From: Pooyan Azad <pooyan.azadparvar@gmail.com>
To: Minchan Kim <minchan@kernel.org>,
Sergey Senozhatsky <senozhatsky@chromium.org>
Cc: Andrew Morton <akpm@linux-foundation.org>,
Jens Axboe <axboe@kernel.dk>,
linux-block@vger.kernel.org, linux-kernel@vger.kernel.org
Subject: [PATCH] zram: fix short reads from block_state
Date: Mon, 28 Sep 2026 18:48:26 +0200 [thread overview]
Message-ID: <20260928164826.24858-1-pooyan.azadparvar@gmail.com> (raw)
In-Reply-To: <CANC3H+LdtoydSp+o2ecErAw7k6R2+gRf9LyxcaoHv_mGhJmyQQ@mail.gmail.com>
read_block_state() formats each entry directly into the buffer supplied
by read(). If the remaining buffer is too small for one complete record,
snprintf() returns the full record length and the function stops without
copying data or advancing the file position. A read smaller than a record
therefore returns zero at a non-EOF position and cannot make progress.
Convert block_state to seq_file so formatted records are buffered
independently of the userspace read size. Keep dev_lock held across each
seq_file iteration and continue to protect individual entries with their
slot locks.
Fixes: c0265342bff4 ("zram: introduce zram memory tracking")
Closes: https://lore.kernel.org/r/CANC3H+LdtoydSp+o2ecErAw7k6R2+gRf9LyxcaoHv_mGhJmyQQ@mail.gmail.com/
Signed-off-by: Pooyan Azad <pooyan.azadparvar@gmail.com>
---
Compile-tested with:
make O=/tmp/zram-build W=1 -j$(nproc) \
drivers/block/zram/zram_drv.o
No runtime testing of the patched kernel was performed.
drivers/block/zram/zram_drv.c | 101 ++++++++++++++++++----------------
1 file changed, 53 insertions(+), 48 deletions(-)
diff --git a/drivers/block/zram/zram_drv.c b/drivers/block/zram/zram_drv.c
index a9b3bb1d3bef..66a2fdb1274b 100644
--- a/drivers/block/zram/zram_drv.c
+++ b/drivers/block/zram/zram_drv.c
@@ -1542,68 +1542,73 @@ static void zram_debugfs_destroy(void)
debugfs_remove_recursive(zram_debugfs_root);
}
-static ssize_t read_block_state(struct file *file, char __user *buf,
- size_t count, loff_t *ppos)
+static void *zram_block_state_start(struct seq_file *seq, loff_t *pos)
{
- char *kbuf;
- unsigned long index;
- ssize_t written = 0;
- struct zram *zram = file->private_data;
+ struct zram *zram = seq->private;
unsigned long nr_pages;
- kbuf = kvmalloc(count, GFP_KERNEL);
- if (!kbuf)
- return -ENOMEM;
-
- guard(rwsem_read)(&zram->dev_lock);
- if (!init_done(zram)) {
- kvfree(kbuf);
- return -EINVAL;
- }
+ down_read(&zram->dev_lock);
+ if (!init_done(zram))
+ return ERR_PTR(-EINVAL);
nr_pages = zram->disksize >> PAGE_SHIFT;
+ if (*pos >= nr_pages)
+ return NULL;
- for (index = *ppos; index < nr_pages; index++) {
- int copied;
+ return &zram->table[*pos];
+}
- slot_lock(zram, index);
- if (!slot_allocated(zram, index))
- goto next;
+static void *zram_block_state_next(struct seq_file *seq, void *v, loff_t *pos)
+{
+ struct zram *zram = seq->private;
+ unsigned long nr_pages = zram->disksize >> PAGE_SHIFT;
- copied = snprintf(kbuf + written, count,
- "%12lu %12u.%06d %c%c%c%c%c%c\n",
- index, zram->table[index].attr.ac_time, 0,
- test_slot_flag(zram, index, ZRAM_SAME) ? 's' : '.',
- test_slot_flag(zram, index, ZRAM_WB) ? 'w' : '.',
- test_slot_flag(zram, index, ZRAM_HUGE) ? 'h' : '.',
- test_slot_flag(zram, index, ZRAM_IDLE) ? 'i' : '.',
- get_slot_comp_priority(zram, index) ? 'r' : '.',
- test_slot_flag(zram, index,
- ZRAM_INCOMPRESSIBLE) ? 'n' : '.');
-
- if (count <= copied) {
- slot_unlock(zram, index);
- break;
- }
- written += copied;
- count -= copied;
-next:
+ ++*pos;
+ if (*pos >= nr_pages)
+ return NULL;
+
+ return &zram->table[*pos];
+}
+
+static void zram_block_state_stop(struct seq_file *seq, void *v)
+{
+ struct zram *zram = seq->private;
+
+ up_read(&zram->dev_lock);
+}
+
+static int zram_block_state_show(struct seq_file *seq, void *v)
+{
+ struct zram *zram = seq->private;
+ struct zram_table_entry *entry = v;
+ unsigned long index = entry - zram->table;
+
+ slot_lock(zram, index);
+ if (!slot_allocated(zram, index)) {
slot_unlock(zram, index);
- *ppos += 1;
+ return SEQ_SKIP;
}
- if (copy_to_user(buf, kbuf, written))
- written = -EFAULT;
- kvfree(kbuf);
+ seq_printf(seq, "%12lu %12u.%06d %c%c%c%c%c%c\n",
+ index, zram->table[index].attr.ac_time, 0,
+ test_slot_flag(zram, index, ZRAM_SAME) ? 's' : '.',
+ test_slot_flag(zram, index, ZRAM_WB) ? 'w' : '.',
+ test_slot_flag(zram, index, ZRAM_HUGE) ? 'h' : '.',
+ test_slot_flag(zram, index, ZRAM_IDLE) ? 'i' : '.',
+ get_slot_comp_priority(zram, index) ? 'r' : '.',
+ test_slot_flag(zram, index, ZRAM_INCOMPRESSIBLE) ? 'n' : '.');
+ slot_unlock(zram, index);
- return written;
+ return 0;
}
-static const struct file_operations proc_zram_block_state_op = {
- .open = simple_open,
- .read = read_block_state,
- .llseek = default_llseek,
+static const struct seq_operations zram_block_state_sops = {
+ .start = zram_block_state_start,
+ .next = zram_block_state_next,
+ .stop = zram_block_state_stop,
+ .show = zram_block_state_show,
};
+DEFINE_SEQ_ATTRIBUTE(zram_block_state);
static void zram_debugfs_register(struct zram *zram)
{
@@ -1613,7 +1618,7 @@ static void zram_debugfs_register(struct zram *zram)
zram->debugfs_dir = debugfs_create_dir(zram->disk->disk_name,
zram_debugfs_root);
debugfs_create_file("block_state", 0400, zram->debugfs_dir,
- zram, &proc_zram_block_state_op);
+ zram, &zram_block_state_fops);
}
static void zram_debugfs_unregister(struct zram *zram)
--
2.43.0
next prev parent reply other threads:[~2026-09-28 16:49 UTC|newest]
Thread overview: 7+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-20 16:27 zram: block_state returns premature EOF with short read buffers Pooyan Azadparvar
2026-09-28 16:48 ` Pooyan Azad [this message]
2026-09-29 4:52 ` [PATCH] zram: fix short reads from block_state Sergey Senozhatsky
2026-09-29 7:18 ` [PATCH v2] " Pooyan Azad
2026-09-29 8:36 ` Sergey Senozhatsky
2026-09-29 4:13 ` zram: block_state returns premature EOF with short read buffers Sergey Senozhatsky
2026-09-29 4:28 ` Sergey Senozhatsky
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260928164826.24858-1-pooyan.azadparvar@gmail.com \
--to=pooyan.azadparvar@gmail.com \
--cc=akpm@linux-foundation.org \
--cc=axboe@kernel.dk \
--cc=linux-block@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=minchan@kernel.org \
--cc=senozhatsky@chromium.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox