Hao Zhang
b7f3090f19
mm/page_alloc: fix uninitialized variable
commit 8fe9ed44dc29fba0786b7e956d2e87179e407582 upstream.
The variable "compact_result" is not initialized in function
__alloc_pages_slowpath(). It causes should_compact_retry() to use an
uninitialized value.
Initialize variable "compact_result" with the value COMPACT_SKIPPED.
BUG: KMSAN: uninit-value in __alloc_pages_slowpath+0xee8/0x16c0 mm/page_alloc.c:4416
__alloc_pages_slowpath+0xee8/0x16c0 mm/page_alloc.c:4416
__alloc_frozen_pages_noprof+0xa4c/0xe00 mm/page_alloc.c:4752
alloc_pages_mpol+0x4cd/0x890 mm/mempolicy.c:2270
alloc_frozen_pages_noprof mm/mempolicy.c:2341 [inline]
alloc_pages_noprof mm/mempolicy.c:2361 [inline]
folio_alloc_noprof+0x1dc/0x350 mm/mempolicy.c:2371
filemap_alloc_folio_noprof+0xa6/0x440 mm/filemap.c:1019
__filemap_get_folio+0xb9a/0x1840 mm/filemap.c:1970
grow_dev_folio fs/buffer.c:1039 [inline]
grow_buffers fs/buffer.c:1105 [inline]
__getblk_slow fs/buffer.c:1131 [inline]
bdev_getblk+0x2c9/0xab0 fs/buffer.c:1431
getblk_unmovable include/linux/buffer_head.h:369 [inline]
ext4_getblk+0x3b7/0xe50 fs/ext4/inode.c:864
ext4_bread_batch+0x9f/0x7d0 fs/ext4/inode.c:933
__ext4_find_entry+0x1ebb/0x36c0 fs/ext4/namei.c:1627
ext4_lookup_entry fs/ext4/namei.c:1729 [inline]
ext4_lookup+0x189/0xb40 fs/ext4/namei.c:1797
__lookup_slow+0x538/0x710 fs/namei.c:1793
lookup_slow+0x6a/0xd0 fs/namei.c:1810
walk_component fs/namei.c:2114 [inline]
link_path_walk+0xf29/0x1420 fs/namei.c:2479
path_openat+0x30f/0x6250 fs/namei.c:3985
do_filp_open+0x268/0x600 fs/namei.c:4016
do_sys_openat2+0x1bf/0x2f0 fs/open.c:1428
do_sys_open fs/open.c:1443 [inline]
__do_sys_openat fs/open.c:1459 [inline]
__se_sys_openat fs/open.c:1454 [inline]
__x64_sys_openat+0x2a1/0x310 fs/open.c:1454
x64_sys_call+0x36f5/0x3c30 arch/x86/include/generated/asm/syscalls_64.h:258
do_syscall_x64 arch/x86/entry/common.c:52 [inline]
do_syscall_64+0xcd/0x1e0 arch/x86/entry/common.c:83
entry_SYSCALL_64_after_hwframe+0x77/0x7f
Local variable compact_result created at:
__alloc_pages_slowpath+0x66/0x16c0 mm/page_alloc.c:4218
__alloc_frozen_pages_noprof+0xa4c/0xe00 mm/page_alloc.c:4752
Link: https://lkml.kernel.org/r/tencent_ED1032321D6510B145CDBA8CBA0093178E09@qq.com
Reported-by: syzbot+0cfd5e38e96a5596f2b6@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=0cfd5e38e96a5596f2b6
Signed-off-by: Hao Zhang <zhanghao1@kylinos.cn>
Reviewed-by: Vlastimil Babka <vbabka@suse.cz>
Cc: Michal Hocko <mhocko@kernel.org>
Cc: Mel Gorman <mgorman@techsingularity.net>
Cc: <stable@vger.kernel.org>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
|
2025-03-13 12:43:28 +01:00 |
| .. |
|
kasan
|
panic: Consolidate open-coded panic_on_warn checks
|
2023-02-06 07:52:50 +01:00 |
|
backing-dev.c
|
mm: bdi: initialize bdi_min_ratio when bdi is unregistered
|
2021-12-14 14:49:00 +01:00 |
|
balloon_compaction.c
|
|
|
|
cleancache.c
|
|
|
|
cma.c
|
mm/cma: use nth_page() in place of direct struct page manipulation
|
2023-11-28 16:50:19 +00:00 |
|
cma.h
|
|
|
|
cma_debug.c
|
|
|
|
compaction.c
|
mm, vmscan: prevent infinite loop for costly GFP_NOIO | __GFP_RETRY_MAYFAIL allocations
|
2024-04-13 12:51:34 +02:00 |
|
debug.c
|
|
|
|
debug_page_ref.c
|
|
|
|
dmapool.c
|
|
|
|
early_ioremap.c
|
|
|
|
fadvise.c
|
|
|
|
failslab.c
|
|
|
|
filemap.c
|
mm: allow a controlled amount of unfairness in the page lock
|
2023-08-30 16:27:26 +02:00 |
|
frame_vector.c
|
v4l2: don't fall back to follow_pfn() if pin_user_pages_fast() fails
|
2022-12-08 11:23:06 +01:00 |
|
frontswap.c
|
treewide: Remove uninitialized_var() usage
|
2023-06-09 10:29:01 +02:00 |
|
gup.c
|
mm/hugetlb: fix races when looking up a CONT-PTE/PMD size hugetlb page
|
2022-12-19 12:24:15 +01:00 |
|
gup_benchmark.c
|
|
|
|
highmem.c
|
|
|
|
hmm.c
|
|
|
|
huge_memory.c
|
mm/thp: check and bail out if page in deferred queue already
|
2023-03-11 16:44:05 +01:00 |
|
hugetlb.c
|
mm/hugetlb: fix races when looking up a CONT-PTE/PMD size hugetlb page
|
2022-12-19 12:24:15 +01:00 |
|
hugetlb_cgroup.c
|
|
|
|
hwpoison-inject.c
|
|
|
|
init-mm.c
|
|
|
|
internal.h
|
mm/thp: fix vma_address() if virtual address below file offset
|
2021-06-30 08:47:52 -04:00 |
|
interval_tree.c
|
|
|
|
Kconfig
|
mm/zsmalloc.c: drop ZSMALLOC_PGTABLE_MAPPING
|
2020-12-16 10:56:59 +01:00 |
|
Kconfig.debug
|
|
|
|
khugepaged.c
|
mm/khugepaged: fix collapse_pte_mapped_thp() to allow anon_vma
|
2023-01-24 07:18:01 +01:00 |
|
kmemleak-test.c
|
|
|
|
kmemleak.c
|
Revert "mm: kmemleak: take a full lowmem check in kmemleak_*_phys()"
|
2022-09-15 12:04:49 +02:00 |
|
ksm.c
|
treewide: Remove uninitialized_var() usage
|
2023-06-09 10:29:01 +02:00 |
|
list_lru.c
|
mm: list_lru: set shrinker map bit when child nr_items is not zero
|
2020-12-11 13:23:31 +01:00 |
|
maccess.c
|
|
|
|
madvise.c
|
mm: fix madivse_pageout mishandling on non-LRU page
|
2022-10-05 10:37:43 +02:00 |
|
Makefile
|
|
|
|
memblock.c
|
Revert "mm: Always release pages to the buddy allocator in memblock_free_late()."
|
2023-02-22 12:50:39 +01:00 |
|
memcontrol.c
|
memcg: fix soft lockup in the OOM process
|
2025-03-13 12:43:21 +01:00 |
|
memfd.c
|
memfd: fix F_SEAL_WRITE after shmem huge page allocated
|
2022-03-08 19:07:49 +01:00 |
|
memory-failure.c
|
mm/memory-failure: fix an incorrect use of tail pages
|
2024-04-13 12:51:31 +02:00 |
|
memory.c
|
mm: avoid leaving partial pfn mappings around in error case
|
2024-11-17 14:58:53 +01:00 |
|
memory_hotplug.c
|
mm/memory_hotplug: use "unsigned long" for PFN in zone_for_pfn_range()
|
2021-09-22 12:26:43 +02:00 |
|
mempolicy.c
|
treewide: Remove uninitialized_var() usage
|
2023-06-09 10:29:01 +02:00 |
|
mempool.c
|
|
|
|
memremap.c
|
|
|
|
memtest.c
|
memtest: use {READ,WRITE}_ONCE in memory scanning
|
2024-04-13 12:51:27 +02:00 |
|
migrate.c
|
mm/migrate: set swap entry values of THP tail pages properly.
|
2024-04-13 12:51:31 +02:00 |
|
mincore.c
|
|
|
|
mlock.c
|
|
|
|
mm_init.c
|
|
|
|
mmap.c
|
mm: Fix TLB flush for not-first PFNMAP mappings in unmap_region()
|
2022-09-20 12:28:00 +02:00 |
|
mmu_context.c
|
mm: fix kthread_use_mm() vs TLB invalidate
|
2020-09-03 11:26:51 +02:00 |
|
mmu_gather.c
|
mm/khugepaged: fix GUP-fast interaction by sending IPI
|
2022-12-14 11:30:42 +01:00 |
|
mmu_notifier.c
|
|
|
|
mmzone.c
|
arm: remove CONFIG_ARCH_HAS_HOLES_MEMORYMODEL
|
2022-05-15 19:54:46 +02:00 |
|
mprotect.c
|
|
|
|
mremap.c
|
mm/mremap: hold the rmap lock in write mode when moving page table entries.
|
2022-08-25 11:17:20 +02:00 |
|
msync.c
|
|
|
|
nommu.c
|
|
|
|
oom_kill.c
|
memcg: fix soft lockup in the OOM process
|
2025-03-13 12:43:21 +01:00 |
|
page-writeback.c
|
mm: avoid overflows in dirty throttling logic
|
2024-08-19 05:33:42 +02:00 |
|
page_alloc.c
|
mm/page_alloc: fix uninitialized variable
|
2025-03-13 12:43:28 +01:00 |
|
page_counter.c
|
|
|
|
page_ext.c
|
|
|
|
page_idle.c
|
|
|
|
page_io.c
|
mm: fix unexpected zeroed page mapping with zram swap
|
2022-05-12 12:23:48 +02:00 |
|
page_isolation.c
|
mm/memory_hotplug: drain per-cpu pages again during memory offline
|
2020-09-23 12:40:47 +02:00 |
|
page_owner.c
|
mm/page_owner: change split_page_owner to take a count
|
2020-10-29 09:57:52 +01:00 |
|
page_poison.c
|
|
|
|
page_vma_mapped.c
|
mm/thp: another PVMW_SYNC fix in page_vma_mapped_walk()
|
2021-06-30 08:47:55 -04:00 |
|
pagewalk.c
|
mm: pagewalk: Fix race between unmap and page walker
|
2022-10-15 07:54:36 +02:00 |
|
percpu-internal.h
|
|
|
|
percpu-km.c
|
|
|
|
percpu-stats.c
|
|
|
|
percpu-vm.c
|
|
|
|
percpu.c
|
treewide: Remove uninitialized_var() usage
|
2023-06-09 10:29:01 +02:00 |
|
pgtable-generic.c
|
mm/thp: fix __split_huge_pmd_locked() on shmem migration entry
|
2021-06-30 08:47:52 -04:00 |
|
process_vm_access.c
|
|
|
|
readahead.c
|
vfs: fix readahead(2) on block devices
|
2023-11-20 10:30:08 +01:00 |
|
rmap.c
|
mm/rmap: Fix anon_vma->degree ambiguity leading to double-reuse
|
2022-09-05 10:27:46 +02:00 |
|
rodata_test.c
|
|
|
|
shmem.c
|
mm: revert "mm: shmem: fix data-race in shmem_getattr()"
|
2024-12-14 19:44:19 +01:00 |
|
shuffle.c
|
mm/shuffle: don't move pages between zones and don't read garbage memmaps
|
2020-09-03 11:26:51 +02:00 |
|
shuffle.h
|
|
|
|
slab.c
|
|
|
|
slab.h
|
mm: kmemleak: slob: respect SLAB_NOLEAKTRACE flag
|
2021-11-26 10:47:21 +01:00 |
|
slab_common.c
|
mm: krealloc: Fix MTE false alarm in __do_krealloc
|
2024-11-08 16:20:54 +01:00 |
|
slob.c
|
|
|
|
slub.c
|
treewide: Remove uninitialized_var() usage
|
2023-06-09 10:29:01 +02:00 |
|
sparse-vmemmap.c
|
|
|
|
sparse.c
|
mm/sparse: add the missing sparse_buffer_fini() in error branch
|
2021-05-14 09:44:32 +02:00 |
|
swap.c
|
treewide: Remove uninitialized_var() usage
|
2023-06-09 10:29:01 +02:00 |
|
swap_cgroup.c
|
|
|
|
swap_slots.c
|
|
|
|
swap_state.c
|
mm/swap_state: fix a data race in swapin_nr_pages
|
2020-10-01 13:18:08 +02:00 |
|
swapfile.c
|
mm/swapfile: skip HugeTLB pages for unuse_vma
|
2024-11-08 16:20:47 +01:00 |
|
truncate.c
|
mm/thp: unmap_mapping_page() to fix THP truncate_cleanup_page()
|
2021-06-30 08:47:53 -04:00 |
|
usercopy.c
|
mm/usercopy: return 1 from hardened_usercopy __setup() handler
|
2022-04-15 14:18:30 +02:00 |
|
userfaultfd.c
|
userfaultfd: fix mmap_changing checking in mfill_atomic_hugetlb
|
2024-03-01 13:13:33 +01:00 |
|
util.c
|
mm: only enforce minimum stack gap size if it's sensible
|
2024-11-08 16:20:35 +01:00 |
|
vmacache.c
|
|
|
|
vmalloc.c
|
mm/vunmap: add cond_resched() in vunmap_pmd_range
|
2020-09-03 11:26:52 +02:00 |
|
vmpressure.c
|
|
|
|
vmscan.c
|
mm: vmscan: account for free pages to prevent infinite Loop in throttle_direct_reclaim()
|
2025-01-09 13:23:37 +01:00 |
|
vmstat.c
|
arm: remove CONFIG_ARCH_HAS_HOLES_MEMORYMODEL
|
2022-05-15 19:54:46 +02:00 |
|
workingset.c
|
|
|
|
z3fold.c
|
mm/z3fold: fix potential memory leak in z3fold_destroy_pool()
|
2021-07-14 16:53:47 +02:00 |
|
zbud.c
|
|
|
|
zpool.c
|
|
|
|
zsmalloc.c
|
zsmalloc: fix races between asynchronous zspage free and page migration
|
2022-06-06 08:33:50 +02:00 |
|
zswap.c
|
|
|