From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from kanga.kvack.org (kanga.kvack.org [205.233.56.17]) by smtp.lore.kernel.org (Postfix) with ESMTP id CAB16C3DA78 for ; Sat, 14 Jan 2023 07:58:09 +0000 (UTC) Received: by kanga.kvack.org (Postfix) id 1770F8E0002; Sat, 14 Jan 2023 02:58:09 -0500 (EST) Received: by kanga.kvack.org (Postfix, from userid 40) id 130E58E0001; Sat, 14 Jan 2023 02:58:09 -0500 (EST) X-Delivered-To: int-list-linux-mm@kvack.org Received: by kanga.kvack.org (Postfix, from userid 63042) id 016C18E0002; Sat, 14 Jan 2023 02:58:08 -0500 (EST) X-Delivered-To: linux-mm@kvack.org Received: from relay.hostedemail.com (smtprelay0011.hostedemail.com [216.40.44.11]) by kanga.kvack.org (Postfix) with ESMTP id E4A218E0001 for ; Sat, 14 Jan 2023 02:58:08 -0500 (EST) Received: from smtpin12.hostedemail.com (a10.router.float.18 [10.200.18.1]) by unirelay02.hostedemail.com (Postfix) with ESMTP id B3BAE120422 for ; Sat, 14 Jan 2023 07:58:08 +0000 (UTC) X-FDA: 80352651456.12.78417CB Received: from mail-wr1-f45.google.com (mail-wr1-f45.google.com [209.85.221.45]) by imf03.hostedemail.com (Postfix) with ESMTP id 0749020009 for ; Sat, 14 Jan 2023 07:58:05 +0000 (UTC) Authentication-Results: imf03.hostedemail.com; dkim=pass header.d=gmail.com header.s=20210112 header.b=EZ1spF+g; spf=pass (imf03.hostedemail.com: domain of error27@gmail.com designates 209.85.221.45 as permitted sender) smtp.mailfrom=error27@gmail.com; dmarc=pass (policy=none) header.from=gmail.com ARC-Seal: i=1; s=arc-20220608; d=hostedemail.com; t=1673683086; a=rsa-sha256; cv=none; b=hf1qZMqpF7y90KlujzUDVs4z9rBOwhE61ay0bvh7qkZq2PbkQrTJDIp3CV46c7aHtDmrBb 6sqCjPVSTN3K7swkA01gYnvBf0jl8J5KuX0yRaLgS+TCmVD6FzU1jvAN+kTdOazj15n7el iT1ZxQVB4Mee5pbN5kvpb0QqbPFSQIo= ARC-Authentication-Results: i=1; imf03.hostedemail.com; dkim=pass header.d=gmail.com header.s=20210112 header.b=EZ1spF+g; spf=pass (imf03.hostedemail.com: domain of error27@gmail.com designates 209.85.221.45 as permitted sender) smtp.mailfrom=error27@gmail.com; dmarc=pass (policy=none) header.from=gmail.com ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=hostedemail.com; s=arc-20220608; t=1673683086; h=from:from:sender:reply-to:subject:subject:date:date: message-id:message-id:to:to:cc:cc:mime-version:mime-version: content-type:content-type:content-transfer-encoding: in-reply-to:in-reply-to:references:dkim-signature; bh=qQA/jgCksOZddh0t+6XHMKOBpW3pPFDdE2DouCM2c2E=; b=CPIS8uoWft3czalrO7cvY7XTDnExsY99ZFyg0zv9L9U0/DD0mHJFhg1jREFVjUxjtN4uK0 6TcvcTEJDlzum3kDytB9eSLwca7UAsxrnDEuqe0/qd7Cmq4MbcBPvgqVcDmbRXb98sJQcq mCQj3TAp19WQgjC+l7JmdkXUnF9LIUE= Received: by mail-wr1-f45.google.com with SMTP id h16so22940908wrz.12 for ; Fri, 13 Jan 2023 23:58:05 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20210112; h=in-reply-to:content-disposition:mime-version:message-id:subject:cc :to:from:date:from:to:cc:subject:date:message-id:reply-to; bh=qQA/jgCksOZddh0t+6XHMKOBpW3pPFDdE2DouCM2c2E=; b=EZ1spF+g9tj6JZ9obKA2f15ldiLo7ImLG5vcNvOKxCI7g1jH7XwfnYg+/TPjYLPwYw dY+mlOjDuh8PfSp+dJPtGQQXwzMRwTA+bI78bvWBJKyOD2N3k3i2/EOc/FTfv0BCiENg gz6DkCu9lxP7li91CBICIVM/KTo4ymo08vjjekqYRLcsvxhftIUHF4rLlrtnv1f1bnBz tpKP97A469zDgIgKAXqppor8SbmqauqWrlENC3e/qY/o5k2bFow4SUKXBbG7ZuCNWjnf pqK6UMuhul99NpBJ+/w3LdvhYwWip2AHtV4EfTXMde4iT1uj0FMcMlnixLnCnRKpco9M Zc3w== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20210112; h=in-reply-to:content-disposition:mime-version:message-id:subject:cc :to:from:date:x-gm-message-state:from:to:cc:subject:date:message-id :reply-to; bh=qQA/jgCksOZddh0t+6XHMKOBpW3pPFDdE2DouCM2c2E=; b=66yZg7fkXnyBvXjNZJ+sIJTaY1PWTpivDOmx1rViYB/+jvyIHukLXaUW12IlFPL5KL 6g1MLHnP91Pj0dX6jS7pVemwIh6cpgnIM586vwC+74fr04RKxiyt6BATionHEchZ3Yfo 4nA7DqsGZmc29jYw8bt1mHldp8HjlIPqZFCI7cZogrZ85CBtN6Jor2HAQoxzPbnHOlLT Hpyhi10hP8goGNOcsXqdnYkKbCc3G3pPFM1MIn6bWVtRsYo/UB+0nNoeajxCS2puhbuZ U2hM0SF6ROOrSTr+AG3hkZLZ52fsA2yyyLNgIOuSCCEfEIozt3eyrTHnC3BLtC1IZ03N NTeA== X-Gm-Message-State: AFqh2krULBrn0nUTM8eRRObyTqnuR68YFemN3006HajSMTbpCaNM4h2d UIVfgs778L1QMck+4wnYmdE= X-Google-Smtp-Source: AMrXdXvCPoBFIbLaSJkx19HGU3lDcez+oZCo3Ap1z0m3e1nMLOEGXaXMSkGzFGIoW9/7X5QkRnu2fg== X-Received: by 2002:adf:de0e:0:b0:242:63e5:2449 with SMTP id b14-20020adfde0e000000b0024263e52449mr54048043wrm.69.1673683084436; Fri, 13 Jan 2023 23:58:04 -0800 (PST) Received: from localhost ([102.36.222.112]) by smtp.gmail.com with ESMTPSA id c8-20020a5d4cc8000000b002bdeb0cf706sm1540112wrt.65.2023.01.13.23.58.02 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Fri, 13 Jan 2023 23:58:03 -0800 (PST) Date: Sat, 14 Jan 2023 10:57:59 +0300 From: Dan Carpenter To: oe-kbuild@lists.linux.dev, Baoquan He , linux-mm@kvack.org Cc: lkp@intel.com, oe-kbuild-all@lists.linux.dev, linux-kernel@vger.kernel.org, urezki@gmail.com, lstoakes@gmail.com, stephen.s.brennan@oracle.com, willy@infradead.org, akpm@linux-foundation.org, hch@infradead.org, Baoquan He Subject: Re: [PATCH v3 3/7] mm/vmalloc.c: allow vread() to read out vm_map_ram areas Message-ID: <202301132345.KVjvHMFq-lkp@intel.com> MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <20230113031921.64716-4-bhe@redhat.com> X-Rspam-User: X-Rspamd-Queue-Id: 0749020009 X-Rspamd-Server: rspam01 X-Stat-Signature: reptq5owkoeykjgdhhtbriz3zpnxxdgz X-HE-Tag: 1673683085-871459 X-HE-Meta: U2FsdGVkX1+jd+n0M49mRk6WpvINajUQfrwqsORRp8Sc/n7uc98EnZXeeTcxbeDzriGJ23baoMgUcZyPDWkNBit2RgZXjU2p2llj2vhY3jA6jm8kE3IilOeuBn9KsCrPB9HnUdcUKjztrv2Bc+RTfKnQ+UU/QhY9VoR14EZMseEzL4XyNyR3QShIQ+aW05hpRVchFxAP/OiT3fAhtGR46LqaoaRLFmbgIH28LTFhHIjo8BgRVEX8kFeC0pbZEGTfKJNlaeI4QNrJKYhCvZOk9xtlUJlNGsiJ7CSObWS/n2QV4HBdW6jCk3ecXlwWXO6Mu6AJulHoMJxxZws8+UN/Rz9HAXpBKk3uQdmNZtBE+QT0rMO8AUirF3zQs+SqvrgOr3N+79VcM+hyJ7uEJj4FRfkKl2Rx6IMGkUeJ5PBMBgDUC+C7xXJ+o722pIL/QmJV5yBYlaIFi/i8G9H1AzmaI/QGjjsZIZ6lsxVdS1f+J7GYLgRGAghCvjPcZS3wtfYBmkkeUfkYGMC8OCVg1GThDXbPeqt+yRQHzdFDnX8RJMIVBXBsBbkLSNS0bR5POs4Qxv4xXZThx1ufamoI2po5hwiGf0VnJWlMXcGIuHzqFrW2jSEeCbwP+X79bXSm4zXfjmpCgknjcXdA9DvVYkNAeK3IBm6zXv/rA4Qzp6TQljme31EMt30Mq83+4VLTZ/4pG9H7Hk0eDIm2qHbBDAFTUQ5o5fK7fPOfdwmWjj562sYSoxh7NPikesnpbMQReYrJVFcOtNVioeWa4fBadz1zLJ+7zOw/95rtQoLeTVn2st/SIB8cUVg+UvU+Y0MtDrU4S3cITqIRaRdsibutifyJ3ifWFdbX5rYKnZSFmoQcBPpXgmOWDRs1CVcB6RzZXmZhUAM6VWlnIT6uY2wENIfGOnyXSQT4Eyx/evQc4NjkpK1HnUf3wDySYtpGsspsOTlZiYPfvpGUMWyv6gAGMFs mtvbRK98 Gt7kbXAvVFn6ZjkaFMGtiAfxRmGWBu+DeqKnn1eSnD0XbcLSbKnwFtdRRlCHdRi57QE+Ktg9ocK7ltua3fF1pdLTDcUtAc58Eg1eZ X-Bogosity: Ham, tests=bogofilter, spamicity=0.000000, version=1.2.4 Sender: owner-linux-mm@kvack.org Precedence: bulk X-Loop: owner-majordomo@kvack.org List-ID: Hi Baoquan, url: https://github.com/intel-lab-lkp/linux/commits/Baoquan-He/mm-vmalloc-c-add-used_map-into-vmap_block-to-track-space-of-vmap_block/20230113-112149 base: https://git.kernel.org/pub/scm/linux/kernel/git/akpm/mm.git mm-everything patch link: https://lore.kernel.org/r/20230113031921.64716-4-bhe%40redhat.com patch subject: [PATCH v3 3/7] mm/vmalloc.c: allow vread() to read out vm_map_ram areas config: i386-randconfig-m021 compiler: gcc-11 (Debian 11.3.0-8) 11.3.0 If you fix the issue, kindly add following tag where applicable | Reported-by: kernel test robot | Reported-by: Dan Carpenter smatch warnings: mm/vmalloc.c:3682 vread() error: we previously assumed 'vm' could be null (see line 3664) vim +/vm +3682 mm/vmalloc.c ^1da177e4c3f415 Linus Torvalds 2005-04-16 3630 long vread(char *buf, char *addr, unsigned long count) ^1da177e4c3f415 Linus Torvalds 2005-04-16 3631 { e81ce85f960c2e2 Joonsoo Kim 2013-04-29 3632 struct vmap_area *va; e81ce85f960c2e2 Joonsoo Kim 2013-04-29 3633 struct vm_struct *vm; ^1da177e4c3f415 Linus Torvalds 2005-04-16 3634 char *vaddr, *buf_start = buf; d0107eb07320b5d KAMEZAWA Hiroyuki 2009-09-21 3635 unsigned long buflen = count; 129dbdf298d7383 Baoquan He 2023-01-13 3636 unsigned long n, size, flags; ^1da177e4c3f415 Linus Torvalds 2005-04-16 3637 4aff1dc4fb3a5a3 Andrey Konovalov 2022-03-24 3638 addr = kasan_reset_tag(addr); 4aff1dc4fb3a5a3 Andrey Konovalov 2022-03-24 3639 ^1da177e4c3f415 Linus Torvalds 2005-04-16 3640 /* Don't allow overflow */ ^1da177e4c3f415 Linus Torvalds 2005-04-16 3641 if ((unsigned long) addr + count < count) ^1da177e4c3f415 Linus Torvalds 2005-04-16 3642 count = -(unsigned long) addr; ^1da177e4c3f415 Linus Torvalds 2005-04-16 3643 e81ce85f960c2e2 Joonsoo Kim 2013-04-29 3644 spin_lock(&vmap_area_lock); f181234a5a21fd0 Chen Wandun 2021-09-02 3645 va = find_vmap_area_exceed_addr((unsigned long)addr); f608788cd2d6cae Serapheim Dimitropoulos 2021-04-29 3646 if (!va) f608788cd2d6cae Serapheim Dimitropoulos 2021-04-29 3647 goto finished; f181234a5a21fd0 Chen Wandun 2021-09-02 3648 f181234a5a21fd0 Chen Wandun 2021-09-02 3649 /* no intersects with alive vmap_area */ f181234a5a21fd0 Chen Wandun 2021-09-02 3650 if ((unsigned long)addr + count <= va->va_start) f181234a5a21fd0 Chen Wandun 2021-09-02 3651 goto finished; f181234a5a21fd0 Chen Wandun 2021-09-02 3652 f608788cd2d6cae Serapheim Dimitropoulos 2021-04-29 3653 list_for_each_entry_from(va, &vmap_area_list, list) { e81ce85f960c2e2 Joonsoo Kim 2013-04-29 3654 if (!count) e81ce85f960c2e2 Joonsoo Kim 2013-04-29 3655 break; e81ce85f960c2e2 Joonsoo Kim 2013-04-29 3656 129dbdf298d7383 Baoquan He 2023-01-13 3657 vm = va->vm; 129dbdf298d7383 Baoquan He 2023-01-13 3658 flags = va->flags & VMAP_FLAGS_MASK; 129dbdf298d7383 Baoquan He 2023-01-13 3659 129dbdf298d7383 Baoquan He 2023-01-13 3660 if (!vm && !flags) ^^^ vm can be NULL if a flag in VMAP_FLAGS_MASK is set. e81ce85f960c2e2 Joonsoo Kim 2013-04-29 3661 continue; e81ce85f960c2e2 Joonsoo Kim 2013-04-29 3662 129dbdf298d7383 Baoquan He 2023-01-13 3663 vaddr = (char *) va->va_start; 129dbdf298d7383 Baoquan He 2023-01-13 @3664 size = vm ? get_vm_area_size(vm) : va_size(va); ^^ 129dbdf298d7383 Baoquan He 2023-01-13 3665 129dbdf298d7383 Baoquan He 2023-01-13 3666 if (addr >= vaddr + size) ^1da177e4c3f415 Linus Torvalds 2005-04-16 3667 continue; ^1da177e4c3f415 Linus Torvalds 2005-04-16 3668 while (addr < vaddr) { ^1da177e4c3f415 Linus Torvalds 2005-04-16 3669 if (count == 0) ^1da177e4c3f415 Linus Torvalds 2005-04-16 3670 goto finished; ^1da177e4c3f415 Linus Torvalds 2005-04-16 3671 *buf = '\0'; ^1da177e4c3f415 Linus Torvalds 2005-04-16 3672 buf++; ^1da177e4c3f415 Linus Torvalds 2005-04-16 3673 addr++; ^1da177e4c3f415 Linus Torvalds 2005-04-16 3674 count--; ^1da177e4c3f415 Linus Torvalds 2005-04-16 3675 } 129dbdf298d7383 Baoquan He 2023-01-13 3676 n = vaddr + size - addr; d0107eb07320b5d KAMEZAWA Hiroyuki 2009-09-21 3677 if (n > count) d0107eb07320b5d KAMEZAWA Hiroyuki 2009-09-21 3678 n = count; 129dbdf298d7383 Baoquan He 2023-01-13 3679 129dbdf298d7383 Baoquan He 2023-01-13 3680 if (flags & VMAP_RAM) assume VMAP_RAM is not set 129dbdf298d7383 Baoquan He 2023-01-13 3681 vmap_ram_vread(buf, addr, n, flags); 129dbdf298d7383 Baoquan He 2023-01-13 @3682 else if (!(vm->flags & VM_IOREMAP)) ^^^^^^^^^ Unchecked dereference. Should this be "flags" instead of "vm->flags"? d0107eb07320b5d KAMEZAWA Hiroyuki 2009-09-21 3683 aligned_vread(buf, addr, n); d0107eb07320b5d KAMEZAWA Hiroyuki 2009-09-21 3684 else /* IOREMAP area is treated as memory hole */ d0107eb07320b5d KAMEZAWA Hiroyuki 2009-09-21 3685 memset(buf, 0, n); d0107eb07320b5d KAMEZAWA Hiroyuki 2009-09-21 3686 buf += n; d0107eb07320b5d KAMEZAWA Hiroyuki 2009-09-21 3687 addr += n; d0107eb07320b5d KAMEZAWA Hiroyuki 2009-09-21 3688 count -= n; ^1da177e4c3f415 Linus Torvalds 2005-04-16 3689 } ^1da177e4c3f415 Linus Torvalds 2005-04-16 3690 finished: e81ce85f960c2e2 Joonsoo Kim 2013-04-29 3691 spin_unlock(&vmap_area_lock); d0107eb07320b5d KAMEZAWA Hiroyuki 2009-09-21 3692 d0107eb07320b5d KAMEZAWA Hiroyuki 2009-09-21 3693 if (buf == buf_start) d0107eb07320b5d KAMEZAWA Hiroyuki 2009-09-21 3694 return 0; d0107eb07320b5d KAMEZAWA Hiroyuki 2009-09-21 3695 /* zero-fill memory holes */ d0107eb07320b5d KAMEZAWA Hiroyuki 2009-09-21 3696 if (buf != buf_start + buflen) d0107eb07320b5d KAMEZAWA Hiroyuki 2009-09-21 3697 memset(buf, 0, buflen - (buf - buf_start)); d0107eb07320b5d KAMEZAWA Hiroyuki 2009-09-21 3698 d0107eb07320b5d KAMEZAWA Hiroyuki 2009-09-21 3699 return buflen; ^1da177e4c3f415 Linus Torvalds 2005-04-16 3700 } -- 0-DAY CI Kernel Test Service https://github.com/intel/lkp-tests