From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-wm1-f48.google.com (mail-wm1-f48.google.com [209.85.128.48]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id D5D67375F67 for ; Fri, 6 Mar 2026 22:11:55 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.128.48 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1772835117; cv=none; b=bVjSVg5+GtYufGEDpGNOTKHK0h0rONJWzO8UV+A0a6XOLykENV9iDk/BwI4SsNdZtRsE9lcbSkxt7d19KwkkXptu7ENyopoUZfdjMkqyH5PX+LVJ4998Jg3h5krcOASpNyeKvM9MAb+Dj6qZMmeMmOwz4Jb7Y/tFAXu9zoFMnkI= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1772835117; c=relaxed/simple; bh=gWBTEsjlrnIpMOQE5lEBCxyKb30jpD/7gGFqD2xtKL8=; h=Date:From:To:Cc:Message-ID:In-Reply-To:References:Subject: MIME-Version:Content-Type; b=bxCrU3ARMCtzxx8O78pp1pdQnI5EsZAdUr4/TbQ0Ul2ZzVU3ZruB8qpusMNt8YlABj/teYslIm3yplAiMliXQBpLXaR/BL+JS3jwzVuboPrFI2jPjphIQGiSpSCMSxPUyaSwQW2MrtZ/xjzsKeDBgAU/DkB+XkkrZuRH3uF/cSs= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=TJ2CuymY; arc=none smtp.client-ip=209.85.128.48 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="TJ2CuymY" Received: by mail-wm1-f48.google.com with SMTP id 5b1f17b1804b1-4837634de51so42437255e9.1 for ; Fri, 06 Mar 2026 14:11:55 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20230601; t=1772835114; x=1773439914; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:subject:references :in-reply-to:message-id:cc:to:from:date:from:to:cc:subject:date :message-id:reply-to; bh=gWBTEsjlrnIpMOQE5lEBCxyKb30jpD/7gGFqD2xtKL8=; b=TJ2CuymY7gYvWcvZseNCviRc9IsL2jj+t8kDhZ6LU0XAQm8Fq1e5syIlfC5KBK7ZwB Z9OgPWXotv8D5625PcT6aKOLneqqBLY9Aje2O2/UzRwfAIkUrwRo25sN4x8rrrYS/Fuy BIARHljPPYZbPUDt5KgGdEit++9jvNRW9eshw1AE/rxvcnK/O3s8BzveJgljxgiYNfNw azOTsy87ySYWPGq+wjyp637PExA3uz+9h/x9Sl1QOCTD6j/fQWb7yoztqAq17/JKm6p2 Ur5SarNTLzPAuAnHmpACawxV9byhhgdAUaWNvkuQKD590lIGy1QWnGqGvit41xdrXwvl Iomg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1772835114; x=1773439914; h=content-transfer-encoding:mime-version:subject:references :in-reply-to:message-id:cc:to:from:date:x-gm-gg:x-gm-message-state :from:to:cc:subject:date:message-id:reply-to; bh=gWBTEsjlrnIpMOQE5lEBCxyKb30jpD/7gGFqD2xtKL8=; b=mFb9AkSxfh860BtFuey48tQpe/PIgqQlAr+V92UW/JAYPAn2XcRwscNxKE3lWKT1uh yq3kkgtkddBqzNFYk0JlfVc6Q7P0e3O23/6YpKV1vDKKarLzgD7NpSHDE74O5YX9m//P cq/YdFd2XzRywijxAhFFIsBoFifEHagk9OTQOwbPK4oNZoKXb40t7Q88BJLNo1fjahk+ 1g8L0M7dp/o5W+JhCIXXpzeq3U0132VMedlh5bT56IRStlR5PpBZM7ItxUiKEWk+BPZi ky+JjNlX3y7gfg89UU6tMVQRt8QpvcW46h7zOxlgVPlOTmTH/2BuUxy33EW29NgIaPHj DRdA== X-Forwarded-Encrypted: i=1; AJvYcCUIxb23murhZJCFOUQ31jYpo7ev7GoJaCHTgKrUHWtAylTKzWX73HxK73//NxQBKvdSfDOWlPogu0DZAqc=@vger.kernel.org X-Gm-Message-State: AOJu0Yx++Oicdy8RhmBm/nBidA7pJx1xKjytopp7tmooUT3LSN/7rsbx xPTHHvY06LIANRKaUb1XATowHIlBamjtwKBs5lxr8o0T412gLtf/C+s0 X-Gm-Gg: ATEYQzxWgRfdy7OkVyCDM4ncNTsF89xsJ85Q5A1UhT5biLhVrVtA6pRepDEbzVAdTJd nPce79MkWjNL39EpHJlmNEc398M1n0lNkHi2w3HOSB0nodDVJmm1HKLxC/fJC0hVTGhprlcT4LV 7priLa8Ng70CSsNKlaNnMgfZYWxI0lF6U4Gmo8lJLbajq5dfwgD8/RewcwF20W/XFT7j6hCraM2 O8fAzrbSjKGhJY7C+T8PXkX9ywrCu1LVXeqCsHwdHzqvc5VHaG2IG80igRqq8ug25k5ka516Fyp CKpqjbDfbSYn7nWtka9F+zLVQH9kApOr87fh4yLOnliQO8TJ39rD7sZzqgc7hhphC0uenFt3NU1 CkoZDKqnmhtRGmkyCsUjVaUXu99Hh1NIidzNn+j5zbeR7WkEDuN2pdo0LX2uvSByg4WQYpzYgpY s6K1Fqjdu2pG2tQRgo X-Received: by 2002:a05:600c:3e86:b0:477:9cdb:e337 with SMTP id 5b1f17b1804b1-48526918f8amr62531485e9.7.1772835113989; Fri, 06 Mar 2026 14:11:53 -0800 (PST) Received: from [127.0.0.1] ([86.1.69.5]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-48527681a3esm142962435e9.4.2026.03.06.14.11.53 (version=TLS1_3 cipher=TLS_AES_128_GCM_SHA256 bits=128/128); Fri, 06 Mar 2026 14:11:53 -0800 (PST) Date: Fri, 6 Mar 2026 22:11:54 +0000 From: Josh Law To: Andrew Morton Cc: Liam.Howlett@oracle.com, aliceryhl@google.com, andrewjballance@gmail.com, maple-tree@lists.infradead.org, linux-mm@kvack.org, linux-kernel@vger.kernel.org, Josh Law Message-ID: In-Reply-To: <20260306133321.4fa6c5a73067bd179a5e888e@linux-foundation.org> References: <20260306200820.2819999-1-objecting@objecting.org> <20260306133321.4fa6c5a73067bd179a5e888e@linux-foundation.org> Subject: Re: [PATCH] lib/maple_tree: fix swapped arguments in mas_safe_pivot() call Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: quoted-printable X-Correlation-ID: 6 Mar 2026 21:33:22 Andrew Morton : > On Fri,=C2=A0 6 Mar 2026 20:08:20 +0000 Josh Law = wrote: > >> From: Josh Law >> >> The call to mas_safe_pivot() in mas_wr_extend_null() has the pivot index >> and maple type arguments swapped. The function signature expects >> (mas, pivots, piv, type) but the call passes (mas, pivots, type, piv). >> >> This causes the pivot index to be interpreted as a maple node type and >> vice versa, leading to incorrect pivot lookups. In practice, this means >> a null-extending store into a maple tree node can read the wrong pivot >> value, potentially corrupting the range tracked by the maple state. For >> a VMA maple tree, this could cause an incorrect vm_area_struct range to >> be returned during operations like mmap or munmap, leading to silent >> memory mapping corruption. >> >> Every other mas_safe_pivot() call site in the file passes the arguments >> in the correct (piv, type) order; this is the only one with them >> reversed. >> >> ... >> >> --- a/lib/maple_tree.c >> +++ b/lib/maple_tree.c >> @@ -3279,7 +3279,7 @@ static inline void mas_extend_spanning_null(struct= ma_wr_state *l_wr_mas, >> =C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0 (r_mas->last < r_mas->max) && >> =C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0 !mas_slot_locked(r_mas, r_wr_= mas->slots, r_mas->offset + 1)) { >> =C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0 r_mas->last =3D mas_safe_pivo= t(r_mas, r_wr_mas->pivots, >> -=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2= =A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0 r_wr_= mas->type, r_mas->offset + 1); >> +=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2= =A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0 r_mas= ->offset + 1, r_wr_mas->type); >> =C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0 r_mas->offset++; >> =C2=A0=C2=A0=C2=A0 } > > Whoops.=C2=A0 How come nobody has noticed after 4+ years? > > I'll add > > =C2=A0=C2=A0=C2=A0 Fixes: 54a611b60590 ("Maple Tree: add new data structu= re") > > and maybe cc:stable if we have a reason to do so. Hi Andrew, on thought, I'd like to add Cc: stable@vger.kernel.org to this. Even though it's been 4 years, a swapped argument in a core data structure = like Maple Tree is a silent bug that could cause rare corruption. Better to= defuse it in the LTS kernels.