Re: [PATCH] md/raid0: validate device count before allocating devlist
From: sashiko-bot@kernel.org
Date: 2026-09-06 14:55:19
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider: - [Medium] The newly added validation `if (nr_devs < mddev->raid_disks)` uses signed integer comparison, which can be bypassed if `mddev->raid_disks` is set to a negative value from user-space, resulting in an incomplete fix. -- commit b0e2bd0b0a05bf7824ef3d801efa4d7542d36bbc Author: Chandradhar Kumar [off-list ref] md/raid0: validate device count before allocating devlist This commit adds early validation to check if there are enough member devices before allocating the device list. It aims to prevent excessive allocations that trigger warnings on invalid configurations. Link: https://syzbot.org/bug?extid=a32ff75e417c0f49a8e9
quoted hunk ↗ jump to hunk
diff --git a/drivers/md/raid0.c b/drivers/md/raid0.c index 35e103f0c2c3e..586e3411f24c1 100644 --- a/drivers/md/raid0.c +++ b/drivers/md/raid0.c
[ ... ]
quoted hunk ↗ jump to hunk
@@ -147,6 +150,14 @@ static int create_strip_zones(struct mddev *mddev, struct r0conf **private_conf) conf->strip_zone = kvzalloc_objs(struct strip_zone, conf->nr_strip_zones); if (!conf->strip_zone) goto abort; + + if (nr_devs < mddev->raid_disks) {
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
[Severity: Medium]
Does this signed comparison allow bypassing the early abort if a negative
value is provided from user-space?
If a user issues the SET_ARRAY_INFO ioctl with a negative value for
raid_disks, it gets assigned directly without validation:
drivers/md/md.c:md_set_array_info() {
...
mddev->raid_disks = info->raid_disks;
...
}
When followed by the RUN_ARRAY ioctl, this validation check in
create_strip_zones() evaluates to false (e.g., 1 < -1). This bypasses the
check and allows the negative value to be cast to SIZE_MAX in array3_size()
which is then passed to kvzalloc().
Could this trigger the exact same warning for huge memory allocations that
this patch was explicitly intended to fix?
+ pr_warn("md/raid0:%s: too few disks (%d of %d) - aborting!\n",
+ mdname(mddev), nr_devs, mddev->raid_disks);
+ err = -EINVAL;
+ goto abort;
+ }
+
conf->devlist = kvzalloc(array3_size(sizeof(struct md_rdev *),
conf->nr_strip_zones,
mddev->raid_disks),-- Sashiko AI review · https://sashiko.dev/#/patchset/20260906143928.105165-1-chandradhar.2003@gmail.com?part=1