From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org X-Spam-Level: X-Spam-Status: No, score=-4.0 required=3.0 tests=BAYES_00,MAILING_LIST_MULTI, SPF_HELO_NONE,SPF_PASS,URIBL_BLOCKED autolearn=no autolearn_force=no version=3.4.0 Received: from mail.kernel.org (mail.kernel.org [198.145.29.99]) by smtp.lore.kernel.org (Postfix) with ESMTP id B1FFAC48BD1 for ; Thu, 10 Jun 2021 12:37:38 +0000 (UTC) Received: from vger.kernel.org (vger.kernel.org [23.128.96.18]) by mail.kernel.org (Postfix) with ESMTP id 9601C61403 for ; Thu, 10 Jun 2021 12:37:38 +0000 (UTC) Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S230297AbhFJMjd (ORCPT ); Thu, 10 Jun 2021 08:39:33 -0400 Received: from mail.kernel.org ([198.145.29.99]:58338 "EHLO mail.kernel.org" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S230267AbhFJMjc (ORCPT ); Thu, 10 Jun 2021 08:39:32 -0400 Received: from disco-boy.misterjones.org (disco-boy.misterjones.org [51.254.78.96]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by mail.kernel.org (Postfix) with ESMTPSA id 5148B613DF; Thu, 10 Jun 2021 12:37:36 +0000 (UTC) Received: from 78.163-31-62.static.virginmediabusiness.co.uk ([62.31.163.78] helo=why.misterjones.org) by disco-boy.misterjones.org with esmtpsa (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.94.2) (envelope-from ) id 1lrJwD-006jLK-Um; Thu, 10 Jun 2021 13:37:34 +0100 Date: Thu, 10 Jun 2021 13:37:33 +0100 Message-ID: <87im2lrj3m.wl-maz@kernel.org> From: Marc Zyngier To: John Garry Cc: Thomas Gleixner , "linux-kernel@vger.kernel.org" Subject: Re: [report] use-after-free in __irq_resolve_mapping() In-Reply-To: <6715098c-6845-c4a1-31ca-42101350c80a@huawei.com> References: <6715098c-6845-c4a1-31ca-42101350c80a@huawei.com> User-Agent: Wanderlust/2.15.9 (Almost Unreal) SEMI-EPG/1.14.7 (Harue) FLIM-LB/1.14.9 (=?UTF-8?B?R29qxY0=?=) APEL-LB/10.8 EasyPG/1.0.0 Emacs/27.1 (x86_64-pc-linux-gnu) MULE/6.0 (HANACHIRUSATO) MIME-Version: 1.0 (generated by SEMI-EPG 1.14.7 - "Harue") Content-Type: text/plain; charset=US-ASCII X-SA-Exim-Connect-IP: 62.31.163.78 X-SA-Exim-Rcpt-To: john.garry@huawei.com, tglx@linutronix.de, linux-kernel@vger.kernel.org X-SA-Exim-Mail-From: maz@kernel.org X-SA-Exim-Scanned: No (on disco-boy.misterjones.org); SAEximRunCond expanded to false Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org On Wed, 09 Jun 2021 12:59:26 +0100, John Garry wrote: > > JFYI, on -next 20210608, I find this on my arm64 D06 and D05: [...] Funny what happens when you blindly replace radix_tree_delete() with radix_tree_insert(NULL) and fail to realise that no, they aren't equivalent... I'll pick a brown paper bag from the stack. I'll run some more tests on some of the bigger iron before rebuilding irq/irqchip-next, but it certainly looks less broken now. Thanks again, M. -- Without deviation from the norm, progress is not possible.