From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-wr1-f46.google.com (mail-wr1-f46.google.com [209.85.221.46]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 4C16D3502BB for ; Tue, 13 Jan 2026 09:42:30 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.221.46 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1768297351; cv=none; b=JmpIg6y8dZ490iXxw4FRIKqvWkGWEVYQyftWd627LZ5ZqiZcIC4D4H5i7JSR1TqXC/9L+bUCdm23caIt9hpEU113QDcHJMtYyaaz3Z0b4UV0AutelNPWKgj8OkEnAQoIwT6MuJvVDZr/GBQhh4+z4/p9/Q3ctKs8AxwKaEM2cIM= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1768297351; c=relaxed/simple; bh=jsTQpeqf//7r5JEUYZk3rsuws1lH6BKGLO8ueWv8/Ak=; h=Date:From:To:Cc:Subject:Message-ID:In-Reply-To:References: MIME-Version:Content-Type; b=TDZzYkMQjx5ZNUvyUOTCNBzSh8Ri9WtnyVeLHJNsHoBK7FFbyHeMu1O/0GxXU8B6hukW6kszzF1HdfpijwTTBm03oI2ZrfK5T2VEaWl8KbQtIA3WcrLX5g6C5yVywnu+tYNzPKX8d4sb1NYHADXWp6HNmFUzhEfCV5F3RT4EcLo= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=AATCChff; arc=none smtp.client-ip=209.85.221.46 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="AATCChff" Received: by mail-wr1-f46.google.com with SMTP id ffacd0b85a97d-4327778df7fso4597678f8f.3 for ; Tue, 13 Jan 2026 01:42:30 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20230601; t=1768297349; x=1768902149; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:subject:cc:to:from:date:from:to:cc:subject:date :message-id:reply-to; bh=qWi0gxImcfe6sPFx7hTgeNf8sv4DbP5sxUz/myXx3jk=; b=AATCChffCjft4duhkcdXSrluLr9HUREMOTCWhpwSLUSCwO3ltkm0pmcL4w1IV0FG3p Ht+0RfeR4pfmGLH4qIUypGB4vCSo9o+PET4FJX9EvaAi/pgt6kuSOUzQnJXIEGCy9k43 Rcv8REBI0/LIxwYk6tDI0y7ok08FToqE03KAIFz8s8b+G2ObtG1DULtJlSlHi/YTYg5v YwqDXnZuyBCT3Gc5no2dngt6g7k+3mduiahF37Cd/3FUOymS6jg2zHCbRw5WGWT6jZEd gvQr5aX2Usg6mx5TVURufHqY8ewpDlRkXYpnJAxh/tqzA3kr01NeI///rJnknfHkpIzK 5UiA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1768297349; x=1768902149; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:subject:cc:to:from:date:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to; bh=qWi0gxImcfe6sPFx7hTgeNf8sv4DbP5sxUz/myXx3jk=; b=gYTkA9uuYzTbGJp+S/m7pCEln66TnVsV+LCMOP+Oletc+8jb3SAc8voBRWbNb0kO5n 7o0lsV4nY0+7ldz1bqx/UL+LXk74mAYUAFYHyGguCoRsB4IuUqKlcnhLpe4d4TVfrO3G yxlkd5k/Yv0bb3Bt+BdjZoRiIM4X62dq5+HqsmWedNgU/FS3vu+pgQDGPJgoG/URXPku 8LlPH7NrU4DVa7bRxFLNsv2YHO/M58SGTnwY7wRvQbOsmALWRcHveT2xkZmb4pIfcKur xHOrdsw8Xh/fGp57n/CHV9/N8wu0lnY4vdaNMq4MX1uPhGsCNZtXT9nYQHaXnz53w09L NTng== X-Gm-Message-State: AOJu0Yylv2DjUzCYwsai8MVL7zLbE9ioHcT8hLp8GyssxdUIjwfb75mN hP6sprduo77miJlPEahmc/QPFoHO9+vK+tVWW17kI4Y6AISByhWOZ7XY X-Gm-Gg: AY/fxX4P/qotBtpdlOJ8b0ZzQLH5wD5nsGvmFwlzINaC4HCfIEsi3b7Musymyjq+80F 5lbdeBz7IKmbtNtK1vQxqcKsAAzT67IyrgPzu1+UNuTFo6UaOfjv/ZGtvy05Ipv/JmCzskivu6p 4MduuFOkEU6SFHdfOkWIhPQBDNg2+yYPmt88NbOvfF0MUB2Qdk/yks1jySpaQ5Y2H5nN9Ao8rI0 RwZQstISkmqnaCjiOlId3XW7+HAFpn+9VBHBdDUP5w2r9WfXIhylKypGFrBhKZPbUvLK5GN7wQu +J62DH1L3FTrk6VRJtRsHYw2wjZZ3Okd9WaIn0VLImWNAX0J456V18Na9s04N1fXaDvFc+o6/Gd YvlEbI8h40X3r4abxpIpcO51rzeGgxSKw0aNIi3FK4Q3X1cSDqZoZhviYtcqbrBDwav+etYngpT 9NcDAwXj35MOJe8pwpvFZ5xXrppJlkyABOXBudl5HfnSBcQOdDQ1WW X-Google-Smtp-Source: AGHT+IGCluKpScy5UmgAEwir80+RNqkqkTWiXHqvvRnvopn9jhUBxHczRPNLOdlhz4XUibpj8zHkVw== X-Received: by 2002:a05:6000:178a:b0:430:f449:5f18 with SMTP id ffacd0b85a97d-432c37644b4mr26662191f8f.46.1768297348421; Tue, 13 Jan 2026 01:42:28 -0800 (PST) Received: from pumpkin (82-69-66-36.dsl.in-addr.zen.co.uk. [82.69.66.36]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-432bd5dfa07sm43196646f8f.25.2026.01.13.01.42.27 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 13 Jan 2026 01:42:28 -0800 (PST) Date: Tue, 13 Jan 2026 09:42:26 +0000 From: David Laight To: Brian Masney Cc: linux-kernel@vger.kernel.org, linux-ext4@vger.kernel.org, linux-fsdevel@vger.kernel.org, linux-mm@kvack.org, Alexander Viro , Andreas Dilger , Christian Brauner , Kees Cook , Miklos Szeredi , OGAWA Hirofumi , Theodore Ts'o Subject: Re: [PATCH 30/44] fs: use min() or umin() instead of min_t() Message-ID: <20260113094226.144973b2@pumpkin> In-Reply-To: References: <20251119224140.8616-1-david.laight.linux@gmail.com> <20251119224140.8616-31-david.laight.linux@gmail.com> X-Mailer: Claws Mail 4.1.1 (GTK 3.24.38; arm-unknown-linux-gnueabihf) Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: quoted-printable On Mon, 12 Jan 2026 16:51:22 -0500 Brian Masney wrote: > Hi David, >=20 > On Wed, Nov 19, 2025 at 10:41:26PM +0000, david.laight.linux@gmail.com wr= ote: > > From: David Laight > >=20 > > min_t(unsigned int, a, b) casts an 'unsigned long' to 'unsigned int'. > > Use min(a, b) instead as it promotes any 'unsigned int' to 'unsigned lo= ng' > > and so cannot discard significant bits. > >=20 > > A couple of places need umin() because of loops like: > > nfolios =3D DIV_ROUND_UP(ret + start, PAGE_SIZE); > >=20 > > for (i =3D 0; i < nfolios; i++) { > > struct folio *folio =3D page_folio(pages[i]); > > ... > > unsigned int len =3D umin(ret, PAGE_SIZE - start); > > ... > > ret -=3D len; > > ... > > } > > where the compiler doesn't track things well enough to know that > > 'ret' is never negative. > >=20 > > The alternate loop: > > for (i =3D 0; ret > 0; i++) { > > struct folio *folio =3D page_folio(pages[i]); > > ... > > unsigned int len =3D min(ret, PAGE_SIZE - start); > > ... > > ret -=3D len; > > ... > > } > > would be equivalent and doesn't need 'nfolios'. > >=20 > > Most of the 'unsigned long' actually come from PAGE_SIZE. > >=20 > > Detected by an extra check added to min_t(). > >=20 > > Signed-off-by: David Laight =20 >=20 > When doing a mips cross compile from an arm64 host > (via ARCH=3Dmips CROSS_COMPILE=3Dmips64-linux-gnu- make), the following > build error occurs in linux-next and goes away when I revert this > commit. I've looked at this one before. I think there is another patch lurking to fix it. > In file included from : = =20 > In function =E2=80=98fuse_wr_pages=E2=80=99, = = =20 > inlined from =E2=80=98fuse_perform_write=E2=80=99 at fs/fuse/file.c:1= 347:27: = =20 > ././include/linux/compiler_types.h:667:45: error: call to =E2=80=98__comp= iletime_assert_405=E2=80=99 declared with attribute error: min(((pos + len= =20 > - 1) >> 12) - (pos >> 12) + 1, max_pages) signedness error = =20 ... > fs/fuse/file.c:1326:16: note: in expansion of macro =E2=80=98min=E2=80=99 > 1326 | return min(((pos + len - 1) >> PAGE_SHIFT) - (pos >> PAGE= _SHIFT) + 1, max_pages); 'len' is 'unsigned long' and the expression is unsigned on 64bit. But 'pos' is s64 so the expression is signed on 32bit. IIRC the final version might have been (equivalent to): len +=3D pos & (PAGE_SIZE - 1); return min(DIV_ROUND_UP(len, PAGE_SIZE), max_pages); which generates much better code as well (no 64bit maths). I don't think len can overflow, read/write are limited to INT_MAX - PAGE_SI= ZE bytes in the syscall interface. David >=20 > This is on a cento-stream-10 host running > gcc version 14.3.1 20250617 (Red Hat 14.3.1-2) (GCC). I didn't look into > this in detail, and I'm not entirely sure what the correct fix here > should be. >=20 > Brian >=20