From: sashiko-bot@kernel.org
Cc: linux-security-module@vger.kernel.org
Subject: Re: [PATCH 18/27] selftests/landlock: Fix regex_escape() error handling in matches_log_fs_extra()
Date: Thu, 08 Oct 2026 14:36:37 +0000 [thread overview]
Message-ID: <sashiko-outbox-164308@kernel.org> (raw)
In-Reply-To: <20261008142604.39107-20-gnoack3000@gmail.com>
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [Medium] selftests: errno clobbering by free() in matches_log_fs_extra()
--
commit fde0a2f164054d717ba379b4c41a67fff69162e2
Author: Günther Noack <gnoack3000@gmail.com>
Date: Thu Oct 8 14:25:47 2026 +0000
selftests/landlock: Fix regex_escape() error handling in matches_log_fs_extra()
This commit updates regex_escape() to use a more conventional error handling
interface. It now returns a ssize_t containing either the number of bytes in
the output, or -1 with errno set on failure, and updates the call site
accordingly.
> diff --git a/tools/testing/selftests/landlock/fs_test.c b/tools/testing/selftests/landlock/fs_test.c
> index b1ce0f810e10d..9abc2adef79db 100644
> --- a/tools/testing/selftests/landlock/fs_test.c
> +++ b/tools/testing/selftests/landlock/fs_test.c
[ ... ]
> @@ -7471,13 +7472,14 @@ static int matches_log_fs_extra(struct __test_metadata *const _metadata,
>
> log_match_remaining -= chunk_len;
> log_match_cursor += chunk_len;
> - log_match_cursor = regex_escape(absolute_path, log_match_cursor,
> - log_match_remaining);
> + escaped_len = regex_escape(absolute_path, log_match_cursor,
> + log_match_remaining);
> free(absolute_path);
> - if (log_match_cursor < 0)
> - return (long long)log_match_cursor;
> + if (escaped_len < 0)
> + return -errno;
[Severity: Medium]
Could this free() call clobber errno before it is returned?
If regex_escape() fails due to an insufficient buffer, it returns -1 and
sets errno to ENOMEM. The code in matches_log_fs_extra() then unconditionally
calls free(absolute_path) before checking escaped_len and reading errno.
Since libc's free() is not strictly guaranteed to preserve errno, and may
clobber it during internal operations like unmap, the original ENOMEM could
be lost. This might cause the function to return an incorrect error code or 0
(success) instead of -ENOMEM, masking the test failure.
Would it be safer to cache errno into a local variable before calling free(),
or move the free() call after the error check?
--
Sashiko AI review · https://sashiko.dev/#/patchset/20261008142604.39107-2-gnoack3000@gmail.com?part=18
next prev parent reply other threads:[~2026-10-08 14:36 UTC|newest]
Thread overview: 56+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-10-08 14:25 [PATCH 00/27] landlock: Selftest fixes and cleanups Günther Noack
2026-10-08 14:25 ` [PATCH 01/27] selftests/landlock: Propagate grandchild failures in unix_scoping Günther Noack
2026-10-08 14:33 ` sashiko-bot
2026-10-08 14:25 ` [PATCH 02/27] selftests/landlock: Propagate EXPECT failures from forked children Günther Noack
2026-10-08 14:35 ` sashiko-bot
2026-10-08 14:25 ` [PATCH 03/27] selftests/landlock: Check the thread result in audit.thread Günther Noack
2026-10-08 14:32 ` sashiko-bot
2026-10-08 14:25 ` [PATCH 04/27] selftests/landlock: Zero-initialize the buffer in inconsistent_attr Günther Noack
2026-10-08 14:33 ` sashiko-bot
2026-10-08 14:25 ` [PATCH 05/27] selftests/landlock: Fix the openat() success check in fs_bench Günther Noack
2026-10-08 14:33 ` sashiko-bot
2026-10-08 14:25 ` [PATCH 06/27] selftests/landlock: Fix the reported clock tick rate " Günther Noack
2026-10-08 14:33 ` sashiko-bot
2026-10-08 14:25 ` [PATCH 07/27] selftests/landlock: Fix the ruleset_fd check in empty_or_same_ruleset Günther Noack
2026-10-08 14:35 ` sashiko-bot
2026-10-08 14:25 ` [PATCH 08/27] selftests/landlock: Handle a missing control message in recv_fd() Günther Noack
2026-10-08 14:31 ` sashiko-bot
2026-10-08 14:25 ` [PATCH 09/27] selftests/landlock: Assert tracefs_extract_field() results that are used Günther Noack
2026-10-08 14:33 ` sashiko-bot
2026-10-08 14:25 ` [PATCH 10/27] selftests/landlock: Assert audit initialization in fixture setups Günther Noack
2026-10-08 14:44 ` sashiko-bot
2026-10-08 14:25 ` [PATCH 11/27] selftests/landlock: Assert helper results that are used afterwards Günther Noack
2026-10-08 14:35 ` sashiko-bot
2026-10-08 14:25 ` [PATCH 12/27] selftests/landlock: Assert audit_count_records() before using its result Günther Noack
2026-10-08 14:35 ` sashiko-bot
2026-10-08 14:25 ` [PATCH 13/27] selftests/landlock: Fix memory leak in audit_init_filter_exe() Günther Noack
2026-10-08 14:35 ` sashiko-bot
2026-10-08 14:25 ` [PATCH 14/27] selftests/landlock: Make audit_message large enough for any exe filter Günther Noack
2026-10-08 14:40 ` sashiko-bot
2026-10-08 14:25 ` [PATCH 15/27] selftests/landlock: Close leaked file descriptors Günther Noack
2026-10-08 14:32 ` sashiko-bot
2026-10-08 14:25 ` [PATCH 16/27] selftests/landlock: Check errno for combined VERSION and ERRATA flags Günther Noack
2026-10-08 14:32 ` sashiko-bot
2026-10-08 14:25 ` [PATCH 17/27] selftests/landlock: Fix SIGURG handler setup in scoped_signal_test Günther Noack
2026-10-08 14:32 ` sashiko-bot
2026-10-08 14:25 ` [PATCH 18/27] selftests/landlock: Fix regex_escape() error handling in matches_log_fs_extra() Günther Noack
2026-10-08 14:36 ` sashiko-bot [this message]
2026-10-08 14:25 ` [PATCH 19/27] selftests/landlock: Fix off-by-one in regex_escape() Günther Noack
2026-10-08 14:36 ` sashiko-bot
2026-10-08 14:25 ` [PATCH 20/27] selftests/landlock: Fix the snprintf() error check in matches_log_fs_extra() Günther Noack
2026-10-08 14:34 ` sashiko-bot
2026-10-08 14:25 ` [PATCH 21/27] selftests/landlock: Use _exit() in the named_pipe_ioctl child Günther Noack
2026-10-08 14:33 ` sashiko-bot
2026-10-08 14:25 ` [PATCH 22/27] selftests/landlock: Fix messages and comments in helper programs Günther Noack
2026-10-08 14:33 ` sashiko-bot
2026-10-08 14:25 ` [PATCH 23/27] selftests/landlock: Fix stale comments in common.h and audit.h Günther Noack
2026-10-08 14:33 ` sashiko-bot
2026-10-08 14:25 ` [PATCH 24/27] selftests/landlock: Use ASSERT for syscall failures before errno checks Günther Noack
2026-10-08 14:41 ` sashiko-bot
2026-10-08 14:25 ` [PATCH 25/27] selftests/landlock: Assert WIFEXITED() before checking the exit status Günther Noack
2026-10-08 14:38 ` sashiko-bot
2026-10-08 14:25 ` [PATCH 26/27] selftests/landlock: Use EXPECT for closing FDs and stopping threads Günther Noack
2026-10-08 14:40 ` sashiko-bot
2026-10-08 14:25 ` [PATCH 27/27] selftests/landlock: Use EXPECT for checks that later steps do not need Günther Noack
2026-10-08 14:39 ` sashiko-bot
2026-10-08 14:33 ` [PATCH 00/27] landlock: Selftest fixes and cleanups Günther Noack
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=sashiko-outbox-164308@kernel.org \
--to=sashiko-bot@kernel.org \
--cc=linux-security-module@vger.kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox