From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from cae.in-ulm.de (cae.in-ulm.de [217.10.14.231]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 6DA8E347FEA for ; Tue, 24 Mar 2026 20:35:10 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=217.10.14.231 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1774384512; cv=none; b=TxS84pZkl4t14MmS1MPsHFZOleqjcMDdPyFb2TxquVZia6+iT/loSWP2RjmxdZg9GFEK+m0OcVrCoeW+BsVSkXsV+YEkjSVKiIQ8BT1x6F60UCDckQOKwMgnZGA5X4g5cf+908je1ivuQxIH6yFx8ICsriKKGG5k24rIIO0EsMk= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1774384512; c=relaxed/simple; bh=x21Ckor7WdloFNUUYW4YjqVJ5uU7zu3TKisF5GRecKE=; h=From:To:Cc:Subject:Date:Message-Id:MIME-Version; b=DaAsF0d4pHlGlnQVitcmItYnbMcf52aez84u49pnwNC/tb7fO+nSAurZXcfdco1ELYL4Y/xNYnLFJVHc35AR4Qv58uRDFi+55VMF4O+zdiNbDtZu4uFIfGTv4n40MxzAaY9deSOpom+5fKisHxBbH+r+m5LXW4+rNFlLi43fJlY= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=c--e.de; spf=pass smtp.mailfrom=c--e.de; arc=none smtp.client-ip=217.10.14.231 Authentication-Results: smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=c--e.de Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=c--e.de Received: by cae.in-ulm.de (Postfix, from userid 1000) id 78430140041; Tue, 24 Mar 2026 21:35:08 +0100 (CET) From: "Christian A. Ehrhardt" To: linux-kernel@vger.kernel.org, Andrew Morton , Josh Law , David Howells Cc: "Christian A. Ehrhardt" , Kees Cook , Petr Mladek , David Gow Subject: [PATCH v2 0/3] Fix length calculation bug in extract_kvec_to_sg Date: Tue, 24 Mar 2026 21:34:50 +0100 Message-Id: <20260324203453.810499-1-lk@c--e.de> X-Mailer: git-send-email 2.39.5 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit There is a bug in extract_kvec_to_sg() where the length of a scatterlist segment is miscalculated. The actual fix is a one-liner and it is quite obvious from reading the code that this is what was intened. As this is a core library function this series first adds test cases to the kunit_iov_iter test that demonstrate that there is a bug before actually fixing it in the last commit. The bug was orignally introduced into kernel v6.3 where the function lived in fs/netfs/iterator.c. It was later moved to lib/scatterlist.c in v6.5. Thus the actual fix is only marked for backports to v6.5+. --- Changes in v2: Addresss valid issues raised by AI review https://sashiko.dev/#/patchset/20260323212350.807118-1-lk@c--e.de: - Add kunit assertions for OOM conditions in the test - Reorder commits. - Fix sg_max == 0 case. - Fix return value if we run out of sg entries. - Adjust tests to catch these cases, too. --- Christian A. Ehrhardt (3): lib: kunit_iov_iter: Improve error detection lib: kunit_iov_iter: Add tests for extract_iter_to_sg lib: Fix length calculation in extract_kvec_to_sg lib/scatterlist.c | 2 +- lib/tests/kunit_iov_iter.c | 147 ++++++++++++++++++++++++++++++++++++- 2 files changed, 147 insertions(+), 2 deletions(-) -- 2.43.0