From: Christoph Hellwig <hch@infradead.org>
To: "Darrick J. Wong" <djwong@kernel.org>
Cc: cem@kernel.org, stable@vger.kernel.org, linux-xfs@vger.kernel.org
Subject: Re: [PATCH 10/14] xfarray: don't crash when sorting if array element crosses a folio
Date: Mon, 21 Sep 2026 22:22:38 -0700 [thread overview]
Message-ID: <arIQntfRrNKGHyoF@infradead.org> (raw)
In-Reply-To: <178996120763.181988.2563798655569721557.stgit@frogsfrogsfrogs>
On Sun, Sep 20, 2026 at 11:17:35PM -0700, Darrick J. Wong wrote:
> From: Darrick J. Wong <djwong@kernel.org>
>
> LOLLM points out that if an array element crosses a folio boundary,
> xfile_get_folio returns a NULL folio pointer. If this happens,
> si->folio is also set to NULL, and calling folio_pos/folio_address will
> just crash the kernel. Teach this function to handle this condition by
> falling back to reading the array element into scratchpad memory.
>
> Cc: <stable@vger.kernel.org> # v6.6
> Fixes: cf36f4f64c2d4e ("xfs: cache pages used for xfarray quicksort convergence")
> Signed-off-by: "Darrick J. Wong" <djwong@kernel.org>
> Assisted-by: LOLLM # finding obvious bugs
> ---
> fs/xfs/scrub/xfarray.c | 18 ++++++++++--------
> 1 file changed, 10 insertions(+), 8 deletions(-)
>
>
> diff --git a/fs/xfs/scrub/xfarray.c b/fs/xfs/scrub/xfarray.c
> index 2ce24bfe4c0fab..30a58e9d4378e4 100644
> --- a/fs/xfs/scrub/xfarray.c
> +++ b/fs/xfs/scrub/xfarray.c
> @@ -830,22 +830,24 @@ xfarray_sort_scan(
> return PTR_ERR(folio);
> si->folio = folio;
>
> - si->first_folio_idx = xfarray_idx(si->array,
> - folio_pos(si->folio) + si->array->obj_size - 1);
> + if (si->folio) {
> + si->first_folio_idx = xfarray_idx(si->array,
> + folio_pos(si->folio) + si->array->obj_size - 1);
Overly long line.
> + if (xfarray_pos(si->array, si->last_folio_idx + 1) > next_pos)
Another one.
> + if (!si->folio || idx < si->first_folio_idx || idx > si->last_folio_idx) {
And one more.
next prev parent reply other threads:[~2026-09-22 5:22 UTC|newest]
Thread overview: 43+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-21 6:13 [PATCHSET] xfs: LLM-inspired bug fixes, part 16 Darrick J. Wong
2026-09-21 6:15 ` [PATCH 01/14] xfs: fix missing xfs_qm_adjust_dqlimits call in quotacheck repair Darrick J. Wong
2026-09-22 5:14 ` Christoph Hellwig
2026-09-21 6:15 ` [PATCH 02/14] xfs: online quotacheck must dirty dquot if enforcement adjustments needed Darrick J. Wong
2026-09-22 5:14 ` Christoph Hellwig
2026-09-22 18:02 ` Darrick J. Wong
2026-09-21 6:15 ` [PATCH 03/14] xfs: fix buffer overruns in xfs_ioc_attr_list Darrick J. Wong
2026-09-22 5:15 ` Christoph Hellwig
2026-09-22 17:31 ` Darrick J. Wong
2026-09-21 6:16 ` [PATCH 04/14] xfs: clean up after failed metafile relinking Darrick J. Wong
2026-09-22 5:17 ` Christoph Hellwig
2026-09-22 17:33 ` Darrick J. Wong
2026-09-21 6:16 ` [PATCH 05/14] xfs: pass xfs_trans_resv object to reservation calculation helpers Darrick J. Wong
2026-09-22 5:18 ` Christoph Hellwig
2026-09-22 17:29 ` Darrick J. Wong
2026-09-22 17:34 ` Darrick J. Wong
2026-09-21 6:16 ` [PATCH 06/14] xfs: fix xfs_rename_space_res for non-pptr filesystems Darrick J. Wong
2026-09-22 5:20 ` Christoph Hellwig
2026-09-22 17:36 ` Darrick J. Wong
2026-09-21 6:16 ` [PATCH 07/14] xfs: fix ondisk symlink target validation in xrep_dinode_check_dfork Darrick J. Wong
2026-09-22 5:20 ` Christoph Hellwig
2026-09-22 20:42 ` Dave Chinner
2026-09-21 6:17 ` [PATCH 08/14] xfs: fix maximum atomic cow length computation Darrick J. Wong
2026-09-22 5:21 ` Christoph Hellwig
2026-09-22 6:53 ` Darrick J. Wong
2026-09-21 6:17 ` [PATCH 09/14] xfs: add missing healthmon trace strings Darrick J. Wong
2026-09-22 5:21 ` Christoph Hellwig
2026-09-21 6:17 ` [PATCH 10/14] xfarray: don't crash when sorting if array element crosses a folio Darrick J. Wong
2026-09-22 5:22 ` Christoph Hellwig [this message]
2026-09-22 17:53 ` Darrick J. Wong
2026-09-23 4:39 ` Christoph Hellwig
2026-09-21 6:17 ` [PATCH 11/14] xfarray: don't allow users to unset in the middle of an array Darrick J. Wong
2026-09-22 5:23 ` Christoph Hellwig
2026-09-22 6:47 ` Darrick J. Wong
2026-09-22 18:14 ` Darrick J. Wong
2026-09-21 6:18 ` [PATCH 12/14] xfs: don't allow sorting sparse arrays Darrick J. Wong
2026-09-22 5:24 ` Christoph Hellwig
2026-09-22 18:07 ` Darrick J. Wong
2026-09-21 6:18 ` [PATCH 13/14] xfs: simply the free space btree repair code Darrick J. Wong
2026-09-22 5:24 ` Christoph Hellwig
2026-09-21 6:18 ` [PATCH 14/14] xfarray: warn against sorting arrays with identical elements Darrick J. Wong
2026-09-22 5:25 ` Christoph Hellwig
2026-09-22 18:10 ` Darrick J. Wong
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=arIQntfRrNKGHyoF@infradead.org \
--to=hch@infradead.org \
--cc=cem@kernel.org \
--cc=djwong@kernel.org \
--cc=linux-xfs@vger.kernel.org \
--cc=stable@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox