From: "Darrick J. Wong" <djwong@kernel.org>
To: Christoph Hellwig <hch@infradead.org>
Cc: cem@kernel.org, stable@vger.kernel.org, linux-xfs@vger.kernel.org
Subject: Re: [PATCH 10/14] xfarray: don't crash when sorting if array element crosses a folio
Date: Tue, 22 Sep 2026 10:53:13 -0700 [thread overview]
Message-ID: <20260922175313.GW2705364@frogsfrogsfrogs> (raw)
In-Reply-To: <arIQntfRrNKGHyoF@infradead.org>
On Mon, Sep 21, 2026 at 10:22:38PM -0700, Christoph Hellwig wrote:
> On Sun, Sep 20, 2026 at 11:17:35PM -0700, Darrick J. Wong wrote:
> > From: Darrick J. Wong <djwong@kernel.org>
> >
> > LOLLM points out that if an array element crosses a folio boundary,
> > xfile_get_folio returns a NULL folio pointer. If this happens,
> > si->folio is also set to NULL, and calling folio_pos/folio_address will
> > just crash the kernel. Teach this function to handle this condition by
> > falling back to reading the array element into scratchpad memory.
> >
> > Cc: <stable@vger.kernel.org> # v6.6
> > Fixes: cf36f4f64c2d4e ("xfs: cache pages used for xfarray quicksort convergence")
> > Signed-off-by: "Darrick J. Wong" <djwong@kernel.org>
> > Assisted-by: LOLLM # finding obvious bugs
> > ---
> > fs/xfs/scrub/xfarray.c | 18 ++++++++++--------
> > 1 file changed, 10 insertions(+), 8 deletions(-)
> >
> >
> > diff --git a/fs/xfs/scrub/xfarray.c b/fs/xfs/scrub/xfarray.c
> > index 2ce24bfe4c0fab..30a58e9d4378e4 100644
> > --- a/fs/xfs/scrub/xfarray.c
> > +++ b/fs/xfs/scrub/xfarray.c
> > @@ -830,22 +830,24 @@ xfarray_sort_scan(
> > return PTR_ERR(folio);
> > si->folio = folio;
> >
> > - si->first_folio_idx = xfarray_idx(si->array,
> > - folio_pos(si->folio) + si->array->obj_size - 1);
> > + if (si->folio) {
> > + si->first_folio_idx = xfarray_idx(si->array,
> > + folio_pos(si->folio) + si->array->obj_size - 1);
>
> Overly long line.
>
> > + if (xfarray_pos(si->array, si->last_folio_idx + 1) > next_pos)
>
> Another one.
>
> > + if (!si->folio || idx < si->first_folio_idx || idx > si->last_folio_idx) {
>
> And one more.
On second glance, I think a cleaner way to fix this is to move the logic
that loads the folio, computes the new {first,last}_folio_idx, and
validates them into a new helper:
static int
xfarray_sort_load_folio(
struct xfarray_sortinfo *si,
xfarray_idx_t idx,
loff_t idx_pos)
{
struct folio *folio;
loff_t next_pos;
folio = xfile_get_folio(si->array->xfile, idx_pos, si->array->obj_size,
XFILE_ALLOC);
if (IS_ERR(folio))
return PTR_ERR(folio);
si->folio = folio;
/* No folio? Get the caller to read into the scratchpad. */
if (!si->folio)
return 0;
si->first_folio_idx = xfarray_idx(si->array,
folio_pos(si->folio) + si->array->obj_size - 1);
next_pos = folio_next_pos(si->folio);
si->last_folio_idx = xfarray_idx(si->array, next_pos - 1);
if (xfarray_pos(si->array, si->last_folio_idx + 1) > next_pos)
si->last_folio_idx--;
/*
* If this folio still doesn't cover the desired element, it must cross
* a folio boundary. Get the caller to read into the scratchpad.
*/
if (idx < si->first_folio_idx || idx > si->last_folio_idx) {
xfarray_sort_scan_done(si);
return 0;
}
trace_xfarray_sort_scan(si, idx);
return 0;
}
--D
next prev parent reply other threads:[~2026-09-22 17:53 UTC|newest]
Thread overview: 43+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-21 6:13 [PATCHSET] xfs: LLM-inspired bug fixes, part 16 Darrick J. Wong
2026-09-21 6:15 ` [PATCH 01/14] xfs: fix missing xfs_qm_adjust_dqlimits call in quotacheck repair Darrick J. Wong
2026-09-22 5:14 ` Christoph Hellwig
2026-09-21 6:15 ` [PATCH 02/14] xfs: online quotacheck must dirty dquot if enforcement adjustments needed Darrick J. Wong
2026-09-22 5:14 ` Christoph Hellwig
2026-09-22 18:02 ` Darrick J. Wong
2026-09-21 6:15 ` [PATCH 03/14] xfs: fix buffer overruns in xfs_ioc_attr_list Darrick J. Wong
2026-09-22 5:15 ` Christoph Hellwig
2026-09-22 17:31 ` Darrick J. Wong
2026-09-21 6:16 ` [PATCH 04/14] xfs: clean up after failed metafile relinking Darrick J. Wong
2026-09-22 5:17 ` Christoph Hellwig
2026-09-22 17:33 ` Darrick J. Wong
2026-09-21 6:16 ` [PATCH 05/14] xfs: pass xfs_trans_resv object to reservation calculation helpers Darrick J. Wong
2026-09-22 5:18 ` Christoph Hellwig
2026-09-22 17:29 ` Darrick J. Wong
2026-09-22 17:34 ` Darrick J. Wong
2026-09-21 6:16 ` [PATCH 06/14] xfs: fix xfs_rename_space_res for non-pptr filesystems Darrick J. Wong
2026-09-22 5:20 ` Christoph Hellwig
2026-09-22 17:36 ` Darrick J. Wong
2026-09-21 6:16 ` [PATCH 07/14] xfs: fix ondisk symlink target validation in xrep_dinode_check_dfork Darrick J. Wong
2026-09-22 5:20 ` Christoph Hellwig
2026-09-22 20:42 ` Dave Chinner
2026-09-21 6:17 ` [PATCH 08/14] xfs: fix maximum atomic cow length computation Darrick J. Wong
2026-09-22 5:21 ` Christoph Hellwig
2026-09-22 6:53 ` Darrick J. Wong
2026-09-21 6:17 ` [PATCH 09/14] xfs: add missing healthmon trace strings Darrick J. Wong
2026-09-22 5:21 ` Christoph Hellwig
2026-09-21 6:17 ` [PATCH 10/14] xfarray: don't crash when sorting if array element crosses a folio Darrick J. Wong
2026-09-22 5:22 ` Christoph Hellwig
2026-09-22 17:53 ` Darrick J. Wong [this message]
2026-09-23 4:39 ` Christoph Hellwig
2026-09-21 6:17 ` [PATCH 11/14] xfarray: don't allow users to unset in the middle of an array Darrick J. Wong
2026-09-22 5:23 ` Christoph Hellwig
2026-09-22 6:47 ` Darrick J. Wong
2026-09-22 18:14 ` Darrick J. Wong
2026-09-21 6:18 ` [PATCH 12/14] xfs: don't allow sorting sparse arrays Darrick J. Wong
2026-09-22 5:24 ` Christoph Hellwig
2026-09-22 18:07 ` Darrick J. Wong
2026-09-21 6:18 ` [PATCH 13/14] xfs: simply the free space btree repair code Darrick J. Wong
2026-09-22 5:24 ` Christoph Hellwig
2026-09-21 6:18 ` [PATCH 14/14] xfarray: warn against sorting arrays with identical elements Darrick J. Wong
2026-09-22 5:25 ` Christoph Hellwig
2026-09-22 18:10 ` Darrick J. Wong
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260922175313.GW2705364@frogsfrogsfrogs \
--to=djwong@kernel.org \
--cc=cem@kernel.org \
--cc=hch@infradead.org \
--cc=linux-xfs@vger.kernel.org \
--cc=stable@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox