Linux filesystem development
 help / color / mirror / Atom feed
From: Dan Carpenter <dan.carpenter@linaro.org>
To: Joanne Koong <joannelkoong@gmail.com>
Cc: linux-fsdevel@vger.kernel.org
Subject: Re: [bug report] fuse: support copying large folios
Date: Fri, 23 May 2025 21:51:36 +0300	[thread overview]
Message-ID: <aDDDuMjF55MV-EZo@stanley.mountain> (raw)
In-Reply-To: <CAJnrk1ZBOw4RwrGRZk8Qd+vDXUEF=O9NC-TSpS3Cs9rhNDAf=w@mail.gmail.com>

On Fri, May 23, 2025 at 10:32:29AM -0700, Joanne Koong wrote:
> On Fri, May 23, 2025 at 8:59 AM Dan Carpenter <dan.carpenter@linaro.org> wrote:
> >
> > Hello Joanne Koong,
> >
> > This is a semi-automatic email about new static checker warnings.
> >
> > Commit f008a4390bde ("fuse: support copying large folios") from May
> > 12, 2025, leads to the following Smatch complaint:
> >
> >     fs/fuse/dev.c:1103 fuse_copy_folio()
> >     warn: variable dereferenced before check 'folio' (see line 1101)
> >
> > fs/fuse/dev.c
> >   1100          struct folio *folio = *foliop;
> >   1101          size_t size = folio_size(folio);
> >                                          ^^^^^
> > The patch adds an unchecked dereference
> >
> >   1102
> >   1103          if (folio && zeroing && count < size)
> >                     ^^^^^
> > and it also adds this check for NULL which is too late.
> >
> >   1104                  folio_zero_range(folio, 0, size);
> >   1105
> 
> Thanks for flagging. I looked through where we call fuse_copy_folio()
> and we'll never run into the case where folio is null, so all the "if
> folio" branches inside there can probably be cleaned up with a WARN_ON
> check.
> 
> I'll submit a patch that fixes this commit and a separate patch that
> cleans up the if folio check.

Another idea is to just crash when people pass a NULL pointer.  The stack
traces from NULL dereference bugs are normally easy to debug unless
they're caused by a race condition or memory corruption.

regards,
dan carpenter

      reply	other threads:[~2025-05-23 18:51 UTC|newest]

Thread overview: 3+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2025-05-23 15:59 [bug report] fuse: support copying large folios Dan Carpenter
2025-05-23 17:32 ` Joanne Koong
2025-05-23 18:51   ` Dan Carpenter [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=aDDDuMjF55MV-EZo@stanley.mountain \
    --to=dan.carpenter@linaro.org \
    --cc=joannelkoong@gmail.com \
    --cc=linux-fsdevel@vger.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox