Received: by 2002:a05:6a10:413:0:0:0:0 with SMTP id 19csp2254920pxp; Mon, 21 Mar 2022 15:05:36 -0700 (PDT) X-Google-Smtp-Source: ABdhPJyX1osGpwPZCNJ3VNwVNLDbREwLMtvzx7GH7Ds8O/UhLDXB6Nt6iA3vwSrA10BDhNIiB1fI X-Received: by 2002:a17:90a:4590:b0:1bc:4afa:1778 with SMTP id v16-20020a17090a459000b001bc4afa1778mr1344072pjg.14.1647900336769; Mon, 21 Mar 2022 15:05:36 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1647900336; cv=none; d=google.com; s=arc-20160816; b=buLieYgNcp/srXheAuBuLXA27GS2vLziD93o4GMAUL41MlOiko5iEQAFLNsTQxh1ys 4FHzWG4MByOS/COPUR4qkjT0eAKecbPHG1H1yuRiUFK4pZZdIBJS+8AXBxs8jCZetBS/ BMOQ668lArZbdwkESrnd9ihhLIKpvG2sy1/GklFJa/Ns+JWrIVV30Oq+LDPV2mtj8jpg cd+R9ywBG5mYxVeSdTGF9pfoSE3o6Q/5ZXJyBrXeaqS3tHsfqULzCfNSqCW4UtR1mjUz MSE8ZGANwVuQO+cNROClqAZ7fTjRuYbl3ObMJn7ngbtfLXOlSwSMBTuQMPr3QMizWdm1 IeDw== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:content-transfer-encoding:mime-version :references:in-reply-to:message-id:date:subject:cc:to:from :dkim-signature; bh=lXXo8Wx8fodr/GuReoIfu4jj3/veJvq5HjguHW4ZOnc=; b=R2yFOKBZNYtBwlc+jAiL0U7ydN1bF4TZ12g9LDWDXEs3lGBOC0PsRtwHGNuTBQyuUD OpPFFZP1l82hfvFbV47xXra82zgbLi7EJjmgCIz9HTBY7vOA5J1t55fYUfx6XHt7zmN7 W3LagYoF/FKTpGlBQUi3bBg16LKmyn0AUt6FKMpNmis0Ik/lQb3VD80WzTf2Y7ev4U/P QRNFrVDoeWRGgo17eRq9etm8qZdIknyGu9knYpv16SrcVVwoHciZW1Nzvh74UBzSfpTr vrOwbQnSPekgLnYfyMsDYQzsvHf4wB7P0AdOlgalvM8re6XVC768jrKkL5pE4wEMWnki 5N6g== ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@gmail.com header.s=20210112 header.b=ewETv+ED; spf=softfail (google.com: domain of transitioning linux-kernel-owner@vger.kernel.org does not designate 23.128.96.19 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=NONE sp=QUARANTINE dis=NONE) header.from=gmail.com Return-Path: Received: from lindbergh.monkeyblade.net (lindbergh.monkeyblade.net. [23.128.96.19]) by mx.google.com with ESMTPS id g5-20020a170902740500b00153b2d165bfsi10738395pll.455.2022.03.21.15.05.34 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 21 Mar 2022 15:05:36 -0700 (PDT) Received-SPF: softfail (google.com: domain of transitioning linux-kernel-owner@vger.kernel.org does not designate 23.128.96.19 as permitted sender) client-ip=23.128.96.19; Authentication-Results: mx.google.com; dkim=pass header.i=@gmail.com header.s=20210112 header.b=ewETv+ED; spf=softfail (google.com: domain of transitioning linux-kernel-owner@vger.kernel.org does not designate 23.128.96.19 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=NONE sp=QUARANTINE dis=NONE) header.from=gmail.com Received: from vger.kernel.org (vger.kernel.org [23.128.96.18]) by lindbergh.monkeyblade.net (Postfix) with ESMTP id E201635785E; Mon, 21 Mar 2022 14:28:16 -0700 (PDT) Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1345314AbiCUIvg (ORCPT + 99 others); Mon, 21 Mar 2022 04:51:36 -0400 Received: from lindbergh.monkeyblade.net ([23.128.96.19]:51900 "EHLO lindbergh.monkeyblade.net" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1344531AbiCUIve (ORCPT ); Mon, 21 Mar 2022 04:51:34 -0400 Received: from mail-ed1-x52a.google.com (mail-ed1-x52a.google.com [IPv6:2a00:1450:4864:20::52a]) by lindbergh.monkeyblade.net (Postfix) with ESMTPS id A807C3630B for ; Mon, 21 Mar 2022 01:50:09 -0700 (PDT) Received: by mail-ed1-x52a.google.com with SMTP id h1so16932020edj.1 for ; Mon, 21 Mar 2022 01:50:09 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20210112; h=from:to:cc:subject:date:message-id:in-reply-to:references :mime-version:content-transfer-encoding; bh=lXXo8Wx8fodr/GuReoIfu4jj3/veJvq5HjguHW4ZOnc=; b=ewETv+EDy7d9n1e5VTKD6REo4XEpJS6NIIrwzk5R/fXYDNDs3EWSm50QLtlCHwEEin IAyDvHCNDzhXSDf/M86ikfrKxaTDSvjGuVgyuY7K7TQ1ERuV5t3OAXr85jgDXO8DUY0S dmIVqQWGbj2EYvSyr4OEj1qW2SEGAj74IbLXmLvy+l6/gCbvG+xJjUEDBBbwjP6/auLa lUlBCNg8DfiJX1oL/ngZzLHpXFFvBM5o8vrtZNY+ta5Q9aB48JM9LZmZgJvDIfQDJ6R8 Y8AQet+rhFtasFWu1yqH23qOk0djWq4pQTi5oCMeyQZk4jh2VLEbOB7NgYBDKykv1Z7U IBsQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20210112; h=x-gm-message-state:from:to:cc:subject:date:message-id:in-reply-to :references:mime-version:content-transfer-encoding; bh=lXXo8Wx8fodr/GuReoIfu4jj3/veJvq5HjguHW4ZOnc=; b=hAwIZBAdjGmuL8eI+a8SbrnxmJ/tiR2BYkROZLu32iurIdogMJf4XjuA21p2N3dgES WvKjjsw6fqa+p2IZb1KQ1b/Q0p5jf/KNDy2hJcw69Yee51lDug0Pfrs8L+HtD1GehURK rBVH76GxQAkZ5HQOxqVZhJx1bIHb6HEtligVMlfBzMjXIH1n7jCQdIszB6NiFiSWui3M LC1YuzVuISK/5heFPoZQrAggE6SeycKmtiBrh39QbW7lUrZmooYYDi+sYlJ4daJjbgXG gsY/vA1HIR5CLC3UqRUaYOAG9HOmgz6THfu8I8kLRYIQD7hy00ogj7w5DIzIM92d1X4Y H2dg== X-Gm-Message-State: AOAM531rv7E/dfxHSFd26A3k4WmRtVklq+JCO2fSyNib4zPd89KXF2K3 c+Ffryo868yxkJBoU/D4UAs= X-Received: by 2002:a05:6402:5162:b0:419:2d46:c8c3 with SMTP id d2-20020a056402516200b004192d46c8c3mr7176173ede.150.1647852608136; Mon, 21 Mar 2022 01:50:08 -0700 (PDT) Received: from leap.localnet (host-87-20-105-171.retail.telecomitalia.it. [87.20.105.171]) by smtp.gmail.com with ESMTPSA id r22-20020a17090638d600b006d584aaa9c9sm6581968ejd.133.2022.03.21.01.50.06 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 21 Mar 2022 01:50:06 -0700 (PDT) From: "Fabio M. De Francesco" To: syzbot , syzkaller-bugs@googlegroups.com Cc: dhowells@redhat.com, christophe.jaillet@wanadoo.fr, linux-kernel@vger.kernel.org, syzkaller-bugs@googlegroups.com, David Howells Subject: Re: [syzbot] KASAN: null-ptr-deref Read in __free_pages Date: Mon, 21 Mar 2022 09:50:05 +0100 Message-ID: <1905446.yKVeVyVuyW@leap> In-Reply-To: <970502.1647851062@warthog.procyon.org.uk> References: <000000000000b1807c05daad8f98@google.com> <970502.1647851062@warthog.procyon.org.uk> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="UTF-8" X-Spam-Status: No, score=-1.7 required=5.0 tests=BAYES_00,DKIM_SIGNED, DKIM_VALID,DKIM_VALID_AU,FREEMAIL_FORGED_FROMDOMAIN,FREEMAIL_FROM, HEADER_FROM_DIFFERENT_DOMAINS,MAILING_LIST_MULTI,RDNS_NONE, SPF_HELO_NONE,T_SCC_BODY_TEXT_LINE autolearn=no autolearn_force=no version=3.4.6 X-Spam-Checker-Version: SpamAssassin 3.4.6 (2021-04-09) on lindbergh.monkeyblade.net Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org On luned=C3=AC 21 marzo 2022 09:24:22 CET David Howells wrote: > It should be possible to just test for the pointer being NULL in the loop > before calling __free_pages() since the list was allocated with kcalloc(). >=20 > David >=20 > #syz test: git://git.kernel.org/pub/scm/linux/kernel/git/dhowells/linux-f= s.git 6d39b096627f0a1eb6e14f049d8ae3c93e0290f2 >=20 > --=20 > You received this message because you are subscribed to the Google Groups= "syzkaller-bugs" group. > To unsubscribe from this group and stop receiving emails from it, send an= email to syzkaller-bugs+unsubscribe@googlegroups.com. > To view this discussion on the web visit https://groups.google.com/d/msgi= d/syzkaller-bugs/970502.1647851062%40warthog.procyon.org.uk. >=20 This way you are doing two test for each iteration of the loop that calls __free_pages(). One for the index "i" to stay less that an unnecessary=20 high limit, the other for pages[i] being NULL. However, since you are the Maintainer, yours are the rules :) Regards, =46abio M. De Francesco