[PATCH 1/1] It needs to check offset array is NULL or not in async_xor_offs

Subsystems: asynchronous transfers/transforms (ioat) api, crypto api, the rest

STALE1926d

3 messages, 3 authors, 2021-06-01 · open the first message on its own page

[PATCH 1/1] It needs to check offset array is NULL or not in async_xor_offs

From: Xiao Ni <hidden>
Date: 2021-05-28 06:16:47

Now we support sharing one big page when PAGE_SIZE is not equal 4096.
4096 bytes is the default stripe size. To support this it adds a
page offset array in raid5_percpu's scribble. It passes the page
offset array to async_xor_offs. But there are some users that don't
use the page offset array. In raid5-ppl.c, async_xor passes NULL to
asynx_xor_offs. So it needs to check src_offs is NULL or not.

Fixes: ceaf2966ab08(async_xor: increase src_offs when dropping destination page)
Reported-by: Oleksandr Shchirskyi <redacted>
Signed-off-by: Xiao Ni <redacted>
---
 crypto/async_tx/async_xor.c | 3 ++-
 1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/crypto/async_tx/async_xor.c b/crypto/async_tx/async_xor.c
index 6cd7f70..d8a9152 100644
--- a/crypto/async_tx/async_xor.c
+++ b/crypto/async_tx/async_xor.c
@@ -233,7 +233,8 @@ async_xor_offs(struct page *dest, unsigned int offset,
 		if (submit->flags & ASYNC_TX_XOR_DROP_DST) {
 			src_cnt--;
 			src_list++;
-			src_offs++;
+			if (src_offs)
+				src_offs++;
 		}
 
 		/* wait for any prerequisite operations */
-- 
2.7.5

Re: [PATCH 1/1] It needs to check offset array is NULL or not in async_xor_offs

From: Song Liu <song@kernel.org>
Date: 2021-05-31 22:53:54

On Thu, May 27, 2021 at 11:16 PM Xiao Ni [off-list ref] wrote:
Now we support sharing one big page when PAGE_SIZE is not equal 4096.
4096 bytes is the default stripe size. To support this it adds a
page offset array in raid5_percpu's scribble. It passes the page
offset array to async_xor_offs. But there are some users that don't
use the page offset array. In raid5-ppl.c, async_xor passes NULL to
asynx_xor_offs. So it needs to check src_offs is NULL or not.

Fixes: ceaf2966ab08(async_xor: increase src_offs when dropping destination page)
Reported-by: Oleksandr Shchirskyi <redacted>
Signed-off-by: Xiao Ni <redacted>
Oleksandr,

Could you please verify this fixes the issue, and reply with your Tested-by?

Thanks,
Song
quoted hunk
---
 crypto/async_tx/async_xor.c | 3 ++-
 1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/crypto/async_tx/async_xor.c b/crypto/async_tx/async_xor.c
index 6cd7f70..d8a9152 100644
--- a/crypto/async_tx/async_xor.c
+++ b/crypto/async_tx/async_xor.c
@@ -233,7 +233,8 @@ async_xor_offs(struct page *dest, unsigned int offset,
                if (submit->flags & ASYNC_TX_XOR_DROP_DST) {
                        src_cnt--;
                        src_list++;
-                       src_offs++;
+                       if (src_offs)
+                               src_offs++;
                }

                /* wait for any prerequisite operations */
--
2.7.5

Re: [PATCH 1/1] It needs to check offset array is NULL or not in async_xor_offs

From: Oleksandr Shchirskyi <hidden>
Date: 2021-06-01 16:34:39

On 6/1/2021 12:53 AM, Song Liu wrote:
On Thu, May 27, 2021 at 11:16 PM Xiao Ni [off-list ref] wrote:
quoted
Now we support sharing one big page when PAGE_SIZE is not equal 4096.
4096 bytes is the default stripe size. To support this it adds a
page offset array in raid5_percpu's scribble. It passes the page
offset array to async_xor_offs. But there are some users that don't
use the page offset array. In raid5-ppl.c, async_xor passes NULL to
asynx_xor_offs. So it needs to check src_offs is NULL or not.

Fixes: ceaf2966ab08(async_xor: increase src_offs when dropping destination page)
Reported-by: Oleksandr Shchirskyi <redacted>
Signed-off-by: Xiao Ni <redacted>
Oleksandr,

Could you please verify this fixes the issue, and reply with your Tested-by?

Thanks,
Song
I can confirm that this patch fixes a NULL pointer dereference issue for me.
Thanks for the fix!

Tested-by: Oleksandr Shchirskyi <redacted>
quoted
---
  crypto/async_tx/async_xor.c | 3 ++-
  1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/crypto/async_tx/async_xor.c b/crypto/async_tx/async_xor.c
index 6cd7f70..d8a9152 100644
--- a/crypto/async_tx/async_xor.c
+++ b/crypto/async_tx/async_xor.c
@@ -233,7 +233,8 @@ async_xor_offs(struct page *dest, unsigned int offset,
                 if (submit->flags & ASYNC_TX_XOR_DROP_DST) {
                         src_cnt--;
                         src_list++;
-                       src_offs++;
+                       if (src_offs)
+                               src_offs++;
                 }

                 /* wait for any prerequisite operations */
--
2.7.5

Regards,
Oleksandr Shchirskyi
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help