* [PATCH v2] blk-mq: fix null pointer dereference in blk_mq_clear_rq_mapping()
@ 2022-10-11 14:22 Yu Kuai
2022-10-15 3:58 ` Yu Kuai
2022-10-16 23:23 ` Jens Axboe
0 siblings, 2 replies; 3+ messages in thread
From: Yu Kuai @ 2022-10-11 14:22 UTC (permalink / raw)
To: axboe, ming.lei, hare, john.garry
Cc: linux-block, linux-kernel, yukuai3, yukuai1, yi.zhang
From: Yu Kuai <yukuai3@huawei.com>
Our syzkaller report a null pointer dereference, root cause is
following:
__blk_mq_alloc_map_and_rqs
set->tags[hctx_idx] = blk_mq_alloc_map_and_rqs
blk_mq_alloc_map_and_rqs
blk_mq_alloc_rqs
// failed due to oom
alloc_pages_node
// set->tags[hctx_idx] is still NULL
blk_mq_free_rqs
drv_tags = set->tags[hctx_idx];
// null pointer dereference is triggered
blk_mq_clear_rq_mapping(drv_tags, ...)
This is because commit 63064be150e4 ("blk-mq:
Add blk_mq_alloc_map_and_rqs()") merged the two steps:
1) set->tags[hctx_idx] = blk_mq_alloc_rq_map()
2) blk_mq_alloc_rqs(..., set->tags[hctx_idx])
into one step:
set->tags[hctx_idx] = blk_mq_alloc_map_and_rqs()
Since tags is not initialized yet in this case, fix the problem by
checking if tags is NULL pointer in blk_mq_clear_rq_mapping().
Fixes: 63064be150e4 ("blk-mq: Add blk_mq_alloc_map_and_rqs()")
Signed-off-by: Yu Kuai <yukuai3@huawei.com>
Reviewed-by: John Garry <john.garry@huawei.com>
---
Changes in v2:
- fix spelling mistakes
- add review tag
block/blk-mq.c | 7 +++++--
1 file changed, 5 insertions(+), 2 deletions(-)
diff --git a/block/blk-mq.c b/block/blk-mq.c
index 8070b6c10e8d..33292c01875d 100644
--- a/block/blk-mq.c
+++ b/block/blk-mq.c
@@ -3112,8 +3112,11 @@ static void blk_mq_clear_rq_mapping(struct blk_mq_tags *drv_tags,
struct page *page;
unsigned long flags;
- /* There is no need to clear a driver tags own mapping */
- if (drv_tags == tags)
+ /*
+ * There is no need to clear mapping if driver tags is not initialized
+ * or the mapping belongs to the driver tags.
+ */
+ if (!drv_tags || drv_tags == tags)
return;
list_for_each_entry(page, &tags->page_list, lru) {
--
2.31.1
^ permalink raw reply [flat|nested] 3+ messages in thread
* Re: [PATCH v2] blk-mq: fix null pointer dereference in blk_mq_clear_rq_mapping()
2022-10-11 14:22 [PATCH v2] blk-mq: fix null pointer dereference in blk_mq_clear_rq_mapping() Yu Kuai
@ 2022-10-15 3:58 ` Yu Kuai
2022-10-16 23:23 ` Jens Axboe
1 sibling, 0 replies; 3+ messages in thread
From: Yu Kuai @ 2022-10-15 3:58 UTC (permalink / raw)
To: Yu Kuai, axboe, ming.lei, hare, john.garry
Cc: linux-block, linux-kernel, yi.zhang, yukuai (C)
Hi, Jens!
在 2022/10/11 22:22, Yu Kuai 写道:
> From: Yu Kuai <yukuai3@huawei.com>
>
> Our syzkaller report a null pointer dereference, root cause is
> following:
>
> __blk_mq_alloc_map_and_rqs
> set->tags[hctx_idx] = blk_mq_alloc_map_and_rqs
> blk_mq_alloc_map_and_rqs
> blk_mq_alloc_rqs
> // failed due to oom
> alloc_pages_node
> // set->tags[hctx_idx] is still NULL
> blk_mq_free_rqs
> drv_tags = set->tags[hctx_idx];
> // null pointer dereference is triggered
> blk_mq_clear_rq_mapping(drv_tags, ...)
>
> This is because commit 63064be150e4 ("blk-mq:
> Add blk_mq_alloc_map_and_rqs()") merged the two steps:
>
> 1) set->tags[hctx_idx] = blk_mq_alloc_rq_map()
> 2) blk_mq_alloc_rqs(..., set->tags[hctx_idx])
>
> into one step:
>
> set->tags[hctx_idx] = blk_mq_alloc_map_and_rqs()
>
> Since tags is not initialized yet in this case, fix the problem by
> checking if tags is NULL pointer in blk_mq_clear_rq_mapping().
>
> Fixes: 63064be150e4 ("blk-mq: Add blk_mq_alloc_map_and_rqs()")
> Signed-off-by: Yu Kuai <yukuai3@huawei.com>
> Reviewed-by: John Garry <john.garry@huawei.com>
> ---
> Changes in v2:
> - fix spelling mistakes
> - add review tag
>
> block/blk-mq.c | 7 +++++--
> 1 file changed, 5 insertions(+), 2 deletions(-)
>
Can you apply this patch?
Thanks,
Kuai
> diff --git a/block/blk-mq.c b/block/blk-mq.c
> index 8070b6c10e8d..33292c01875d 100644
> --- a/block/blk-mq.c
> +++ b/block/blk-mq.c
> @@ -3112,8 +3112,11 @@ static void blk_mq_clear_rq_mapping(struct blk_mq_tags *drv_tags,
> struct page *page;
> unsigned long flags;
>
> - /* There is no need to clear a driver tags own mapping */
> - if (drv_tags == tags)
> + /*
> + * There is no need to clear mapping if driver tags is not initialized
> + * or the mapping belongs to the driver tags.
> + */
> + if (!drv_tags || drv_tags == tags)
> return;
>
> list_for_each_entry(page, &tags->page_list, lru) {
>
^ permalink raw reply [flat|nested] 3+ messages in thread
* Re: [PATCH v2] blk-mq: fix null pointer dereference in blk_mq_clear_rq_mapping()
2022-10-11 14:22 [PATCH v2] blk-mq: fix null pointer dereference in blk_mq_clear_rq_mapping() Yu Kuai
2022-10-15 3:58 ` Yu Kuai
@ 2022-10-16 23:23 ` Jens Axboe
1 sibling, 0 replies; 3+ messages in thread
From: Jens Axboe @ 2022-10-16 23:23 UTC (permalink / raw)
To: ming.lei, Yu Kuai, john.garry, hare
Cc: linux-block, yukuai3, linux-kernel, yi.zhang
On Tue, 11 Oct 2022 22:22:53 +0800, Yu Kuai wrote:
> From: Yu Kuai <yukuai3@huawei.com>
>
> Our syzkaller report a null pointer dereference, root cause is
> following:
>
> __blk_mq_alloc_map_and_rqs
> set->tags[hctx_idx] = blk_mq_alloc_map_and_rqs
> blk_mq_alloc_map_and_rqs
> blk_mq_alloc_rqs
> // failed due to oom
> alloc_pages_node
> // set->tags[hctx_idx] is still NULL
> blk_mq_free_rqs
> drv_tags = set->tags[hctx_idx];
> // null pointer dereference is triggered
> blk_mq_clear_rq_mapping(drv_tags, ...)
>
> [...]
Applied, thanks!
[1/1] blk-mq: fix null pointer dereference in blk_mq_clear_rq_mapping()
commit: 76dd298094f484c6250ebd076fa53287477b2328
Best regards,
--
Jens Axboe
^ permalink raw reply [flat|nested] 3+ messages in thread
end of thread, other threads:[~2022-10-16 23:23 UTC | newest]
Thread overview: 3+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2022-10-11 14:22 [PATCH v2] blk-mq: fix null pointer dereference in blk_mq_clear_rq_mapping() Yu Kuai
2022-10-15 3:58 ` Yu Kuai
2022-10-16 23:23 ` Jens Axboe
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®