* Build error with kernel from 2026-08-21
@ 2026-08-21 6:38 Juergen Gross
2026-08-21 7:06 ` Juergen Gross
0 siblings, 1 reply; 15+ messages in thread
From: Juergen Gross @ 2026-08-21 6:38 UTC (permalink / raw)
To: lkml; +Cc: Jiri Kosina, michael.bommarito, longli, decui, wei.liu, haiyangz,
kys
[-- Attachment #1.1.1: Type: text/plain, Size: 3189 bytes --]
Hi,
I'm seeing a build error with today's kernel (allyesconfig on x86, using gcc13):
make[3]: *** [/home/gross/linux/head/scripts/Makefile.build:550: drivers] Error 2
make[1]: Leaving directory '/home/gross/linux/head/jg/build/x86_32-yes'
make[2]: *** [/home/gross/linux/head/Makefile:2193: .] Error 2
make[1]: *** [/home/gross/linux/head/Makefile:248: __sub-make] Error 2
make: *** [Makefile:248: __sub-make] Error 2
[msr]~/linux/head> mk x86_32-yes
make O=jg/build/x86_32-yes CC=gcc-13 PYTHON3=python3.11
make[1]: Entering directory '/home/gross/linux/head/jg/build/x86_32-yes'
CC drivers/hid/hid-hyperv.o
In file included from /home/gross/linux/head/include/linux/string.h:383,
from /home/gross/linux/head/arch/x86/include/asm/page_32.h:18,
from /home/gross/linux/head/arch/x86/include/asm/page.h:14,
from /home/gross/linux/head/arch/x86/include/asm/processor.h:20,
from /home/gross/linux/head/arch/x86/include/asm/timex.h:5,
from /home/gross/linux/head/include/linux/timex.h:67,
from /home/gross/linux/head/include/linux/time32.h:13,
from /home/gross/linux/head/include/linux/time.h:60,
from /home/gross/linux/head/include/linux/stat.h:19,
from /home/gross/linux/head/include/linux/module.h:13,
from /home/gross/linux/head/drivers/hid/hid-hyperv.c:8:
In function ‘fortify_memset_chk’,
inlined from ‘mousevsc_device_info_valid_descriptor’ at
/home/gross/linux/head/drivers/hid/hid-hyperv.c:691:2:
/home/gross/linux/head/include/linux/fortify-string.h:430:25: error: call to
‘__write_overflow_field’ declared with attribute warning: detected write beyond
size of field (1st parameter); maybe use struct_group()? [-Werror=attribute-warning]
430 | __write_overflow_field(p_size_field, size);
| ^~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
In function ‘fortify_memset_chk’,
inlined from ‘mousevsc_device_info_report_desc_oob’ at
/home/gross/linux/head/drivers/hid/hid-hyperv.c:717:2:
/home/gross/linux/head/include/linux/fortify-string.h:430:25: error: call to
‘__write_overflow_field’ declared with attribute warning: detected write beyond
size of field (1st parameter); maybe use struct_group()? [-Werror=attribute-warning]
430 | __write_overflow_field(p_size_field, size);
| ^~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
cc1: all warnings being treated as errors
make[5]: *** [/home/gross/linux/head/scripts/Makefile.build:290:
drivers/hid/hid-hyperv.o] Error 1
make[4]: *** [/home/gross/linux/head/scripts/Makefile.build:550: drivers/hid]
Error 2
make[3]: *** [/home/gross/linux/head/scripts/Makefile.build:550: drivers] Error 2
make[2]: *** [/home/gross/linux/head/Makefile:2193: .] Error 2
make[1]: Leaving directory '/home/gross/linux/head/jg/build/x86_32-yes'
make[1]: *** [/home/gross/linux/head/Makefile:248: __sub-make] Error 2
make: *** [Makefile:248: __sub-make] Error 2
Juergen
[-- Attachment #1.1.2: OpenPGP public key --]
[-- Type: application/pgp-keys, Size: 3743 bytes --]
[-- Attachment #2: OpenPGP digital signature --]
[-- Type: application/pgp-signature, Size: 495 bytes --]
^ permalink raw reply [flat|nested] 15+ messages in thread* Re: Build error with kernel from 2026-08-21 2026-08-21 6:38 Build error with kernel from 2026-08-21 Juergen Gross @ 2026-08-21 7:06 ` Juergen Gross 2026-08-21 8:41 ` Jiri Kosina 0 siblings, 1 reply; 15+ messages in thread From: Juergen Gross @ 2026-08-21 7:06 UTC (permalink / raw) To: lkml; +Cc: Jiri Kosina, michael.bommarito, longli, decui, wei.liu, haiyangz, kys [-- Attachment #1.1.1: Type: text/plain, Size: 3727 bytes --] On 21.08.26 08:38, Juergen Gross wrote: > Hi, > > I'm seeing a build error with today's kernel (allyesconfig on x86, using gcc13): > > make[3]: *** [/home/gross/linux/head/scripts/Makefile.build:550: drivers] Error 2 > make[1]: Leaving directory '/home/gross/linux/head/jg/build/x86_32-yes' > make[2]: *** [/home/gross/linux/head/Makefile:2193: .] Error 2 > make[1]: *** [/home/gross/linux/head/Makefile:248: __sub-make] Error 2 > make: *** [Makefile:248: __sub-make] Error 2 > [msr]~/linux/head> mk x86_32-yes > make O=jg/build/x86_32-yes CC=gcc-13 PYTHON3=python3.11 > make[1]: Entering directory '/home/gross/linux/head/jg/build/x86_32-yes' > CC drivers/hid/hid-hyperv.o > In file included from /home/gross/linux/head/include/linux/string.h:383, > from /home/gross/linux/head/arch/x86/include/asm/page_32.h:18, > from /home/gross/linux/head/arch/x86/include/asm/page.h:14, > from /home/gross/linux/head/arch/x86/include/asm/processor.h:20, > from /home/gross/linux/head/arch/x86/include/asm/timex.h:5, > from /home/gross/linux/head/include/linux/timex.h:67, > from /home/gross/linux/head/include/linux/time32.h:13, > from /home/gross/linux/head/include/linux/time.h:60, > from /home/gross/linux/head/include/linux/stat.h:19, > from /home/gross/linux/head/include/linux/module.h:13, > from /home/gross/linux/head/drivers/hid/hid-hyperv.c:8: > In function ‘fortify_memset_chk’, > inlined from ‘mousevsc_device_info_valid_descriptor’ at /home/gross/linux/ > head/drivers/hid/hid-hyperv.c:691:2: > /home/gross/linux/head/include/linux/fortify-string.h:430:25: error: call to > ‘__write_overflow_field’ declared with attribute warning: detected write beyond > size of field (1st parameter); maybe use struct_group()? [-Werror=attribute- > warning] > 430 | __write_overflow_field(p_size_field, size); > | ^~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ > In function ‘fortify_memset_chk’, > inlined from ‘mousevsc_device_info_report_desc_oob’ at /home/gross/linux/ > head/drivers/hid/hid-hyperv.c:717:2: > /home/gross/linux/head/include/linux/fortify-string.h:430:25: error: call to > ‘__write_overflow_field’ declared with attribute warning: detected write beyond > size of field (1st parameter); maybe use struct_group()? [-Werror=attribute- > warning] > 430 | __write_overflow_field(p_size_field, size); > | ^~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ > cc1: all warnings being treated as errors > make[5]: *** [/home/gross/linux/head/scripts/Makefile.build:290: drivers/hid/ > hid-hyperv.o] Error 1 > make[4]: *** [/home/gross/linux/head/scripts/Makefile.build:550: drivers/hid] > Error 2 > make[3]: *** [/home/gross/linux/head/scripts/Makefile.build:550: drivers] Error 2 > make[2]: *** [/home/gross/linux/head/Makefile:2193: .] Error 2 > make[1]: Leaving directory '/home/gross/linux/head/jg/build/x86_32-yes' > make[1]: *** [/home/gross/linux/head/Makefile:248: __sub-make] Error 2 > make: *** [Makefile:248: __sub-make] Error 2 A git bisect flagged commit 83df7b5fa6735b5084ecd296a0f67208650ba497 to be the problematic patch. Juergen [-- Attachment #1.1.2: OpenPGP public key --] [-- Type: application/pgp-keys, Size: 3743 bytes --] [-- Attachment #2: OpenPGP digital signature --] [-- Type: application/pgp-signature, Size: 495 bytes --] ^ permalink raw reply [flat|nested] 15+ messages in thread
* Re: Build error with kernel from 2026-08-21 2026-08-21 7:06 ` Juergen Gross @ 2026-08-21 8:41 ` Jiri Kosina 2026-08-21 8:51 ` Jürgen Groß 2026-08-21 8:52 ` Jürgen Groß 0 siblings, 2 replies; 15+ messages in thread From: Jiri Kosina @ 2026-08-21 8:41 UTC (permalink / raw) To: Juergen Gross Cc: lkml, michael.bommarito, longli, decui, wei.liu, haiyangz, kys On Fri, 21 Aug 2026, Juergen Gross wrote: > > I'm seeing a build error with today's kernel (allyesconfig on x86, using > > gcc13): > > > > make[3]: *** [/home/gross/linux/head/scripts/Makefile.build:550: drivers] > > Error 2 > > make[1]: Leaving directory '/home/gross/linux/head/jg/build/x86_32-yes' > > make[2]: *** [/home/gross/linux/head/Makefile:2193: .] Error 2 > > make[1]: *** [/home/gross/linux/head/Makefile:248: __sub-make] Error 2 > > make: *** [Makefile:248: __sub-make] Error 2 > > [msr]~/linux/head> mk x86_32-yes > > make O=jg/build/x86_32-yes CC=gcc-13 PYTHON3=python3.11 > > make[1]: Entering directory '/home/gross/linux/head/jg/build/x86_32-yes' > > CC drivers/hid/hid-hyperv.o > > In file included from /home/gross/linux/head/include/linux/string.h:383, > > from > > /home/gross/linux/head/arch/x86/include/asm/page_32.h:18, > > from > > /home/gross/linux/head/arch/x86/include/asm/page.h:14, > > from > > /home/gross/linux/head/arch/x86/include/asm/processor.h:20, > > from > > /home/gross/linux/head/arch/x86/include/asm/timex.h:5, > > from /home/gross/linux/head/include/linux/timex.h:67, > > from /home/gross/linux/head/include/linux/time32.h:13, > > from /home/gross/linux/head/include/linux/time.h:60, > > from /home/gross/linux/head/include/linux/stat.h:19, > > from /home/gross/linux/head/include/linux/module.h:13, > > from /home/gross/linux/head/drivers/hid/hid-hyperv.c:8: > > In function ‘fortify_memset_chk’, > > inlined from ‘mousevsc_device_info_valid_descriptor’ at > > /home/gross/linux/ head/drivers/hid/hid-hyperv.c:691:2: > > /home/gross/linux/head/include/linux/fortify-string.h:430:25: error: call to > > ‘__write_overflow_field’ declared with attribute warning: detected write > > beyond size of field (1st parameter); maybe use struct_group()? > > [-Werror=attribute- warning] > > 430 | __write_overflow_field(p_size_field, size); > > | ^~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ > > In function ‘fortify_memset_chk’, > > inlined from ‘mousevsc_device_info_report_desc_oob’ at > > /home/gross/linux/ head/drivers/hid/hid-hyperv.c:717:2: > > /home/gross/linux/head/include/linux/fortify-string.h:430:25: error: call to > > ‘__write_overflow_field’ declared with attribute warning: detected write > > beyond size of field (1st parameter); maybe use struct_group()? > > [-Werror=attribute- warning] > > 430 | __write_overflow_field(p_size_field, size); > > | ^~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ > > cc1: all warnings being treated as errors > > make[5]: *** [/home/gross/linux/head/scripts/Makefile.build:290: > > drivers/hid/ hid-hyperv.o] Error 1 > > make[4]: *** [/home/gross/linux/head/scripts/Makefile.build:550: > > drivers/hid] Error 2 > > make[3]: *** [/home/gross/linux/head/scripts/Makefile.build:550: drivers] > > Error 2 > > make[2]: *** [/home/gross/linux/head/Makefile:2193: .] Error 2 > > make[1]: Leaving directory '/home/gross/linux/head/jg/build/x86_32-yes' > > make[1]: *** [/home/gross/linux/head/Makefile:248: __sub-make] Error 2 > > make: *** [Makefile:248: __sub-make] Error 2 > > A git bisect flagged commit 83df7b5fa6735b5084ecd296a0f67208650ba497 to be the > problematic patch. Hi, this was reported by syzbot two days ago. I asked it to test a candidate fix [1], but it never responded back. Can you give it a quick shot in your 32bit build environment, please? Thanks. [1] https://lore.kernel.org/all/s6r47sn1-pr1p-8s7r-o164-q27s2o40p9r1@fhfr.pbz/ -- Jiri Kosina SUSE Labs ^ permalink raw reply [flat|nested] 15+ messages in thread
* Re: Build error with kernel from 2026-08-21 2026-08-21 8:41 ` Jiri Kosina @ 2026-08-21 8:51 ` Jürgen Groß 2026-08-21 8:52 ` Jürgen Groß 1 sibling, 0 replies; 15+ messages in thread From: Jürgen Groß @ 2026-08-21 8:51 UTC (permalink / raw) To: Jiri Kosina Cc: lkml, michael.bommarito, longli, decui, wei.liu, haiyangz, kys [-- Attachment #1.1.1: Type: text/plain, Size: 4246 bytes --] On 21.08.26 10:41, Jiri Kosina wrote: > On Fri, 21 Aug 2026, Juergen Gross wrote: > >>> I'm seeing a build error with today's kernel (allyesconfig on x86, using >>> gcc13): >>> >>> make[3]: *** [/home/gross/linux/head/scripts/Makefile.build:550: drivers] >>> Error 2 >>> make[1]: Leaving directory '/home/gross/linux/head/jg/build/x86_32-yes' >>> make[2]: *** [/home/gross/linux/head/Makefile:2193: .] Error 2 >>> make[1]: *** [/home/gross/linux/head/Makefile:248: __sub-make] Error 2 >>> make: *** [Makefile:248: __sub-make] Error 2 >>> [msr]~/linux/head> mk x86_32-yes >>> make O=jg/build/x86_32-yes CC=gcc-13 PYTHON3=python3.11 >>> make[1]: Entering directory '/home/gross/linux/head/jg/build/x86_32-yes' >>> CC drivers/hid/hid-hyperv.o >>> In file included from /home/gross/linux/head/include/linux/string.h:383, >>> from >>> /home/gross/linux/head/arch/x86/include/asm/page_32.h:18, >>> from >>> /home/gross/linux/head/arch/x86/include/asm/page.h:14, >>> from >>> /home/gross/linux/head/arch/x86/include/asm/processor.h:20, >>> from >>> /home/gross/linux/head/arch/x86/include/asm/timex.h:5, >>> from /home/gross/linux/head/include/linux/timex.h:67, >>> from /home/gross/linux/head/include/linux/time32.h:13, >>> from /home/gross/linux/head/include/linux/time.h:60, >>> from /home/gross/linux/head/include/linux/stat.h:19, >>> from /home/gross/linux/head/include/linux/module.h:13, >>> from /home/gross/linux/head/drivers/hid/hid-hyperv.c:8: >>> In function ‘fortify_memset_chk’, >>> inlined from ‘mousevsc_device_info_valid_descriptor’ at >>> /home/gross/linux/ head/drivers/hid/hid-hyperv.c:691:2: >>> /home/gross/linux/head/include/linux/fortify-string.h:430:25: error: call to >>> ‘__write_overflow_field’ declared with attribute warning: detected write >>> beyond size of field (1st parameter); maybe use struct_group()? >>> [-Werror=attribute- warning] >>> 430 | __write_overflow_field(p_size_field, size); >>> | ^~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ >>> In function ‘fortify_memset_chk’, >>> inlined from ‘mousevsc_device_info_report_desc_oob’ at >>> /home/gross/linux/ head/drivers/hid/hid-hyperv.c:717:2: >>> /home/gross/linux/head/include/linux/fortify-string.h:430:25: error: call to >>> ‘__write_overflow_field’ declared with attribute warning: detected write >>> beyond size of field (1st parameter); maybe use struct_group()? >>> [-Werror=attribute- warning] >>> 430 | __write_overflow_field(p_size_field, size); >>> | ^~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ >>> cc1: all warnings being treated as errors >>> make[5]: *** [/home/gross/linux/head/scripts/Makefile.build:290: >>> drivers/hid/ hid-hyperv.o] Error 1 >>> make[4]: *** [/home/gross/linux/head/scripts/Makefile.build:550: >>> drivers/hid] Error 2 >>> make[3]: *** [/home/gross/linux/head/scripts/Makefile.build:550: drivers] >>> Error 2 >>> make[2]: *** [/home/gross/linux/head/Makefile:2193: .] Error 2 >>> make[1]: Leaving directory '/home/gross/linux/head/jg/build/x86_32-yes' >>> make[1]: *** [/home/gross/linux/head/Makefile:248: __sub-make] Error 2 >>> make: *** [Makefile:248: __sub-make] Error 2 >> >> A git bisect flagged commit 83df7b5fa6735b5084ecd296a0f67208650ba497 to be the >> problematic patch. > > Hi, > > this was reported by syzbot two days ago. I asked it to test a candidate > fix [1], but it never responded back. Can you give it a quick shot in your > 32bit build environment, please? > > Thanks. > > [1] https://lore.kernel.org/all/s6r47sn1-pr1p-8s7r-o164-q27s2o40p9r1@fhfr.pbz/ > No, doesn't work. Juergen [-- Attachment #1.1.2: OpenPGP public key --] [-- Type: application/pgp-keys, Size: 3743 bytes --] [-- Attachment #2: OpenPGP digital signature --] [-- Type: application/pgp-signature, Size: 495 bytes --] ^ permalink raw reply [flat|nested] 15+ messages in thread
* Re: Build error with kernel from 2026-08-21 2026-08-21 8:41 ` Jiri Kosina 2026-08-21 8:51 ` Jürgen Groß @ 2026-08-21 8:52 ` Jürgen Groß 2026-08-21 9:24 ` Jiri Kosina 1 sibling, 1 reply; 15+ messages in thread From: Jürgen Groß @ 2026-08-21 8:52 UTC (permalink / raw) To: Jiri Kosina Cc: lkml, michael.bommarito, longli, decui, wei.liu, haiyangz, kys [-- Attachment #1.1.1: Type: text/plain, Size: 4290 bytes --] On 21.08.26 10:41, Jiri Kosina wrote: > On Fri, 21 Aug 2026, Juergen Gross wrote: > >>> I'm seeing a build error with today's kernel (allyesconfig on x86, using >>> gcc13): >>> >>> make[3]: *** [/home/gross/linux/head/scripts/Makefile.build:550: drivers] >>> Error 2 >>> make[1]: Leaving directory '/home/gross/linux/head/jg/build/x86_32-yes' >>> make[2]: *** [/home/gross/linux/head/Makefile:2193: .] Error 2 >>> make[1]: *** [/home/gross/linux/head/Makefile:248: __sub-make] Error 2 >>> make: *** [Makefile:248: __sub-make] Error 2 >>> [msr]~/linux/head> mk x86_32-yes >>> make O=jg/build/x86_32-yes CC=gcc-13 PYTHON3=python3.11 >>> make[1]: Entering directory '/home/gross/linux/head/jg/build/x86_32-yes' >>> CC drivers/hid/hid-hyperv.o >>> In file included from /home/gross/linux/head/include/linux/string.h:383, >>> from >>> /home/gross/linux/head/arch/x86/include/asm/page_32.h:18, >>> from >>> /home/gross/linux/head/arch/x86/include/asm/page.h:14, >>> from >>> /home/gross/linux/head/arch/x86/include/asm/processor.h:20, >>> from >>> /home/gross/linux/head/arch/x86/include/asm/timex.h:5, >>> from /home/gross/linux/head/include/linux/timex.h:67, >>> from /home/gross/linux/head/include/linux/time32.h:13, >>> from /home/gross/linux/head/include/linux/time.h:60, >>> from /home/gross/linux/head/include/linux/stat.h:19, >>> from /home/gross/linux/head/include/linux/module.h:13, >>> from /home/gross/linux/head/drivers/hid/hid-hyperv.c:8: >>> In function ‘fortify_memset_chk’, >>> inlined from ‘mousevsc_device_info_valid_descriptor’ at >>> /home/gross/linux/ head/drivers/hid/hid-hyperv.c:691:2: >>> /home/gross/linux/head/include/linux/fortify-string.h:430:25: error: call to >>> ‘__write_overflow_field’ declared with attribute warning: detected write >>> beyond size of field (1st parameter); maybe use struct_group()? >>> [-Werror=attribute- warning] >>> 430 | __write_overflow_field(p_size_field, size); >>> | ^~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ >>> In function ‘fortify_memset_chk’, >>> inlined from ‘mousevsc_device_info_report_desc_oob’ at >>> /home/gross/linux/ head/drivers/hid/hid-hyperv.c:717:2: >>> /home/gross/linux/head/include/linux/fortify-string.h:430:25: error: call to >>> ‘__write_overflow_field’ declared with attribute warning: detected write >>> beyond size of field (1st parameter); maybe use struct_group()? >>> [-Werror=attribute- warning] >>> 430 | __write_overflow_field(p_size_field, size); >>> | ^~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ >>> cc1: all warnings being treated as errors >>> make[5]: *** [/home/gross/linux/head/scripts/Makefile.build:290: >>> drivers/hid/ hid-hyperv.o] Error 1 >>> make[4]: *** [/home/gross/linux/head/scripts/Makefile.build:550: >>> drivers/hid] Error 2 >>> make[3]: *** [/home/gross/linux/head/scripts/Makefile.build:550: drivers] >>> Error 2 >>> make[2]: *** [/home/gross/linux/head/Makefile:2193: .] Error 2 >>> make[1]: Leaving directory '/home/gross/linux/head/jg/build/x86_32-yes' >>> make[1]: *** [/home/gross/linux/head/Makefile:248: __sub-make] Error 2 >>> make: *** [Makefile:248: __sub-make] Error 2 >> >> A git bisect flagged commit 83df7b5fa6735b5084ecd296a0f67208650ba497 to be the >> problematic patch. > > Hi, > > this was reported by syzbot two days ago. I asked it to test a candidate > fix [1], but it never responded back. Can you give it a quick shot in your > 32bit build environment, please? > > Thanks. > > [1] https://lore.kernel.org/all/s6r47sn1-pr1p-8s7r-o164-q27s2o40p9r1@fhfr.pbz/ > BTW, I'm seeing the build failure in 64-bit environment, too. Juergen [-- Attachment #1.1.2: OpenPGP public key --] [-- Type: application/pgp-keys, Size: 3743 bytes --] [-- Attachment #2: OpenPGP digital signature --] [-- Type: application/pgp-signature, Size: 495 bytes --] ^ permalink raw reply [flat|nested] 15+ messages in thread
* Re: Build error with kernel from 2026-08-21 2026-08-21 8:52 ` Jürgen Groß @ 2026-08-21 9:24 ` Jiri Kosina 2026-08-21 9:35 ` Jiri Kosina 0 siblings, 1 reply; 15+ messages in thread From: Jiri Kosina @ 2026-08-21 9:24 UTC (permalink / raw) To: Jürgen Groß Cc: lkml, michael.bommarito, longli, decui, wei.liu, haiyangz, kys On Fri, 21 Aug 2026, Jürgen Groß wrote: > >>> I'm seeing a build error with today's kernel (allyesconfig on x86, using > >>> gcc13): > >>> > >>> make[3]: *** [/home/gross/linux/head/scripts/Makefile.build:550: drivers] > >>> Error 2 > >>> make[1]: Leaving directory '/home/gross/linux/head/jg/build/x86_32-yes' > >>> make[2]: *** [/home/gross/linux/head/Makefile:2193: .] Error 2 > >>> make[1]: *** [/home/gross/linux/head/Makefile:248: __sub-make] Error 2 > >>> make: *** [Makefile:248: __sub-make] Error 2 > >>> [msr]~/linux/head> mk x86_32-yes > >>> make O=jg/build/x86_32-yes CC=gcc-13 PYTHON3=python3.11 > >>> make[1]: Entering directory '/home/gross/linux/head/jg/build/x86_32-yes' > >>> CC drivers/hid/hid-hyperv.o > >>> In file included from /home/gross/linux/head/include/linux/string.h:383, > >>> from > >>> /home/gross/linux/head/arch/x86/include/asm/page_32.h:18, > >>> from > >>> /home/gross/linux/head/arch/x86/include/asm/page.h:14, > >>> from > >>> /home/gross/linux/head/arch/x86/include/asm/processor.h:20, > >>> from > >>> /home/gross/linux/head/arch/x86/include/asm/timex.h:5, > >>> from /home/gross/linux/head/include/linux/timex.h:67, > >>> from /home/gross/linux/head/include/linux/time32.h:13, > >>> from /home/gross/linux/head/include/linux/time.h:60, > >>> from /home/gross/linux/head/include/linux/stat.h:19, > >>> from /home/gross/linux/head/include/linux/module.h:13, > >>> from /home/gross/linux/head/drivers/hid/hid-hyperv.c:8: > >>> In function ‘fortify_memset_chk’, > >>> inlined from ‘mousevsc_device_info_valid_descriptor’ at > >>> /home/gross/linux/ head/drivers/hid/hid-hyperv.c:691:2: > >>> /home/gross/linux/head/include/linux/fortify-string.h:430:25: error: call > >>> to > >>> ‘__write_overflow_field’ declared with attribute warning: detected write > >>> beyond size of field (1st parameter); maybe use struct_group()? > >>> [-Werror=attribute- warning] > >>> 430 | __write_overflow_field(p_size_field, > >>> size); > >>> | > >>> ^~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ > >>> In function ‘fortify_memset_chk’, > >>> inlined from ‘mousevsc_device_info_report_desc_oob’ at > >>> /home/gross/linux/ head/drivers/hid/hid-hyperv.c:717:2: > >>> /home/gross/linux/head/include/linux/fortify-string.h:430:25: error: call > >>> to > >>> ‘__write_overflow_field’ declared with attribute warning: detected write > >>> beyond size of field (1st parameter); maybe use struct_group()? > >>> [-Werror=attribute- warning] > >>> 430 | __write_overflow_field(p_size_field, > >>> size); > >>> | > >>> ^~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ > >>> cc1: all warnings being treated as errors > >>> make[5]: *** [/home/gross/linux/head/scripts/Makefile.build:290: > >>> drivers/hid/ hid-hyperv.o] Error 1 > >>> make[4]: *** [/home/gross/linux/head/scripts/Makefile.build:550: > >>> drivers/hid] Error 2 > >>> make[3]: *** [/home/gross/linux/head/scripts/Makefile.build:550: drivers] > >>> Error 2 > >>> make[2]: *** [/home/gross/linux/head/Makefile:2193: .] Error 2 > >>> make[1]: Leaving directory '/home/gross/linux/head/jg/build/x86_32-yes' > >>> make[1]: *** [/home/gross/linux/head/Makefile:248: __sub-make] Error 2 > >>> make: *** [Makefile:248: __sub-make] Error 2 > >> > >> A git bisect flagged commit 83df7b5fa6735b5084ecd296a0f67208650ba497 to be > >> the > >> problematic patch. > > > > Hi, > > > > this was reported by syzbot two days ago. I asked it to test a candidate > > fix [1], but it never responded back. Can you give it a quick shot in your > > 32bit build environment, please? > > > > Thanks. > > > > [1] > > https://lore.kernel.org/all/s6r47sn1-pr1p-8s7r-o164-q27s2o40p9r1@fhfr.pbz/ > > > > BTW, I'm seeing the build failure in 64-bit environment, too. Ah, that's actually a different issue than the syzbot-reported one. I'll look into this one after I am done with the other build failure introduced by the same commit. -- Jiri Kosina SUSE Labs ^ permalink raw reply [flat|nested] 15+ messages in thread
* Re: Build error with kernel from 2026-08-21 2026-08-21 9:24 ` Jiri Kosina @ 2026-08-21 9:35 ` Jiri Kosina 2026-08-21 10:13 ` Jürgen Groß 0 siblings, 1 reply; 15+ messages in thread From: Jiri Kosina @ 2026-08-21 9:35 UTC (permalink / raw) To: Jürgen Groß Cc: lkml, michael.bommarito, longli, decui, wei.liu, haiyangz, kys On Fri, 21 Aug 2026, Jiri Kosina wrote: > > >>> make[3]: *** [/home/gross/linux/head/scripts/Makefile.build:550: drivers] > > >>> Error 2 > > >>> make[1]: Leaving directory '/home/gross/linux/head/jg/build/x86_32-yes' > > >>> make[2]: *** [/home/gross/linux/head/Makefile:2193: .] Error 2 > > >>> make[1]: *** [/home/gross/linux/head/Makefile:248: __sub-make] Error 2 > > >>> make: *** [Makefile:248: __sub-make] Error 2 > > >>> [msr]~/linux/head> mk x86_32-yes > > >>> make O=jg/build/x86_32-yes CC=gcc-13 PYTHON3=python3.11 > > >>> make[1]: Entering directory '/home/gross/linux/head/jg/build/x86_32-yes' > > >>> CC drivers/hid/hid-hyperv.o > > >>> In file included from /home/gross/linux/head/include/linux/string.h:383, > > >>> from > > >>> /home/gross/linux/head/arch/x86/include/asm/page_32.h:18, > > >>> from > > >>> /home/gross/linux/head/arch/x86/include/asm/page.h:14, > > >>> from > > >>> /home/gross/linux/head/arch/x86/include/asm/processor.h:20, > > >>> from > > >>> /home/gross/linux/head/arch/x86/include/asm/timex.h:5, > > >>> from /home/gross/linux/head/include/linux/timex.h:67, > > >>> from /home/gross/linux/head/include/linux/time32.h:13, > > >>> from /home/gross/linux/head/include/linux/time.h:60, > > >>> from /home/gross/linux/head/include/linux/stat.h:19, > > >>> from /home/gross/linux/head/include/linux/module.h:13, > > >>> from /home/gross/linux/head/drivers/hid/hid-hyperv.c:8: > > >>> In function ‘fortify_memset_chk’, > > >>> inlined from ‘mousevsc_device_info_valid_descriptor’ at > > >>> /home/gross/linux/ head/drivers/hid/hid-hyperv.c:691:2: > > >>> /home/gross/linux/head/include/linux/fortify-string.h:430:25: error: call > > >>> to > > >>> ‘__write_overflow_field’ declared with attribute warning: detected write > > >>> beyond size of field (1st parameter); maybe use struct_group()? > > >>> [-Werror=attribute- warning] > > >>> 430 | __write_overflow_field(p_size_field, > > >>> size); > > >>> | > > >>> ^~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ > > >>> In function ‘fortify_memset_chk’, > > >>> inlined from ‘mousevsc_device_info_report_desc_oob’ at > > >>> /home/gross/linux/ head/drivers/hid/hid-hyperv.c:717:2: > > >>> /home/gross/linux/head/include/linux/fortify-string.h:430:25: error: call > > >>> to > > >>> ‘__write_overflow_field’ declared with attribute warning: detected write > > >>> beyond size of field (1st parameter); maybe use struct_group()? > > >>> [-Werror=attribute- warning] > > >>> 430 | __write_overflow_field(p_size_field, > > >>> size); > > >>> | > > >>> ^~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ > > >>> cc1: all warnings being treated as errors > > >>> make[5]: *** [/home/gross/linux/head/scripts/Makefile.build:290: > > >>> drivers/hid/ hid-hyperv.o] Error 1 > > >>> make[4]: *** [/home/gross/linux/head/scripts/Makefile.build:550: > > >>> drivers/hid] Error 2 > > >>> make[3]: *** [/home/gross/linux/head/scripts/Makefile.build:550: drivers] > > >>> Error 2 > > >>> make[2]: *** [/home/gross/linux/head/Makefile:2193: .] Error 2 > > >>> make[1]: Leaving directory '/home/gross/linux/head/jg/build/x86_32-yes' > > >>> make[1]: *** [/home/gross/linux/head/Makefile:248: __sub-make] Error 2 > > >>> make: *** [Makefile:248: __sub-make] Error 2 > > >> > > >> A git bisect flagged commit 83df7b5fa6735b5084ecd296a0f67208650ba497 to be > > >> the > > >> problematic patch. > > > > > > Hi, > > > > > > this was reported by syzbot two days ago. I asked it to test a candidate > > > fix [1], but it never responded back. Can you give it a quick shot in your > > > 32bit build environment, please? > > > > > > Thanks. > > > > > > [1] > > > https://lore.kernel.org/all/s6r47sn1-pr1p-8s7r-o164-q27s2o40p9r1@fhfr.pbz/ > > > > > > > BTW, I'm seeing the build failure in 64-bit environment, too. > > Ah, that's actually a different issue than the syzbot-reported one. I'll > look into this one after I am done with the other build failure introduced > by the same commit. Can you please test the one below? Thanks. diff --git a/drivers/hid/hid-hyperv.c b/drivers/hid/hid-hyperv.c index 6579bd19da13..4a10b24da9fa 100644 --- a/drivers/hid/hid-hyperv.c +++ b/drivers/hid/hid-hyperv.c @@ -687,7 +687,7 @@ static void mousevsc_device_info_valid_descriptor(struct kunit *test) info->hid_descriptor.bLength = sizeof(struct hid_descriptor); info->hid_descriptor.rpt_desc.wDescriptorLength = cpu_to_le16(4); - report = ((u8 *)&info->hid_descriptor) + info->hid_descriptor.bLength; + report = (u8 *)info + offsetof(struct synthhid_device_info, hid_descriptor) + info->hid_descriptor.bLength; memset(report, 0x42, 4); mousevsc_on_receive_device_info(input_dev, info, sizeof(*info) + 4); @@ -713,7 +713,7 @@ static void mousevsc_device_info_report_desc_oob(struct kunit *test) info->hid_descriptor.bLength = sizeof(struct hid_descriptor); info->hid_descriptor.rpt_desc.wDescriptorLength = cpu_to_le16(64); - report = ((u8 *)&info->hid_descriptor) + info->hid_descriptor.bLength; + report = (u8 *)info + offsetof(struct synthhid_device_info, hid_descriptor) + info->hid_descriptor.bLength; memset(report, 0x42, 8); mousevsc_on_receive_device_info(input_dev, info, sizeof(*info) + 8); -- Jiri Kosina SUSE Labs ^ permalink raw reply related [flat|nested] 15+ messages in thread
* Re: Build error with kernel from 2026-08-21 2026-08-21 9:35 ` Jiri Kosina @ 2026-08-21 10:13 ` Jürgen Groß 2026-08-21 10:23 ` [PATCH] HID: hyperv: make pointer arithmetics understandable for FORTIFY_SOURCE Jiri Kosina 0 siblings, 1 reply; 15+ messages in thread From: Jürgen Groß @ 2026-08-21 10:13 UTC (permalink / raw) To: Jiri Kosina Cc: lkml, michael.bommarito, longli, decui, wei.liu, haiyangz, kys [-- Attachment #1.1.1: Type: text/plain, Size: 5939 bytes --] On 21.08.26 11:35, Jiri Kosina wrote: > On Fri, 21 Aug 2026, Jiri Kosina wrote: > >>>>>> make[3]: *** [/home/gross/linux/head/scripts/Makefile.build:550: drivers] >>>>>> Error 2 >>>>>> make[1]: Leaving directory '/home/gross/linux/head/jg/build/x86_32-yes' >>>>>> make[2]: *** [/home/gross/linux/head/Makefile:2193: .] Error 2 >>>>>> make[1]: *** [/home/gross/linux/head/Makefile:248: __sub-make] Error 2 >>>>>> make: *** [Makefile:248: __sub-make] Error 2 >>>>>> [msr]~/linux/head> mk x86_32-yes >>>>>> make O=jg/build/x86_32-yes CC=gcc-13 PYTHON3=python3.11 >>>>>> make[1]: Entering directory '/home/gross/linux/head/jg/build/x86_32-yes' >>>>>> CC drivers/hid/hid-hyperv.o >>>>>> In file included from /home/gross/linux/head/include/linux/string.h:383, >>>>>> from >>>>>> /home/gross/linux/head/arch/x86/include/asm/page_32.h:18, >>>>>> from >>>>>> /home/gross/linux/head/arch/x86/include/asm/page.h:14, >>>>>> from >>>>>> /home/gross/linux/head/arch/x86/include/asm/processor.h:20, >>>>>> from >>>>>> /home/gross/linux/head/arch/x86/include/asm/timex.h:5, >>>>>> from /home/gross/linux/head/include/linux/timex.h:67, >>>>>> from /home/gross/linux/head/include/linux/time32.h:13, >>>>>> from /home/gross/linux/head/include/linux/time.h:60, >>>>>> from /home/gross/linux/head/include/linux/stat.h:19, >>>>>> from /home/gross/linux/head/include/linux/module.h:13, >>>>>> from /home/gross/linux/head/drivers/hid/hid-hyperv.c:8: >>>>>> In function ‘fortify_memset_chk’, >>>>>> inlined from ‘mousevsc_device_info_valid_descriptor’ at >>>>>> /home/gross/linux/ head/drivers/hid/hid-hyperv.c:691:2: >>>>>> /home/gross/linux/head/include/linux/fortify-string.h:430:25: error: call >>>>>> to >>>>>> ‘__write_overflow_field’ declared with attribute warning: detected write >>>>>> beyond size of field (1st parameter); maybe use struct_group()? >>>>>> [-Werror=attribute- warning] >>>>>> 430 | __write_overflow_field(p_size_field, >>>>>> size); >>>>>> | >>>>>> ^~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ >>>>>> In function ‘fortify_memset_chk’, >>>>>> inlined from ‘mousevsc_device_info_report_desc_oob’ at >>>>>> /home/gross/linux/ head/drivers/hid/hid-hyperv.c:717:2: >>>>>> /home/gross/linux/head/include/linux/fortify-string.h:430:25: error: call >>>>>> to >>>>>> ‘__write_overflow_field’ declared with attribute warning: detected write >>>>>> beyond size of field (1st parameter); maybe use struct_group()? >>>>>> [-Werror=attribute- warning] >>>>>> 430 | __write_overflow_field(p_size_field, >>>>>> size); >>>>>> | >>>>>> ^~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ >>>>>> cc1: all warnings being treated as errors >>>>>> make[5]: *** [/home/gross/linux/head/scripts/Makefile.build:290: >>>>>> drivers/hid/ hid-hyperv.o] Error 1 >>>>>> make[4]: *** [/home/gross/linux/head/scripts/Makefile.build:550: >>>>>> drivers/hid] Error 2 >>>>>> make[3]: *** [/home/gross/linux/head/scripts/Makefile.build:550: drivers] >>>>>> Error 2 >>>>>> make[2]: *** [/home/gross/linux/head/Makefile:2193: .] Error 2 >>>>>> make[1]: Leaving directory '/home/gross/linux/head/jg/build/x86_32-yes' >>>>>> make[1]: *** [/home/gross/linux/head/Makefile:248: __sub-make] Error 2 >>>>>> make: *** [Makefile:248: __sub-make] Error 2 >>>>> >>>>> A git bisect flagged commit 83df7b5fa6735b5084ecd296a0f67208650ba497 to be >>>>> the >>>>> problematic patch. >>>> >>>> Hi, >>>> >>>> this was reported by syzbot two days ago. I asked it to test a candidate >>>> fix [1], but it never responded back. Can you give it a quick shot in your >>>> 32bit build environment, please? >>>> >>>> Thanks. >>>> >>>> [1] >>>> https://lore.kernel.org/all/s6r47sn1-pr1p-8s7r-o164-q27s2o40p9r1@fhfr.pbz/ >>>> >>> >>> BTW, I'm seeing the build failure in 64-bit environment, too. >> >> Ah, that's actually a different issue than the syzbot-reported one. I'll >> look into this one after I am done with the other build failure introduced >> by the same commit. > > Can you please test the one below? Thanks. > > diff --git a/drivers/hid/hid-hyperv.c b/drivers/hid/hid-hyperv.c > index 6579bd19da13..4a10b24da9fa 100644 > --- a/drivers/hid/hid-hyperv.c > +++ b/drivers/hid/hid-hyperv.c > @@ -687,7 +687,7 @@ static void mousevsc_device_info_valid_descriptor(struct kunit *test) > > info->hid_descriptor.bLength = sizeof(struct hid_descriptor); > info->hid_descriptor.rpt_desc.wDescriptorLength = cpu_to_le16(4); > - report = ((u8 *)&info->hid_descriptor) + info->hid_descriptor.bLength; > + report = (u8 *)info + offsetof(struct synthhid_device_info, hid_descriptor) + info->hid_descriptor.bLength; > memset(report, 0x42, 4); > > mousevsc_on_receive_device_info(input_dev, info, sizeof(*info) + 4); > @@ -713,7 +713,7 @@ static void mousevsc_device_info_report_desc_oob(struct kunit *test) > > info->hid_descriptor.bLength = sizeof(struct hid_descriptor); > info->hid_descriptor.rpt_desc.wDescriptorLength = cpu_to_le16(64); > - report = ((u8 *)&info->hid_descriptor) + info->hid_descriptor.bLength; > + report = (u8 *)info + offsetof(struct synthhid_device_info, hid_descriptor) + info->hid_descriptor.bLength; > memset(report, 0x42, 8); > > mousevsc_on_receive_device_info(input_dev, info, sizeof(*info) + 8); > Yes, this is fixing the issue I'm seeing. Juergen [-- Attachment #1.1.2: OpenPGP public key --] [-- Type: application/pgp-keys, Size: 3743 bytes --] [-- Attachment #2: OpenPGP digital signature --] [-- Type: application/pgp-signature, Size: 495 bytes --] ^ permalink raw reply [flat|nested] 15+ messages in thread
* [PATCH] HID: hyperv: make pointer arithmetics understandable for FORTIFY_SOURCE 2026-08-21 10:13 ` Jürgen Groß @ 2026-08-21 10:23 ` Jiri Kosina 2026-08-21 11:16 ` Jürgen Groß 2026-08-21 13:18 ` Benjamin Tissoires 0 siblings, 2 replies; 15+ messages in thread From: Jiri Kosina @ 2026-08-21 10:23 UTC (permalink / raw) To: Jürgen Groß Cc: lkml, michael.bommarito, longli, decui, wei.liu, haiyangz, kys, Benjamin Tissoires From: Jiri Kosina <jkosina@suse.com> Commit 83df7b5fa6735b5084ecd2 ("HID: hyperv: add KUnit coverage for device info bounds") introduced this piece of code report = ((u8 *)&info->hid_descriptor) + info->hid_descriptor.bLength; memset(report, 0x42, 4); to populate the report descriptor, making use of the fact that the report. &info->hid_descriptor points to a struct hid_descriptor (which is a fixed-size struct) GCC's FORTIFY_SOURCE infer the object size from that specific struct field rather than the outer dynamically allocated info buffer. As a result, writing past sizeof(struct hid_descriptor) triggers the __write_overflow_field warning. Calculate the pointer offset using info directly, so the compiler evaluates the memory bounds against the allocated flexible layout of struct synthhid_device_info instead of the nested struct. Fixes: 83df7b5fa6735b5084ecd2 ("HID: hyperv: add KUnit coverage for device info bounds") Reported-by: Jürgen Groß <jgross@suse.com> Signed-off-by: Jiri Kosina <jkosina@suse.com> --- drivers/hid/hid-hyperv.c | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/drivers/hid/hid-hyperv.c b/drivers/hid/hid-hyperv.c index 6579bd19da13..4a10b24da9fa 100644 --- a/drivers/hid/hid-hyperv.c +++ b/drivers/hid/hid-hyperv.c @@ -687,7 +687,7 @@ static void mousevsc_device_info_valid_descriptor(struct kunit *test) info->hid_descriptor.bLength = sizeof(struct hid_descriptor); info->hid_descriptor.rpt_desc.wDescriptorLength = cpu_to_le16(4); - report = ((u8 *)&info->hid_descriptor) + info->hid_descriptor.bLength; + report = (u8 *)info + offsetof(struct synthhid_device_info, hid_descriptor) + info->hid_descriptor.bLength; memset(report, 0x42, 4); mousevsc_on_receive_device_info(input_dev, info, sizeof(*info) + 4); @@ -713,7 +713,7 @@ static void mousevsc_device_info_report_desc_oob(struct kunit *test) info->hid_descriptor.bLength = sizeof(struct hid_descriptor); info->hid_descriptor.rpt_desc.wDescriptorLength = cpu_to_le16(64); - report = ((u8 *)&info->hid_descriptor) + info->hid_descriptor.bLength; + report = (u8 *)info + offsetof(struct synthhid_device_info, hid_descriptor) + info->hid_descriptor.bLength; memset(report, 0x42, 8); mousevsc_on_receive_device_info(input_dev, info, sizeof(*info) + 8); -- Jiri Kosina SUSE Labs ^ permalink raw reply related [flat|nested] 15+ messages in thread
* Re: [PATCH] HID: hyperv: make pointer arithmetics understandable for FORTIFY_SOURCE 2026-08-21 10:23 ` [PATCH] HID: hyperv: make pointer arithmetics understandable for FORTIFY_SOURCE Jiri Kosina @ 2026-08-21 11:16 ` Jürgen Groß 2026-08-21 13:18 ` Benjamin Tissoires 1 sibling, 0 replies; 15+ messages in thread From: Jürgen Groß @ 2026-08-21 11:16 UTC (permalink / raw) To: Jiri Kosina Cc: lkml, michael.bommarito, longli, decui, wei.liu, haiyangz, kys, Benjamin Tissoires [-- Attachment #1.1.1: Type: text/plain, Size: 1188 bytes --] On 21.08.26 12:23, Jiri Kosina wrote: > From: Jiri Kosina <jkosina@suse.com> > > Commit 83df7b5fa6735b5084ecd2 ("HID: hyperv: add KUnit coverage for device info > bounds") introduced this piece of code > > report = ((u8 *)&info->hid_descriptor) + info->hid_descriptor.bLength; > memset(report, 0x42, 4); > > to populate the report descriptor, making use of the fact that the report. > &info->hid_descriptor points to a struct hid_descriptor (which is a fixed-size struct) > GCC's FORTIFY_SOURCE infer the object size from that specific struct field rather than the > outer dynamically allocated info buffer. As a result, writing past sizeof(struct hid_descriptor) > triggers the __write_overflow_field warning. > > Calculate the pointer offset using info directly, so the compiler evaluates the > memory bounds against the allocated flexible layout of struct > synthhid_device_info instead of the nested struct. > > Fixes: 83df7b5fa6735b5084ecd2 ("HID: hyperv: add KUnit coverage for device info bounds") > Reported-by: Jürgen Groß <jgross@suse.com> > Signed-off-by: Jiri Kosina <jkosina@suse.com> Tested-by: Jürgen Groß <jgross@suse.com> Jürgen [-- Attachment #1.1.2: OpenPGP public key --] [-- Type: application/pgp-keys, Size: 3743 bytes --] [-- Attachment #2: OpenPGP digital signature --] [-- Type: application/pgp-signature, Size: 495 bytes --] ^ permalink raw reply [flat|nested] 15+ messages in thread
* Re: [PATCH] HID: hyperv: make pointer arithmetics understandable for FORTIFY_SOURCE 2026-08-21 10:23 ` [PATCH] HID: hyperv: make pointer arithmetics understandable for FORTIFY_SOURCE Jiri Kosina 2026-08-21 11:16 ` Jürgen Groß @ 2026-08-21 13:18 ` Benjamin Tissoires 2026-08-21 13:39 ` [PATCH v2] " Jiri Kosina 1 sibling, 1 reply; 15+ messages in thread From: Benjamin Tissoires @ 2026-08-21 13:18 UTC (permalink / raw) To: Jiri Kosina Cc: Jürgen Groß, lkml, michael.bommarito, longli, decui, wei.liu, haiyangz, kys On Aug 21 2026, Jiri Kosina wrote: > From: Jiri Kosina <jkosina@suse.com> > > Commit 83df7b5fa6735b5084ecd2 ("HID: hyperv: add KUnit coverage for device info > bounds") introduced this piece of code > > report = ((u8 *)&info->hid_descriptor) + info->hid_descriptor.bLength; > memset(report, 0x42, 4); > > to populate the report descriptor, making use of the fact that the report. > &info->hid_descriptor points to a struct hid_descriptor (which is a fixed-size struct) > GCC's FORTIFY_SOURCE infer the object size from that specific struct field rather than the > outer dynamically allocated info buffer. As a result, writing past sizeof(struct hid_descriptor) > triggers the __write_overflow_field warning. > > Calculate the pointer offset using info directly, so the compiler evaluates the > memory bounds against the allocated flexible layout of struct > synthhid_device_info instead of the nested struct. > > Fixes: 83df7b5fa6735b5084ecd2 ("HID: hyperv: add KUnit coverage for device info bounds") > Reported-by: Jürgen Groß <jgross@suse.com> > Signed-off-by: Jiri Kosina <jkosina@suse.com> > --- > drivers/hid/hid-hyperv.c | 4 ++-- > 1 file changed, 2 insertions(+), 2 deletions(-) > > diff --git a/drivers/hid/hid-hyperv.c b/drivers/hid/hid-hyperv.c > index 6579bd19da13..4a10b24da9fa 100644 > --- a/drivers/hid/hid-hyperv.c > +++ b/drivers/hid/hid-hyperv.c > @@ -687,7 +687,7 @@ static void mousevsc_device_info_valid_descriptor(struct kunit *test) > > info->hid_descriptor.bLength = sizeof(struct hid_descriptor); > info->hid_descriptor.rpt_desc.wDescriptorLength = cpu_to_le16(4); > - report = ((u8 *)&info->hid_descriptor) + info->hid_descriptor.bLength; > + report = (u8 *)info + offsetof(struct synthhid_device_info, hid_descriptor) + info->hid_descriptor.bLength; Isn't that overcomplicated?: Above we have: struct synthhid_device_info { struct synthhid_msg_hdr header; struct hv_input_dev_info hid_dev_info; struct hid_descriptor hid_descriptor; }; ... struct synthhid_device_info *info; ... info = kunit_kzalloc(test, sizeof(*info) + 4, GFP_KERNEL); so info is 0 allocated with the sizeof(struct synthhid_device_info) plus 4 for the report (immediately after). with the bLength being set a couple of lines above, we basically have: + report = (u8 *)info + offsetof(struct synthhid_device_info, hid_descriptor) + sizeof(struct hid_descriptor); So pointer address + offset of the last field + size of the last field. Isn't that equivalent to: report = (u8 *)info + sizeof(*info); or even: `(u8 *)(info + 1)`? > memset(report, 0x42, 4); > > mousevsc_on_receive_device_info(input_dev, info, sizeof(*info) + 4); > @@ -713,7 +713,7 @@ static void mousevsc_device_info_report_desc_oob(struct kunit *test) > > info->hid_descriptor.bLength = sizeof(struct hid_descriptor); > info->hid_descriptor.rpt_desc.wDescriptorLength = cpu_to_le16(64); > - report = ((u8 *)&info->hid_descriptor) + info->hid_descriptor.bLength; > + report = (u8 *)info + offsetof(struct synthhid_device_info, hid_descriptor) + info->hid_descriptor.bLength; Same overcomplexification applies here. Unless of course there is something I missed in the string fortification. Cheers, Benjamin > memset(report, 0x42, 8); > > mousevsc_on_receive_device_info(input_dev, info, sizeof(*info) + 8); > > -- > Jiri Kosina > SUSE Labs > > ^ permalink raw reply [flat|nested] 15+ messages in thread
* [PATCH v2] HID: hyperv: make pointer arithmetics understandable for FORTIFY_SOURCE 2026-08-21 13:18 ` Benjamin Tissoires @ 2026-08-21 13:39 ` Jiri Kosina 2026-08-21 13:50 ` Benjamin Tissoires 2026-08-21 13:54 ` Juergen Gross 0 siblings, 2 replies; 15+ messages in thread From: Jiri Kosina @ 2026-08-21 13:39 UTC (permalink / raw) To: Benjamin Tissoires, Jürgen Groß Cc: lkml, michael.bommarito, longli, decui, wei.liu, haiyangz, kys On Fri, 21 Aug 2026, Benjamin Tissoires wrote: > > - report = ((u8 *)&info->hid_descriptor) + info->hid_descriptor.bLength; > > + report = (u8 *)info + offsetof(struct synthhid_device_info, hid_descriptor) + info->hid_descriptor.bLength; > > Isn't that overcomplicated?: > > Above we have: > struct synthhid_device_info { > struct synthhid_msg_hdr header; > struct hv_input_dev_info hid_dev_info; > struct hid_descriptor hid_descriptor; > }; > ... > struct synthhid_device_info *info; > ... > info = kunit_kzalloc(test, sizeof(*info) + 4, GFP_KERNEL); > > so info is 0 allocated with the sizeof(struct synthhid_device_info) plus > 4 for the report (immediately after). > > with the bLength being set a couple of lines above, we basically have: > + report = (u8 *)info + offsetof(struct synthhid_device_info, hid_descriptor) + sizeof(struct hid_descriptor); > > So pointer address + offset of the last field + size of the last field. > > Isn't that equivalent to: > report = (u8 *)info + sizeof(*info); > > or even: `(u8 *)(info + 1)`? I considered that one as well, but then I decided to keep what the original author intended as perhaps it's more self-explanatory what we're actually doing. But the argument that whenever a new field is added after hid_descriptor, this will silently break, is convicing enough :) Thanks. v2 below. Juergen, could you please re-Ack your Tested-by: on this? For some reason, my allyesconfig with gcc-15 doesn't trigger it. From: Jiri Kosina <jkosina@suse.com> Subject: [PATCH] HID: hyperv: make pointer arithmetics understandable for FORTIFY_SOURCE Commit 83df7b5fa6735b5084ecd2 ("HID: hyperv: add KUnit coverage for device info bounds") introduced this piece of code report = ((u8 *)&info->hid_descriptor) + info->hid_descriptor.bLength; memset(report, 0x42, 4); to populate the report descriptor, making use of the fact that the report &info->hid_descriptor points to a struct hid_descriptor (which is a fixed-size struct). GCC's FORTIFY_SOURCE infer the object size from that specific struct field rather than the outer dynamically allocated info buffer. As a result, writing past sizeof(struct hid_descriptor) triggers the __write_overflow_field warning. Calculate the pointer offset using info directly, so the compiler evaluates the memory bounds against the allocated flexible layout of struct synthhid_device_info instead of the nested struct. Fixes: 83df7b5fa6735b5084ecd2 ("HID: hyperv: add KUnit coverage for device info bounds") Reported-by: Jürgen Groß <jgross@suse.com> Signed-off-by: Jiri Kosina <jkosina@suse.com> --- drivers/hid/hid-hyperv.c | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/drivers/hid/hid-hyperv.c b/drivers/hid/hid-hyperv.c index 6579bd19da13..cfc061dbdd24 100644 --- a/drivers/hid/hid-hyperv.c +++ b/drivers/hid/hid-hyperv.c @@ -687,7 +687,7 @@ static void mousevsc_device_info_valid_descriptor(struct kunit *test) info->hid_descriptor.bLength = sizeof(struct hid_descriptor); info->hid_descriptor.rpt_desc.wDescriptorLength = cpu_to_le16(4); - report = ((u8 *)&info->hid_descriptor) + info->hid_descriptor.bLength; + report = (u8 *)(info + 1); memset(report, 0x42, 4); mousevsc_on_receive_device_info(input_dev, info, sizeof(*info) + 4); @@ -713,7 +713,7 @@ static void mousevsc_device_info_report_desc_oob(struct kunit *test) info->hid_descriptor.bLength = sizeof(struct hid_descriptor); info->hid_descriptor.rpt_desc.wDescriptorLength = cpu_to_le16(64); - report = ((u8 *)&info->hid_descriptor) + info->hid_descriptor.bLength; + report = (u8 *)(info + 1); memset(report, 0x42, 8); mousevsc_on_receive_device_info(input_dev, info, sizeof(*info) + 8); -- Jiri Kosina SUSE Labs ^ permalink raw reply related [flat|nested] 15+ messages in thread
* Re: [PATCH v2] HID: hyperv: make pointer arithmetics understandable for FORTIFY_SOURCE 2026-08-21 13:39 ` [PATCH v2] " Jiri Kosina @ 2026-08-21 13:50 ` Benjamin Tissoires 2026-08-21 13:54 ` Juergen Gross 1 sibling, 0 replies; 15+ messages in thread From: Benjamin Tissoires @ 2026-08-21 13:50 UTC (permalink / raw) To: Jiri Kosina Cc: Jürgen Groß, lkml, michael.bommarito, longli, decui, wei.liu, haiyangz, kys On Aug 21 2026, Jiri Kosina wrote: > On Fri, 21 Aug 2026, Benjamin Tissoires wrote: > > > > - report = ((u8 *)&info->hid_descriptor) + info->hid_descriptor.bLength; > > > + report = (u8 *)info + offsetof(struct synthhid_device_info, hid_descriptor) + info->hid_descriptor.bLength; > > > > Isn't that overcomplicated?: > > > > Above we have: > > struct synthhid_device_info { > > struct synthhid_msg_hdr header; > > struct hv_input_dev_info hid_dev_info; > > struct hid_descriptor hid_descriptor; > > }; > > ... > > struct synthhid_device_info *info; > > ... > > info = kunit_kzalloc(test, sizeof(*info) + 4, GFP_KERNEL); > > > > so info is 0 allocated with the sizeof(struct synthhid_device_info) plus > > 4 for the report (immediately after). > > > > with the bLength being set a couple of lines above, we basically have: > > + report = (u8 *)info + offsetof(struct synthhid_device_info, hid_descriptor) + sizeof(struct hid_descriptor); > > > > So pointer address + offset of the last field + size of the last field. > > > > Isn't that equivalent to: > > report = (u8 *)info + sizeof(*info); > > > > or even: `(u8 *)(info + 1)`? > > I considered that one as well, but then I decided to keep what the > original author intended as perhaps it's more self-explanatory what we're > actually doing. But the argument that whenever a new field is added after > hid_descriptor, this will silently break, is convicing enough :) Yep, that's a killer argument :) Acked-by: Benjamin Tissoires <bentiss@kernel.org> Cheers, Benjamin > > Thanks. v2 below. > > Juergen, could you please re-Ack your Tested-by: on this? For some reason, > my allyesconfig with gcc-15 doesn't trigger it. > > > > > From: Jiri Kosina <jkosina@suse.com> > Subject: [PATCH] HID: hyperv: make pointer arithmetics understandable for FORTIFY_SOURCE > > Commit 83df7b5fa6735b5084ecd2 ("HID: hyperv: add KUnit coverage for device info > bounds") introduced this piece of code > > report = ((u8 *)&info->hid_descriptor) + info->hid_descriptor.bLength; > memset(report, 0x42, 4); > > to populate the report descriptor, making use of the fact that the report > &info->hid_descriptor points to a struct hid_descriptor (which is a fixed-size struct). > GCC's FORTIFY_SOURCE infer the object size from that specific struct field rather than the > outer dynamically allocated info buffer. As a result, writing past sizeof(struct hid_descriptor) > triggers the __write_overflow_field warning. > > Calculate the pointer offset using info directly, so the compiler evaluates the > memory bounds against the allocated flexible layout of struct > synthhid_device_info instead of the nested struct. > > Fixes: 83df7b5fa6735b5084ecd2 ("HID: hyperv: add KUnit coverage for device info bounds") > Reported-by: Jürgen Groß <jgross@suse.com> > Signed-off-by: Jiri Kosina <jkosina@suse.com> > --- > drivers/hid/hid-hyperv.c | 4 ++-- > 1 file changed, 2 insertions(+), 2 deletions(-) > > diff --git a/drivers/hid/hid-hyperv.c b/drivers/hid/hid-hyperv.c > index 6579bd19da13..cfc061dbdd24 100644 > --- a/drivers/hid/hid-hyperv.c > +++ b/drivers/hid/hid-hyperv.c > @@ -687,7 +687,7 @@ static void mousevsc_device_info_valid_descriptor(struct kunit *test) > > info->hid_descriptor.bLength = sizeof(struct hid_descriptor); > info->hid_descriptor.rpt_desc.wDescriptorLength = cpu_to_le16(4); > - report = ((u8 *)&info->hid_descriptor) + info->hid_descriptor.bLength; > + report = (u8 *)(info + 1); > memset(report, 0x42, 4); > > mousevsc_on_receive_device_info(input_dev, info, sizeof(*info) + 4); > @@ -713,7 +713,7 @@ static void mousevsc_device_info_report_desc_oob(struct kunit *test) > > info->hid_descriptor.bLength = sizeof(struct hid_descriptor); > info->hid_descriptor.rpt_desc.wDescriptorLength = cpu_to_le16(64); > - report = ((u8 *)&info->hid_descriptor) + info->hid_descriptor.bLength; > + report = (u8 *)(info + 1); > memset(report, 0x42, 8); > > mousevsc_on_receive_device_info(input_dev, info, sizeof(*info) + 8); > > -- > Jiri Kosina > SUSE Labs > > ^ permalink raw reply [flat|nested] 15+ messages in thread
* Re: [PATCH v2] HID: hyperv: make pointer arithmetics understandable for FORTIFY_SOURCE 2026-08-21 13:39 ` [PATCH v2] " Jiri Kosina 2026-08-21 13:50 ` Benjamin Tissoires @ 2026-08-21 13:54 ` Juergen Gross 2026-08-21 14:00 ` Jiri Kosina 1 sibling, 1 reply; 15+ messages in thread From: Juergen Gross @ 2026-08-21 13:54 UTC (permalink / raw) To: Jiri Kosina, Benjamin Tissoires Cc: lkml, michael.bommarito, longli, decui, wei.liu, haiyangz, kys [-- Attachment #1.1.1: Type: text/plain, Size: 2858 bytes --] On 21.08.26 15:39, Jiri Kosina wrote: > On Fri, 21 Aug 2026, Benjamin Tissoires wrote: > >>> - report = ((u8 *)&info->hid_descriptor) + info->hid_descriptor.bLength; >>> + report = (u8 *)info + offsetof(struct synthhid_device_info, hid_descriptor) + info->hid_descriptor.bLength; >> >> Isn't that overcomplicated?: >> >> Above we have: >> struct synthhid_device_info { >> struct synthhid_msg_hdr header; >> struct hv_input_dev_info hid_dev_info; >> struct hid_descriptor hid_descriptor; >> }; >> ... >> struct synthhid_device_info *info; >> ... >> info = kunit_kzalloc(test, sizeof(*info) + 4, GFP_KERNEL); >> >> so info is 0 allocated with the sizeof(struct synthhid_device_info) plus >> 4 for the report (immediately after). >> >> with the bLength being set a couple of lines above, we basically have: >> + report = (u8 *)info + offsetof(struct synthhid_device_info, hid_descriptor) + sizeof(struct hid_descriptor); >> >> So pointer address + offset of the last field + size of the last field. >> >> Isn't that equivalent to: >> report = (u8 *)info + sizeof(*info); >> >> or even: `(u8 *)(info + 1)`? > > I considered that one as well, but then I decided to keep what the > original author intended as perhaps it's more self-explanatory what we're > actually doing. But the argument that whenever a new field is added after > hid_descriptor, this will silently break, is convicing enough :) > > Thanks. v2 below. > > Juergen, could you please re-Ack your Tested-by: on this? For some reason, > my allyesconfig with gcc-15 doesn't trigger it. > > > > > From: Jiri Kosina <jkosina@suse.com> > Subject: [PATCH] HID: hyperv: make pointer arithmetics understandable for FORTIFY_SOURCE > > Commit 83df7b5fa6735b5084ecd2 ("HID: hyperv: add KUnit coverage for device info > bounds") introduced this piece of code > > report = ((u8 *)&info->hid_descriptor) + info->hid_descriptor.bLength; > memset(report, 0x42, 4); > > to populate the report descriptor, making use of the fact that the report > &info->hid_descriptor points to a struct hid_descriptor (which is a fixed-size struct). > GCC's FORTIFY_SOURCE infer the object size from that specific struct field rather than the > outer dynamically allocated info buffer. As a result, writing past sizeof(struct hid_descriptor) > triggers the __write_overflow_field warning. > > Calculate the pointer offset using info directly, so the compiler evaluates the > memory bounds against the allocated flexible layout of struct > synthhid_device_info instead of the nested struct. > > Fixes: 83df7b5fa6735b5084ecd2 ("HID: hyperv: add KUnit coverage for device info bounds") > Reported-by: Jürgen Groß <jgross@suse.com> > Signed-off-by: Jiri Kosina <jkosina@suse.com> Tested-by: Jürgen Groß <jgross@suse.com> Jürgen [-- Attachment #1.1.2: OpenPGP public key --] [-- Type: application/pgp-keys, Size: 3743 bytes --] [-- Attachment #2: OpenPGP digital signature --] [-- Type: application/pgp-signature, Size: 495 bytes --] ^ permalink raw reply [flat|nested] 15+ messages in thread
* Re: [PATCH v2] HID: hyperv: make pointer arithmetics understandable for FORTIFY_SOURCE 2026-08-21 13:54 ` Juergen Gross @ 2026-08-21 14:00 ` Jiri Kosina 0 siblings, 0 replies; 15+ messages in thread From: Jiri Kosina @ 2026-08-21 14:00 UTC (permalink / raw) To: Juergen Gross Cc: Benjamin Tissoires, lkml, michael.bommarito, longli, decui, wei.liu, haiyangz, kys On Fri, 21 Aug 2026, Juergen Gross wrote: > Tested-by: Jürgen Groß <jgross@suse.com> Thanks, now applied. -- Jiri Kosina SUSE Labs ^ permalink raw reply [flat|nested] 15+ messages in thread
end of thread, other threads:[~2026-08-21 14:00 UTC | newest] Thread overview: 15+ messages (download: mbox.gz follow: Atom feed -- links below jump to the message on this page -- 2026-08-21 6:38 Build error with kernel from 2026-08-21 Juergen Gross 2026-08-21 7:06 ` Juergen Gross 2026-08-21 8:41 ` Jiri Kosina 2026-08-21 8:51 ` Jürgen Groß 2026-08-21 8:52 ` Jürgen Groß 2026-08-21 9:24 ` Jiri Kosina 2026-08-21 9:35 ` Jiri Kosina 2026-08-21 10:13 ` Jürgen Groß 2026-08-21 10:23 ` [PATCH] HID: hyperv: make pointer arithmetics understandable for FORTIFY_SOURCE Jiri Kosina 2026-08-21 11:16 ` Jürgen Groß 2026-08-21 13:18 ` Benjamin Tissoires 2026-08-21 13:39 ` [PATCH v2] " Jiri Kosina 2026-08-21 13:50 ` Benjamin Tissoires 2026-08-21 13:54 ` Juergen Gross 2026-08-21 14:00 ` Jiri Kosina
This is a public inbox, see mirroring instructions for how to clone and mirror all data and code used for this inbox