From: Jiri Slaby <jirislaby@kernel.org>
To: 聂江磊 <niejianglei2021@163.com>, gregkh@linuxfoundation.org
Cc: linux-kernel@vger.kernel.org
Subject: Re: [PATCH] tty: vt: consolemap: Add missing kfree() in con_do_clear_unimap()
Date: Mon, 25 Apr 2022 09:09:35 +0200 [thread overview]
Message-ID: <b2363c1a-89e3-0de2-fe2a-3b529c8fb3e4@kernel.org> (raw)
In-Reply-To: <71d92931-ac01-be32-a7ef-9f533096ab49@kernel.org>
On 25. 04. 22, 8:59, Jiri Slaby wrote:
> Hi,
>
> On 09. 03. 22, 13:34, 聂江磊 wrote:
>> I found this bug by using clang static analyse checkers. I found that
>> function con_release_unimap() is only called in this
>> file(drivers/tty/vt/consolemap.c b/drivers/tty/vt/consolemap.c). There
>> are totally 5 times that con_release_unimap() is called
>> (line 430, 466, 522, 599, 673) while con_release_unimap() is not
>> followed by kfree() only in line 522. So I think it is a bug
>> and make this patch.
>>
>>
>> At 2022-03-03 10:06:30, "Jianglei Nie" <niejianglei2021@163.com> wrote:
>>> We should free p after con_release_unimap(p) like the call points of
>>> con_release_unimap() do in the same file.
>
> But this one does not free it on purpose, right? See below.
>
>>> This patch adds the missing kfree() after con_release_unimap(p).
>>>
>>> Signed-off-by: Jianglei Nie <niejianglei2021@163.com>
>>> ---
>>> drivers/tty/vt/consolemap.c | 1 +
>>> 1 file changed, 1 insertion(+)
>>>
>>> diff --git a/drivers/tty/vt/consolemap.c b/drivers/tty/vt/consolemap.c
>>> index d815ac98b39e..5279c3d27720 100644
>>> --- a/drivers/tty/vt/consolemap.c
>>> +++ b/drivers/tty/vt/consolemap.c
>>> @@ -520,6 +520,7 @@ static int con_do_clear_unimap(struct vc_data *vc)
>>> p->refcount++;
>>> p->sum = 0;
>>> con_release_unimap(p);
>>> + kfree(p);
>
> You've just broken con_set_unimap(), or do I miss something?
No, you did not. The interface is terrible and deserves cleanup.
I found this, likely related, syzkaller report in my INBOX:
https://lore.kernel.org/all/000000000000ee58d305bbe9197a@google.com/
Care to test the reproducer both with and without your change? Does your
patch fixes the issue. And if it does, could you add this to your patch:
Reported-by: syzbot+bcc922b19ccc64240b42@syzkaller.appspotmail.com
? So that syzbot verifies the patch.
Once you do all this, I will re-review the patch and the code. The code
is really very hard to follow, so I cannot decide whether your patch is
correct or not ATM.
And provided the above, I put a note to my TODO list to restructure the
code, so that people know what's going on there.
thanks,
--
js
prev parent reply other threads:[~2022-04-25 7:09 UTC|newest]
Thread overview: 6+ messages / expand[flat|nested] mbox.gz Atom feed top
2022-03-03 2:06 Jianglei Nie
2022-03-03 7:37 ` Greg KH
[not found] ` <4a7fe3ca.68b6.17f6eacb952.Coremail.niejianglei2021@163.com>
2022-03-09 13:40 ` Greg KH
2022-04-22 13:44 ` Greg KH
2022-04-25 6:59 ` Jiri Slaby
2022-04-25 7:09 ` Jiri Slaby [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=b2363c1a-89e3-0de2-fe2a-3b529c8fb3e4@kernel.org \
--to=jirislaby@kernel.org \
--cc=gregkh@linuxfoundation.org \
--cc=linux-kernel@vger.kernel.org \
--cc=niejianglei2021@163.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®