Thread (3 messages) 3 messages, 2 authors, 2025-08-02

[PATCH] fbdev: core: Add checks for vc_resize failures

flat view
STALE431d

From: Zsolt Kajtar <soci@c64.rulez.org>
Date: 2025-07-31 17:30:58
Subsystem: framebuffer console, framebuffer core, framebuffer layer, the rest · Maintainers: Helge Deller, Thomas Zimmermann, Simona Vetter, Linus Torvalds

Whenever fbcon resizes the framebuffer the virtual console size is set
to match the new geometry. This ensures that the content won't end up
off-screen.

But in very rare cases vc_resize() can fail. If one follows the syzbot
monthly reports then this isn't all that rare because allocation
fault injection can do that reliably. Usually the one in
fbcon_set_disp.

Handling these failures gracefully and rolling back the resize isn't
trivial effort, at least for me. So the next best thing is to add
BUG_ON() checks.

In theory these checks shouldn't trigger normally. But when they do
memory corruption is prevented.

One check was left out in fbcon_startup.c, that's not a mistake. It
needs more investigation as it triggers on boot for me.

Signed-off-by: Zsolt Kajtar <soci@c64.rulez.org>
---
 drivers/video/fbdev/core/fbcon.c | 8 ++++----
 1 file changed, 4 insertions(+), 4 deletions(-)
diff --git a/drivers/video/fbdev/core/fbcon.c b/drivers/video/fbdev/core/fbcon.c
index 2df480376..b9b65ae32 100644
--- a/drivers/video/fbdev/core/fbcon.c
+++ b/drivers/video/fbdev/core/fbcon.c
@@ -1144,7 +1144,7 @@ static void fbcon_init(struct vc_data *vc, bool init)
 		vc->vc_cols = new_cols;
 		vc->vc_rows = new_rows;
 	} else
-		vc_resize(vc, new_cols, new_rows);
+		BUG_ON(vc_resize(vc, new_cols, new_rows));
 
 	if (logo)
 		fbcon_prepare_logo(vc, info, cols, rows, new_cols, new_rows);
@@ -1412,7 +1412,7 @@ static void fbcon_set_disp(struct fb_info *info, struct fb_var_screeninfo *var,
 	rows = FBCON_SWAP(ops->rotate, info->var.yres, info->var.xres);
 	cols /= vc->vc_font.width;
 	rows /= vc->vc_font.height;
-	vc_resize(vc, cols, rows);
+	BUG_ON(vc_resize(vc, cols, rows));
 
 	if (con_is_visible(vc)) {
 		update_screen(vc);
@@ -2682,7 +2682,7 @@ static void fbcon_modechanged(struct fb_info *info)
 		rows = FBCON_SWAP(ops->rotate, info->var.yres, info->var.xres);
 		cols /= vc->vc_font.width;
 		rows /= vc->vc_font.height;
-		vc_resize(vc, cols, rows);
+		BUG_ON(vc_resize(vc, cols, rows));
 		updatescrollmode(p, info, vc);
 		scrollback_max = 0;
 		scrollback_current = 0;
@@ -2725,7 +2725,7 @@ static void fbcon_set_all_vcs(struct fb_info *info)
 		rows = FBCON_SWAP(ops->rotate, info->var.yres, info->var.xres);
 		cols /= vc->vc_font.width;
 		rows /= vc->vc_font.height;
-		vc_resize(vc, cols, rows);
+		BUG_ON(vc_resize(vc, cols, rows));
 	}
 
 	if (fg != -1)
-- 
2.30.2
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help