From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-wm1-f45.google.com (mail-wm1-f45.google.com [209.85.128.45]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 5DB8C29D27D for ; Thu, 12 Mar 2026 20:57:50 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.128.45 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1773349071; cv=none; b=m00prNF/7yYi2g1DxI1Fh4uF3d/hnYOOeFTCFhnPyFFLBZ8fBetViOdwK03fTKdAinQ6sGhoch32lOOug5IpaI0GY0r0RuZt7KJBWGDRZYLMHHP5DpA1s0uhfvuWouEhKDpU+S9O5Wsgnf5BtDj2F+dQQxBXWMo/qfH22V+gdNw= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1773349071; c=relaxed/simple; bh=5TCU3IeL+CM9jwMcCHM5UD2nm48BrqqrHRJzKJccTi0=; h=Date:From:To:Cc:Message-ID:In-Reply-To:References:Subject: MIME-Version:Content-Type; b=fqb1roYgTCq6RsyP2yf+toiLoGC0NJp2ahQNbofLyzlcTf/Mk5QMh9PdHzjRXC1+yUzeyiYt+sa3hDwk5RRnxv7iu+HeBZRrxs015oUqpQDptsY0ncLqClKptnklecfydFI9Yo0AEiLaCGKVec1kq3hwNrypYPtASkykpBm6nvU= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=jpdapM2j; arc=none smtp.client-ip=209.85.128.45 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="jpdapM2j" Received: by mail-wm1-f45.google.com with SMTP id 5b1f17b1804b1-4853e1ce427so16295225e9.3 for ; Thu, 12 Mar 2026 13:57:50 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20230601; t=1773349069; x=1773953869; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:subject:references :in-reply-to:message-id:cc:to:from:date:from:to:cc:subject:date :message-id:reply-to; bh=5TCU3IeL+CM9jwMcCHM5UD2nm48BrqqrHRJzKJccTi0=; b=jpdapM2jWx6X3xqrXHOuhB1/x6KB96m+9q/ReCd/ny5e/81Nd/DjpuAWL3KTOYhEWj d/r9d2ceZ0G8/euY+LewxKJVMZ8E8V4y/3RENSlG6YVXoBs204NE1vKCpkM2ft4IRbd+ KOpcIJ+hxEUblzIvhAAoa6AUoJ4dx6PT4rXff+2lVl20zrv9AFUD/c3pf1pBrEtFd9rk y6yp3io4HgvLMi5hUihuiUwN548oj9hNL1a5qMKBc7Fyqt98L3bEnjwgqdNpwDV01o+9 MeTwJmD6Mw/UZmetnb0kjasgbk3EFrtL6Mq2vXxz0NRy/gjuyLeqITtk3bwjUM1feR7T A04A== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1773349069; x=1773953869; h=content-transfer-encoding:mime-version:subject:references :in-reply-to:message-id:cc:to:from:date:x-gm-gg:x-gm-message-state :from:to:cc:subject:date:message-id:reply-to; bh=5TCU3IeL+CM9jwMcCHM5UD2nm48BrqqrHRJzKJccTi0=; b=W839r2EfHIySv/tQQ1yZ7SRPcfm3GNEfPpNsRFpIzsWs/R2F6QE89Ox6OS2dYBuiOo iICJpRZBtjx3cdzMCGyfXhtYXn8Fwa2Xg0nKYnFUayb8aER1sCq3OSixhhkaepfnHjVw sO9a31bJ9wJjtv1U6W24RnxveT7zIjxFvNpAHufYjT2nacdqW6dOpwN+QcKOTQdhFX0A 6fuNODJCbXCGQr4UwiPnsJh7TEavHFtA9320a3+/Us5Sib1H5xMsUQXtK6WyLjvp9qYY 9Dn3Qp3jr9f4TjpwqoEBtqxE3RJ/nGW4WM3BIbfdSY1l5XMgWspr9Jafi55YwFi46N4V fMjQ== X-Forwarded-Encrypted: i=1; AJvYcCWEFW1+bHyGf9PMDcIMxQB2gRkfkD/TH9MCEkoSeJEZXcASlwzrNANSV2lyePiG9jbDeDtpv+Yku5YgjL8=@vger.kernel.org X-Gm-Message-State: AOJu0YwWaRRn70XBdvvDetnfZ0FSYmSgps4CC6ykHzkntyvEYJtYBhaR 8V/jjmnm/pOwhOfx3wNN2MNvwIuSPfLYnVsqmMrzW5E2B4Z0uy2e4J4/ X-Gm-Gg: ATEYQzz23UH/RNMYmcMOomTyGyTkH1wRyJv9ixoenFVZPBkDGLJFAX8WLZ5U9taYrSi i+/f/VN6xNz2/uegvhP1NafBCsIIc++rVCd6+sideWv+Vnz64k92Tr5hHOLm14w4sqpFYixS9ry WFsjidb/fZAWmQERLkFCcVfOLPJszK4gPQM6sZt6jFSiJmWV+ED0LA2KLbddHwF94N9Cqamwq5I oETccq4YlvbJoilcD48vsMg168goW2VyKzk7eN29q4KGurF8AyQXn6D01S/5pBH7ZUI7YSIfoKN 9I8x9f0L26GRr/tTPOmjIiE11YiA7gUYjkRRktRq9uZYMaDNHeCplJJVi1hyDt7EDpZEkW9X0yb 5ghgPubySwxkgFwEPGt7SHnESgtSmIv08xepwZzVpT3jDX+y6R8ZiByPRvvaVCSyVdlWJGeS/nX BW/Ixy4mAbvttU2pGCG531KBWRbg== X-Received: by 2002:a05:600c:4f8f:b0:485:3423:727d with SMTP id 5b1f17b1804b1-4855670c095mr12566595e9.26.1773349068753; Thu, 12 Mar 2026 13:57:48 -0700 (PDT) Received: from ?IPv6:::1? ([2a00:23ee:2968:90cb:1c6d:1979:bcad:501a]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-4855725572csm6531295e9.2.2026.03.12.13.57.47 (version=TLS1_3 cipher=TLS_AES_128_GCM_SHA256 bits=128/128); Thu, 12 Mar 2026 13:57:48 -0700 (PDT) Date: Thu, 12 Mar 2026 20:57:46 +0000 From: Josh Law To: Andrew Morton Cc: Matthew Wilcox , linux-fsdevel@vger.kernel.org, linux-mm@kvack.org, linux-kernel@vger.kernel.org, Josh Law Message-ID: <43bacae7-3891-417e-9384-20cede8eec6e@gmail.com> In-Reply-To: <20260312135514.e4fc0fa4c1f50e6fbda2644c@linux-foundation.org> References: <20260312181948.20020-1-objecting@objecting.org> <20260312181948.20020-2-objecting@objecting.org> <20260312135514.e4fc0fa4c1f50e6fbda2644c@linux-foundation.org> Subject: Re: [PATCH v3 1/2] lib/idr: fix infinite loop in idr_get_next() Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: quoted-printable X-Correlation-ID: <43bacae7-3891-417e-9384-20cede8eec6e@gmail.com> 12 Mar 2026 20:55:15 Andrew Morton : > On Thu, 12 Mar 2026 18:19:47 +0000 Josh Law wrote= : > >> In idr_get_next(), if the returned id from idr_get_next_ul() is greater >> than INT_MAX, the function issues a warning and returns NULL without >> updating the *nextid pointer. This causes a soft lockup for any caller >> iterating over an IDR (e.g. via idr_for_each_entry) because they will >> receive NULL, fail to advance their index, and repeatedly query the same >> state forever. > > This assumes that the idr_get_next() caller ignores the NULL return and > just keeps on looping.=C2=A0 Isn't that a caller bug and if so, do we nee= d > to defend against it here? The risk isn't just a single loop failure; it's that idr_get_next() breaks = the 'forward-progress' guarantee of the iterator. In macros like idr_for_each_entry_continue, if idr_get_next() returns NULL = without advancing the pointer, the caller is left in a permanent trap. Any = attempt to resume or retry the iteration results in an infinite loop of the= same warning because the index is never incremented past the problematic I= D. Advancing the pointer ensures the infrastructure is robust against these 's= oft lockups', even if the caller's error handling is imperfect..