From: Leizhen Zhang <lzsx618@gmail.com>
To: nathan@kernel.org, nsc@kernel.org
Cc: rostedt@goodmis.org, linux-kbuild@vger.kernel.org,
linux-kernel@vger.kernel.org
Subject: [PATCH v2 1/8] genksyms: fix infinite loop on declarations with parameter lists
Date: Thu, 8 Oct 2026 11:40:28 -0500 [thread overview]
Message-ID: <20261008164035.3668885-2-lzsx618@gmail.com> (raw)
In-Reply-To: <20261008164035.3668885-1-lzsx618@gmail.com>
decl_specifier_seq updates the global decl_spec, which is used by the ','
action of init_declarator_list to give each further declarator the
specifiers of the declaration. However, decl_specifier_seq is also used
for parameter declarations, so for a declaration such as
int a, f(int);
decl_spec is clobbered by the specifiers of the parameter "int" by the
time the ',' action runs. The action then links the parameter's own token
node back into its chain, creating a cycle, and copy_list_range() loops
forever while allocating memory:
$ printf 'int a, f(int);\n' | scripts/genksyms/genksyms
(hangs)
Before commit 45c9c4101d3d ("genksyms: fix memory leak when the same
symbol is added from source") the same corruption did not hang but
silently recorded a wrong type for subsequent declarators (e.g. for
"int f(long), a;" the type of "a" was recorded as "int f ( long a").
Only set decl_spec in decl_specifier_seq_opt, which is used at the
declaration level, and let decl_specifier_seq just return the last
specifier. Struct and union member declarations use a new
member_decl_specifier_seq_opt that does not touch decl_spec, so a
struct body nested in a parameter list cannot clobber it either.
The generated symtypes and CRCs for 149 preprocessed kernel source files
(1128 exported symbols) are unchanged, and no new bison conflicts are
introduced.
Found by fuzzing genksyms with ASan/UBSan.
Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
Assisted-by: Claude:claude-opus-5-5 ASan UBSan
Signed-off-by: Leizhen Zhang <lzsx618@gmail.com>
---
v2:
- Use my real name in the From and Signed-off-by lines. No code
changes.
v1: https://lore.kernel.org/r/20261005104050.1786222-3-lzsx618@gmail.com
scripts/genksyms/parse.y | 23 +++++++++++++++++++----
1 file changed, 19 insertions(+), 4 deletions(-)
diff --git a/scripts/genksyms/parse.y b/scripts/genksyms/parse.y
index cabcd146f3..7cc0336a79 100644
--- a/scripts/genksyms/parse.y
+++ b/scripts/genksyms/parse.y
@@ -201,13 +201,28 @@ init_declarator:
/* Hang on to the specifiers so that we can reuse them. */
decl_specifier_seq_opt:
/* empty */ { decl_spec = NULL; }
+ | decl_specifier_seq { decl_spec = *$1; }
+ ;
+
+/*
+ * Unlike decl_specifier_seq_opt, this does not touch decl_spec, so that
+ * a struct/union body nested in a parameter list does not clobber the
+ * specifiers of the enclosing declaration.
+ */
+member_decl_specifier_seq_opt:
+ /* empty */ { $$ = NULL; }
| decl_specifier_seq
;
+/*
+ * Do not set decl_spec here; decl_specifier_seq is also used for parameter
+ * declarations, which would clobber the specifiers of the enclosing
+ * declaration, e.g. "int a, f(long);".
+ */
decl_specifier_seq:
- attribute_opt decl_specifier { decl_spec = *$2; }
- | decl_specifier_seq decl_specifier { decl_spec = *$2; }
- | decl_specifier_seq ATTRIBUTE_PHRASE { decl_spec = *$2; }
+ attribute_opt decl_specifier { $$ = $2; }
+ | decl_specifier_seq decl_specifier { $$ = $2; }
+ | decl_specifier_seq ATTRIBUTE_PHRASE { $$ = $2; }
;
decl_specifier:
@@ -456,7 +471,7 @@ member_specification:
;
member_declaration:
- decl_specifier_seq_opt member_declarator_list_opt ';'
+ member_decl_specifier_seq_opt member_declarator_list_opt ';'
{ $$ = $3; dont_want_type_specifier = false; }
| error ';'
{ $$ = $2; dont_want_type_specifier = false; }
--
2.34.1
next prev parent reply other threads:[~2026-10-08 16:40 UTC|newest]
Thread overview: 9+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-10-08 16:40 [PATCH v2 0/8] kbuild: fix memory safety and UB bugs in host tools found by fuzzing Leizhen Zhang
2026-10-08 16:40 ` Leizhen Zhang [this message]
2026-10-08 16:40 ` [PATCH v2 2/8] fixdep: fix out-of-bounds read on a comment ending with a backslash Leizhen Zhang
2026-10-08 16:40 ` [PATCH v2 3/8] kallsyms: do not call qsort() with a NULL table Leizhen Zhang
2026-10-08 16:40 ` [PATCH v2 4/8] modpost: fix stack out-of-bounds read for unterminated PNP ids Leizhen Zhang
2026-10-08 16:40 ` [PATCH v2 5/8] modpost: fix handling of short reads in read_text_file() Leizhen Zhang
2026-10-08 16:40 ` [PATCH v2 6/8] modpost: fix pointer arithmetic on NULL in parse_source_files() Leizhen Zhang
2026-10-08 16:40 ` [PATCH v2 7/8] sorttable: avoid pointer arithmetic overflow when locating sort_needed Leizhen Zhang
2026-10-08 16:40 ` [PATCH v2 8/8] tools/include: fix signed shift overflow in 32-bit unaligned accessors Leizhen Zhang
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20261008164035.3668885-2-lzsx618@gmail.com \
--to=lzsx618@gmail.com \
--cc=linux-kbuild@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=nathan@kernel.org \
--cc=nsc@kernel.org \
--cc=rostedt@goodmis.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®