_copy_folio()
> > warn: variable dereferenced before check 'folio' (see line 1101)
> >
> > fs/fuse/dev.c
> > 1100 struct folio *folio = *foliop;
> > 1101 size_t size = folio_size(folio);
> > ^^^^^
> > The patch adds an unchecked dereference
> >
> > 1102
> > 1103 if (folio && zeroing && count < size)
> > ^^^^^
> > and it also adds this check for NULL which is too late.
> >
> > 1104 folio_zero_range(folio, 0, size);
> > 1105
>
> Thanks for flagging. I looked through where we call fuse_copy_folio()
> and we'll never run into the case where folio is null, so all the "if
> folio" branches inside there can probably be cleaned up with a WARN_ON
> check.
>
> I'll submit a patch that fixes this commit and a separate patch that
> cleans up the if folio check.
Another idea is to just crash when people pass a NULL pointer. The stack
traces from NULL dereference bugs are normally easy to debug unless
they're caused by a race condition or memory corruption.
regards,
dan carpenter
prev parent reply other threads:[~2025-05-23 18:51 UTC|newest]
Thread overview: 3+ messages / expand[flat|nested] mbox.gz Atom feed top
2025-05-23 15:59 [bug report] fuse: support copying large folios Dan Carpenter
2025-05-23 17:32 ` Joanne Koong
2025-05-23 18:51 ` Dan Carpenter [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=aDDDuMjF55MV-EZo@stanley.mountain \
--to=dan.carpenter@linaro.org \
--cc=joannelkoong@gmail.com \
--cc=linux-fsdevel@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.