mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* [PATCH] assoc_array: Preserve full words when splitting shortcuts
@ 2026-10-06 22:06 Kyle Zeng
  2026-10-06 22:25 ` Andrew Morton
  0 siblings, 1 reply; 4+ messages in thread
From: Kyle Zeng @ 2026-10-06 22:06 UTC (permalink / raw)
  To: linux-kernel; +Cc: akpm, Kyle Zeng, stable

assoc_array_insert_mid_shortcut() copies enough index-key words for the
new pre-shortcut, then masks off the unused bits in its last word.  If
diff is word-aligned, the shift is zero and the mask clears that entire
word, even though all of it belongs to the required prefix.  The new
shortcut no longer matches the objects behind it, so lookups can fail
for both the existing objects and the new one.

For example, inserting a user key with a different description length
into a keyring containing enough full-hash collisions can split a
shortcut at bit 64 and erase its hash word.  The resulting search
failure can also expose the pointer-dependent keyring hash as a KASLR
oracle.

Only trim the last word when diff ends inside it.  This mirrors
commit bb2ba2d75a2d ("assoc_array: Fix shortcut creation"), which fixed
the terminal-node case, and leaves non-word-aligned splits unchanged.

Fixes: 3cb989501c26 ("Add a generic associative array implementation.")
Cc: stable@vger.kernel.org
Assisted-by: Codex:gpt-6-astra
Signed-off-by: Kyle Zeng <kylebot@openai.com>
---
 lib/assoc_array.c | 8 +++++---
 1 file changed, 5 insertions(+), 3 deletions(-)

diff --git a/lib/assoc_array.c b/lib/assoc_array.c
index b6c9723e12ce..20ef69e03780 100644
--- a/lib/assoc_array.c
+++ b/lib/assoc_array.c
@@ -865,9 +865,11 @@ static bool assoc_array_insert_mid_shortcut(struct assoc_array_edit *edit,
 		memcpy(new_s0->index_key, shortcut->index_key,
 		       flex_array_size(new_s0, index_key, keylen));
 
-		blank = ULONG_MAX << (diff & ASSOC_ARRAY_KEY_CHUNK_MASK);
-		pr_devel("blank off [%zu] %d: %lx\n", keylen - 1, diff, blank);
-		new_s0->index_key[keylen - 1] &= ~blank;
+		if (diff & ASSOC_ARRAY_KEY_CHUNK_MASK) {
+			blank = ULONG_MAX << (diff & ASSOC_ARRAY_KEY_CHUNK_MASK);
+			pr_devel("blank off [%zu] %d: %lx\n", keylen - 1, diff, blank);
+			new_s0->index_key[keylen - 1] &= ~blank;
+		}
 	} else {
 		pr_devel("no pre-shortcut\n");
 		edit->set[0].to = assoc_array_node_to_ptr(new_n0);
-- 
2.53.0


^ permalink raw reply	[flat|nested] 4+ messages in thread

end of thread, other threads:[~2026-10-06 22:43 UTC | newest]

Thread overview: 4+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-10-06 22:06 [PATCH] assoc_array: Preserve full words when splitting shortcuts Kyle Zeng
2026-10-06 22:25 ` Andrew Morton
2026-10-06 22:33   ` Kyle Zeng
2026-10-06 22:42     ` Andrew Morton

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®