mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* [PATCH] lib/test_meminit: handle kmem_cache_alloc() failure
@ 2026-10-09  7:30 Tuo Li
  2026-10-10 23:08 ` Andrew Morton
  0 siblings, 1 reply; 2+ messages in thread
From: Tuo Li @ 2026-10-09  7:30 UTC (permalink / raw)
  To: akpm; +Cc: linux-kernel, Tuo Li

In do_kmem_cache_size(), kmem_cache_alloc() may fail and return NULL.
The returned pointer is subsequently passed to check_buf() and
fill_with_garbage_skip() without being checked, which may result in a
NULL pointer dereference.

Handle the allocation failure by marking the test as failed and
continuing with the next iteration.

Fixes: 5015a300a522 ("lib: introduce test_meminit module")
Signed-off-by: Tuo Li <islituo@gmail.com>
---
 lib/test_meminit.c | 4 ++++
 1 file changed, 4 insertions(+)

diff --git a/lib/test_meminit.c b/lib/test_meminit.c
index 68c3b9da090e..db4b4398e1c1 100644
--- a/lib/test_meminit.c
+++ b/lib/test_meminit.c
@@ -241,6 +241,10 @@ static int __init do_kmem_cache_size(size_t size, bool want_ctor,
 		}
 
 		buf = kmem_cache_alloc(c, alloc_mask);
+		if (!buf) {
+			fail = true;
+			continue;
+		}
 		/* Check that buf is zeroed, if it must be. */
 		fail |= check_buf(buf, size, want_ctor, want_rcu, want_zero);
 		fill_with_garbage_skip(buf, size, want_ctor ? CTOR_BYTES : 0);
-- 
2.43.0


^ permalink raw reply	[flat|nested] 2+ messages in thread

* Re: [PATCH] lib/test_meminit: handle kmem_cache_alloc() failure
  2026-10-09  7:30 [PATCH] lib/test_meminit: handle kmem_cache_alloc() failure Tuo Li
@ 2026-10-10 23:08 ` Andrew Morton
  0 siblings, 0 replies; 2+ messages in thread
From: Andrew Morton @ 2026-10-10 23:08 UTC (permalink / raw)
  To: Tuo Li; +Cc: linux-kernel

On Fri,  9 Oct 2026 15:30:40 +0800 Tuo Li <islituo@gmail.com> wrote:

> In do_kmem_cache_size(), kmem_cache_alloc() may fail and return NULL.
> The returned pointer is subsequently passed to check_buf() and
> fill_with_garbage_skip() without being checked, which may result in a
> NULL pointer dereference.
> 
> Handle the allocation failure by marking the test as failed and
> continuing with the next iteration.
> 
> ...
>
> --- a/lib/test_meminit.c
> +++ b/lib/test_meminit.c
> @@ -241,6 +241,10 @@ static int __init do_kmem_cache_size(size_t size, bool want_ctor,
>  		}
>  
>  		buf = kmem_cache_alloc(c, alloc_mask);
> +		if (!buf) {
> +			fail = true;
> +			continue;
> +		}
>  		/* Check that buf is zeroed, if it must be. */
>  		fail |= check_buf(buf, size, want_ctor, want_rcu, want_zero);
>  		fill_with_garbage_skip(buf, size, want_ctor ? CTOR_BYTES : 0);

Thanks, but we have an assumption that __init-time allocations cannot
fail and so they don't need to be checked.  Because if they do fail,
something has gone horribly wrong and this kernel cannot work and a
later null-deref of "buf" is a suitable way of reporting this.



^ permalink raw reply	[flat|nested] 2+ messages in thread

end of thread, other threads:[~2026-10-10 23:08 UTC | newest]

Thread overview: 2+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-10-09  7:30 [PATCH] lib/test_meminit: handle kmem_cache_alloc() failure Tuo Li
2026-10-10 23:08 ` Andrew Morton

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®