From: syzbot <syzbot+df28076a30d726933015@syzkaller.appspotmail.com>
To: linux-kernel@vger.kernel.org, syzkaller-bugs@googlegroups.com
Subject: Forwarded: [PATCH] iommufd: Initialize batch structures in map/unmap paths
Date: Sat, 24 Jan 2026 03:24:53 -0800 [thread overview]
Message-ID: <6974ac05.a00a0220.33ccc7.0005.GAE@google.com> (raw)
In-Reply-To: <69746a86.050a0220.226181.0002.GAE@google.com>
For archival purposes, forwarding an incoming command email to
linux-kernel@vger.kernel.org, syzkaller-bugs@googlegroups.com.
***
Subject: [PATCH] iommufd: Initialize batch structures in map/unmap paths
Author: kartikey406@gmail.com
#syz test: git://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git master
KMSAN reported uninitialized values in batch processing for both the
map and unmap paths:
1. In iopt_area_fill_domains(), struct pfn_reader pfns was used
uninitialized, causing warnings in batch_add_pfn_num() when
accessing batch->npfns[] and batch->pfns[] arrays.
2. In __iopt_area_unfill_domain(), struct pfn_batch batch was used
uninitialized, causing warnings in batch_from_domain() when
accessing the same arrays.
Although some initialization functions are called on these structures,
they do not initialize all fields, leaving arrays and padding bytes
uninitialized.
Initialize both structures to zero to ensure all fields start in a
known state.
Reported-by: syzbot+df28076a30d726933015@syzkaller.appspotmail.com
Signed-off-by: Deepanshu Kartikey <kartikey406@gmail.com>
---
drivers/iommu/iommufd/pages.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/drivers/iommu/iommufd/pages.c b/drivers/iommu/iommufd/pages.c
index dbe51ecb9a20..8c7681192a07 100644
--- a/drivers/iommu/iommufd/pages.c
+++ b/drivers/iommu/iommufd/pages.c
@@ -1735,7 +1735,7 @@ static void __iopt_area_unfill_domain(struct iopt_area *area,
unsigned long start_index = iopt_area_index(area);
unsigned long unmapped_end_index = start_index;
u64 backup[BATCH_BACKUP_SIZE];
- struct pfn_batch batch;
+ struct pfn_batch batch = {};
lockdep_assert_held(&pages->mutex);
@@ -1897,7 +1897,7 @@ int iopt_area_fill_domains(struct iopt_area *area, struct iopt_pages *pages)
unsigned long done_all_end_index;
struct iommu_domain *domain;
unsigned long unmap_index;
- struct pfn_reader pfns;
+ struct pfn_reader pfns = {};
unsigned long index;
int rc;
--
2.43.0
next prev parent reply other threads:[~2026-01-24 11:24 UTC|newest]
Thread overview: 4+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-01-24 6:45 [syzbot] [iommu?] KMSAN: uninit-value in pfn_reader_next syzbot
2026-01-24 9:07 ` Forwarded: [PATCH] iommufd: Initialize pfn_reader in iopt_area_fill_domains() syzbot
2026-01-24 11:24 ` syzbot [this message]
2026-01-24 12:46 ` Forwarded: [PATCH] iommufd: Initialize batch->kind in batch_clear() syzbot
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=6974ac05.a00a0220.33ccc7.0005.GAE@google.com \
--to=syzbot+df28076a30d726933015@syzkaller.appspotmail.com \
--cc=linux-kernel@vger.kernel.org \
--cc=syzkaller-bugs@googlegroups.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox