* [PATCH] kconfig: fix dangling check_top after an unexpected recursive dependency
@ 2026-10-05 20:25 lzhan011
0 siblings, 0 replies; only message in thread
From: lzhan011 @ 2026-10-05 20:25 UTC (permalink / raw)
To: nathan, nsc; +Cc: linux-kbuild, linux-kernel
From: lzhan011 <zhangleizhen645@gmail.com>
If the last symbol of a recursive dependency is a choice value,
sym_check_print_recursive() pushes the on-stack cv_stack onto the
dependency stack. If the choice is then not found on the stack, the
function prints "unexpected recursive dependency error" and returns
without removing cv_stack again. check_top is left pointing into the
stack frame of the returned function, and the next dep_stack_remove()
dereferences it:
AddressSanitizer: stack-use-after-return ... in dep_stack_remove
This can be triggered by an (invalid) Kconfig file in which a symbol is
a choice value of two choices and the second choice depends on it:
choice
prompt "c1"
config A
bool "a"
endchoice
choice
prompt "c2"
depends on A
config A
bool "a"
endchoice
Jump to the existing cleanup at the end of the function instead of
returning directly.
Found by fuzzing Kconfig input with ASan/UBSan.
Fixes: d595cea62403 ("kconfig: print more info when we see a recursive dependency")
Assisted-by: Claude:claude-opus-5-5 ASan UBSan libFuzzer
Signed-off-by: lzhan011 <zhangleizhen645@gmail.com>
---
scripts/kconfig/symbol.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/scripts/kconfig/symbol.c b/scripts/kconfig/symbol.c
index dcb4b45e6..2e87af098 100644
--- a/scripts/kconfig/symbol.c
+++ b/scripts/kconfig/symbol.c
@@ -1181,7 +1181,7 @@ static void sym_check_print_recursive(struct symbol *last_sym)
break;
if (!stack) {
fprintf(stderr, "unexpected recursive dependency error\n");
- return;
+ goto out;
}
for (; stack; stack = stack->next) {
@@ -1226,6 +1226,7 @@ static void sym_check_print_recursive(struct symbol *last_sym)
"subsection \"Kconfig recursive dependency limitations\"\n"
"\n");
+out:
if (check_top == &cv_stack)
dep_stack_remove();
}
--
2.34.1
^ permalink raw reply [flat|nested] only message in thread
only message in thread, other threads:[~2026-10-05 20:25 UTC | newest]
Thread overview: (only message) (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-10-05 20:25 [PATCH] kconfig: fix dangling check_top after an unexpected recursive dependency lzhan011
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®