From: Dan Carpenter <dan.carpenter@linaro.org>
To: Joanne Koong <joannelkoong@gmail.com>
Cc: linux-fsdevel@vger.kernel.org
Subject: Re: [bug report] fuse: support copying large folios
Date: Fri, 23 May 2025 21:51:36 +0300 [thread overview]
Message-ID: <aDDDuMjF55MV-EZo@stanley.mountain> (raw)
In-Reply-To: <CAJnrk1ZBOw4RwrGRZk8Qd+vDXUEF=O9NC-TSpS3Cs9rhNDAf=w@mail.gmail.com>
On Fri, May 23, 2025 at 10:32:29AM -0700, Joanne Koong wrote:
> On Fri, May 23, 2025 at 8:59 AM Dan Carpenter <dan.carpenter@linaro.org> wrote:
> >
> > Hello Joanne Koong,
> >
> > This is a semi-automatic email about new static checker warnings.
> >
> > Commit f008a4390bde ("fuse: support copying large folios") from May
> > 12, 2025, leads to the following Smatch complaint:
> >
> > fs/fuse/dev.c:1103 fuse_copy_folio()
> > warn: variable dereferenced before check 'folio' (see line 1101)
> >
> > fs/fuse/dev.c
> > 1100 struct folio *folio = *foliop;
> > 1101 size_t size = folio_size(folio);
> > ^^^^^
> > The patch adds an unchecked dereference
> >
> > 1102
> > 1103 if (folio && zeroing && count < size)
> > ^^^^^
> > and it also adds this check for NULL which is too late.
> >
> > 1104 folio_zero_range(folio, 0, size);
> > 1105
>
> Thanks for flagging. I looked through where we call fuse_copy_folio()
> and we'll never run into the case where folio is null, so all the "if
> folio" branches inside there can probably be cleaned up with a WARN_ON
> check.
>
> I'll submit a patch that fixes this commit and a separate patch that
> cleans up the if folio check.
Another idea is to just crash when people pass a NULL pointer. The stack
traces from NULL dereference bugs are normally easy to debug unless
they're caused by a race condition or memory corruption.
regards,
dan carpenter
prev parent reply other threads:[~2025-05-23 18:51 UTC|newest]
Thread overview: 3+ messages / expand[flat|nested] mbox.gz Atom feed top
2025-05-23 15:59 [bug report] fuse: support copying large folios Dan Carpenter
2025-05-23 17:32 ` Joanne Koong
2025-05-23 18:51 ` Dan Carpenter [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=aDDDuMjF55MV-EZo@stanley.mountain \
--to=dan.carpenter@linaro.org \
--cc=joannelkoong@gmail.com \
--cc=linux-fsdevel@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox