Linux XFS filesystem development
 help / color / mirror / Atom feed
From: "Darrick J. Wong" <djwong@kernel.org>
To: Christoph Hellwig <hch@infradead.org>
Cc: cem@kernel.org, stable@vger.kernel.org, linux-xfs@vger.kernel.org
Subject: Re: [PATCH 10/14] xfarray: don't crash when sorting if array element crosses a folio
Date: Tue, 22 Sep 2026 10:53:13 -0700	[thread overview]
Message-ID: <20260922175313.GW2705364@frogsfrogsfrogs> (raw)
In-Reply-To: <arIQntfRrNKGHyoF@infradead.org>

On Mon, Sep 21, 2026 at 10:22:38PM -0700, Christoph Hellwig wrote:
> On Sun, Sep 20, 2026 at 11:17:35PM -0700, Darrick J. Wong wrote:
> > From: Darrick J. Wong <djwong@kernel.org>
> > 
> > LOLLM points out that if an array element crosses a folio boundary,
> > xfile_get_folio returns a NULL folio pointer.  If this happens,
> > si->folio is also set to NULL, and calling folio_pos/folio_address will
> > just crash the kernel.  Teach this function to handle this condition by
> > falling back to reading the array element into scratchpad memory.
> > 
> > Cc: <stable@vger.kernel.org> # v6.6
> > Fixes: cf36f4f64c2d4e ("xfs: cache pages used for xfarray quicksort convergence")
> > Signed-off-by: "Darrick J. Wong" <djwong@kernel.org>
> > Assisted-by: LOLLM # finding obvious bugs
> > ---
> >  fs/xfs/scrub/xfarray.c |   18 ++++++++++--------
> >  1 file changed, 10 insertions(+), 8 deletions(-)
> > 
> > 
> > diff --git a/fs/xfs/scrub/xfarray.c b/fs/xfs/scrub/xfarray.c
> > index 2ce24bfe4c0fab..30a58e9d4378e4 100644
> > --- a/fs/xfs/scrub/xfarray.c
> > +++ b/fs/xfs/scrub/xfarray.c
> > @@ -830,22 +830,24 @@ xfarray_sort_scan(
> >  			return PTR_ERR(folio);
> >  		si->folio = folio;
> >  
> > -		si->first_folio_idx = xfarray_idx(si->array,
> > -				folio_pos(si->folio) + si->array->obj_size - 1);
> > +		if (si->folio) {
> > +			si->first_folio_idx = xfarray_idx(si->array,
> > +					folio_pos(si->folio) + si->array->obj_size - 1);
> 
> Overly long line.
> 
> > +			if (xfarray_pos(si->array, si->last_folio_idx + 1) > next_pos)
> 
> Another one.
> 
> > +	if (!si->folio || idx < si->first_folio_idx || idx > si->last_folio_idx) {
> 
> And one more.

On second glance, I think a cleaner way to fix this is to move the logic
that loads the folio, computes the new {first,last}_folio_idx, and
validates them into a new helper:

static int
xfarray_sort_load_folio(
	struct xfarray_sortinfo	*si,
	xfarray_idx_t		idx,
	loff_t			idx_pos)
{
	struct folio		*folio;
	loff_t			next_pos;

	folio = xfile_get_folio(si->array->xfile, idx_pos, si->array->obj_size,
			XFILE_ALLOC);
	if (IS_ERR(folio))
		return PTR_ERR(folio);
	si->folio = folio;

	/* No folio?  Get the caller to read into the scratchpad. */
	if (!si->folio)
		return 0;

	si->first_folio_idx = xfarray_idx(si->array,
			folio_pos(si->folio) + si->array->obj_size - 1);

	next_pos = folio_next_pos(si->folio);
	si->last_folio_idx = xfarray_idx(si->array, next_pos - 1);
	if (xfarray_pos(si->array, si->last_folio_idx + 1) > next_pos)
		si->last_folio_idx--;

	/*
	 * If this folio still doesn't cover the desired element, it must cross
	 * a folio boundary.  Get the caller to read into the scratchpad.
	 */
	if (idx < si->first_folio_idx || idx > si->last_folio_idx) {
		xfarray_sort_scan_done(si);
		return 0;
	}

	trace_xfarray_sort_scan(si, idx);
	return 0;
}

--D

  reply	other threads:[~2026-09-22 17:53 UTC|newest]

Thread overview: 43+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-21  6:13 [PATCHSET] xfs: LLM-inspired bug fixes, part 16 Darrick J. Wong
2026-09-21  6:15 ` [PATCH 01/14] xfs: fix missing xfs_qm_adjust_dqlimits call in quotacheck repair Darrick J. Wong
2026-09-22  5:14   ` Christoph Hellwig
2026-09-21  6:15 ` [PATCH 02/14] xfs: online quotacheck must dirty dquot if enforcement adjustments needed Darrick J. Wong
2026-09-22  5:14   ` Christoph Hellwig
2026-09-22 18:02   ` Darrick J. Wong
2026-09-21  6:15 ` [PATCH 03/14] xfs: fix buffer overruns in xfs_ioc_attr_list Darrick J. Wong
2026-09-22  5:15   ` Christoph Hellwig
2026-09-22 17:31     ` Darrick J. Wong
2026-09-21  6:16 ` [PATCH 04/14] xfs: clean up after failed metafile relinking Darrick J. Wong
2026-09-22  5:17   ` Christoph Hellwig
2026-09-22 17:33     ` Darrick J. Wong
2026-09-21  6:16 ` [PATCH 05/14] xfs: pass xfs_trans_resv object to reservation calculation helpers Darrick J. Wong
2026-09-22  5:18   ` Christoph Hellwig
2026-09-22 17:29     ` Darrick J. Wong
2026-09-22 17:34     ` Darrick J. Wong
2026-09-21  6:16 ` [PATCH 06/14] xfs: fix xfs_rename_space_res for non-pptr filesystems Darrick J. Wong
2026-09-22  5:20   ` Christoph Hellwig
2026-09-22 17:36     ` Darrick J. Wong
2026-09-21  6:16 ` [PATCH 07/14] xfs: fix ondisk symlink target validation in xrep_dinode_check_dfork Darrick J. Wong
2026-09-22  5:20   ` Christoph Hellwig
2026-09-22 20:42   ` Dave Chinner
2026-09-21  6:17 ` [PATCH 08/14] xfs: fix maximum atomic cow length computation Darrick J. Wong
2026-09-22  5:21   ` Christoph Hellwig
2026-09-22  6:53     ` Darrick J. Wong
2026-09-21  6:17 ` [PATCH 09/14] xfs: add missing healthmon trace strings Darrick J. Wong
2026-09-22  5:21   ` Christoph Hellwig
2026-09-21  6:17 ` [PATCH 10/14] xfarray: don't crash when sorting if array element crosses a folio Darrick J. Wong
2026-09-22  5:22   ` Christoph Hellwig
2026-09-22 17:53     ` Darrick J. Wong [this message]
2026-09-23  4:39       ` Christoph Hellwig
2026-09-21  6:17 ` [PATCH 11/14] xfarray: don't allow users to unset in the middle of an array Darrick J. Wong
2026-09-22  5:23   ` Christoph Hellwig
2026-09-22  6:47     ` Darrick J. Wong
2026-09-22 18:14   ` Darrick J. Wong
2026-09-21  6:18 ` [PATCH 12/14] xfs: don't allow sorting sparse arrays Darrick J. Wong
2026-09-22  5:24   ` Christoph Hellwig
2026-09-22 18:07   ` Darrick J. Wong
2026-09-21  6:18 ` [PATCH 13/14] xfs: simply the free space btree repair code Darrick J. Wong
2026-09-22  5:24   ` Christoph Hellwig
2026-09-21  6:18 ` [PATCH 14/14] xfarray: warn against sorting arrays with identical elements Darrick J. Wong
2026-09-22  5:25   ` Christoph Hellwig
2026-09-22 18:10   ` Darrick J. Wong

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260922175313.GW2705364@frogsfrogsfrogs \
    --to=djwong@kernel.org \
    --cc=cem@kernel.org \
    --cc=hch@infradead.org \
    --cc=linux-xfs@vger.kernel.org \
    --cc=stable@vger.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox