From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from mail.openvz.org (unknown [69.168.225.77]) by lore.virtuozzo.com (Postfix) with ESMTPS id 3C8088013F for ; Fri, 4 Sep 2026 01:59:01 +0000 (UTC) Received: from mail.openvz.org (localhost [127.0.0.1]) by mail.openvz.org (8.14.4/8.14.4) with ESMTP id 6841viNx026809; Fri, 4 Sep 2026 04:57:46 +0300 DKIM-Filter: OpenDKIM Filter v2.11.0 mail.openvz.org 6841viNx026809 Authentication-Results: mail.openvz.org; dkim=fail reason="signature verification failed" (2048-bit key) header.d=virtuozzo.com header.i=@virtuozzo.com header.b="TPKhaC3O" Received: from mail-wm1-f70.google.com (mail-wm1-f70.google.com [209.85.128.70]) by mail.openvz.org (8.14.4/8.14.4) with ESMTP id 6841vhFB026803 (version=TLSv1/SSLv3 cipher=AES128-GCM-SHA256 bits=128 verify=FAIL) for ; Fri, 4 Sep 2026 04:57:43 +0300 DKIM-Filter: OpenDKIM Filter v2.11.0 mail.openvz.org 6841vhFB026803 Received: by mail-wm1-f70.google.com with SMTP id 5b1f17b1804b1-495474a5fbcso3948245e9.1 for ; Thu, 03 Sep 2026 18:57:43 -0700 (PDT) X-Gm-Message-State: AFuF++mnxWkk3sH3Mns5BTGRlPfJ5zd5D2VOSwAlOeqP7XPSLyrH/5sb Gsw6XNoNncQSoNijXwGwF23VOIJ4zs3WUVwKrGUISZgwxUv3avjhVnx+/Wv2lhal/Np+2L/uerE BmO6pHkP67QfuqWJMX1OrpNii15ntLdsHLH90nMwLw6RggXC5ib7PnA== X-Gm-Gg: AYBFou3Ku77XM0fr3aSsA6eWhSFOICZgT0q1dLZSRXjTAvJkhPNIX37uSFFaWUBtRxW r/FEcX88RjXAs93JIUE5Gb7CoeDJmP2Tlu0GhlF7dY0vFrYTq4tGyoV43qKj+R4+l+7KtgjL/ZI 74PKFxlLEL5rgYbAZ/mjKb0Hdllu10WHJJLM+rO9JH1LorrfZuehfusMYOQOgg30sXR1Ebtfil+ uqRi/Z5BtegMAL36ArD3SMP7ihCctznIgppsuNJXi00Sd9oc1QC4PznBaNG6D1ddqA6PsfdFzeO yjGSDZtuyhyrpN/GorHhnC2+YgjMOzJQcIlUq2HvMwXWmtXMCzMLcFFtby61kkENvnGt/d39cAP dgoegLkIVLM+n919e X-Received: by 2002:a05:600c:19d1:b0:49c:fc6e:8cbb with SMTP id 5b1f17b1804b1-49cfc6e8e05mr78545e9.31.1788487063141; Thu, 03 Sep 2026 18:57:43 -0700 (PDT) X-Received: by 2002:a05:600c:19d1:b0:49c:fc6e:8cbb with SMTP id 5b1f17b1804b1-49cfc6e8e05mr78335e9.31.1788487062672; Thu, 03 Sep 2026 18:57:42 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1788487062; cv=none; d=google.com; s=arc-20260327; b=qhFsghSRIUQHePtlrlqjboXqBw+l/tp/JU2hbyU66/JQ+uJbl6o8APqYJczmdyAy5n 19t32cB7jATiQb2qpwZza2Q5O0srNXcmM2Ogc6IlQy+kZfLeO2Yp7CVnR4BgwJ4IfKg7 a6HC5DWLV2hmHRosVOW4bh4BVeA1a9MsFnE33CpacddSx9G9PbohyVBP3yqO5xEI7Cb8 AJiRc1/qW743Qfb0xi0B1n+d8u8SGrlnn9/7r2DJZ8DNYkI19/cckrWTZsKLGnawKbzY de8zJC8FV6PDw3roCrCfI5Oy/C5mRxTQA6PaITIp+Q4lAKN+FWJ98fiUVh2XE+Qqf9ih POzA== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20260327; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:dkim-signature; bh=WRSPn64XfPqptV7dTmQ8UtO/V6JN02VWkhkj3zuvEI0=; fh=CyEa5k0km+zUBGOSzDGfbole2hTjTZicm1CHqnc8J2I=; b=F43bahS63iRPHFkeP8m9Dg9ioW3p30IQYS+/Bv+B73zxurMYOdIWLG/TpHrl2K611d w+LqL09Yza1WJ7TVTRMk/jD/ebbCi3mV7DftHZVdykDzvsifhlHH905SBCXW8wI8dhp/ dw5UDxRtwvrgaREvNAop4lkGAlGTZ9ZdHZOVvI34ajB0IBtm3Yz89iDlE23nS3i97ldW 0wUWOt0FbwV74CKZ6x1z2Rz2y2ojdIZrGnNrmIpi/xwQBqXH680MfeQpifJQptyLRiCp kc3tpveb2AvS5JKVaMyOeuDLmoLD1P/nqLeGxcneaF2EbgaU3fIDQ02EioxUMJXnMmc4 J17g==; dara=google.com ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@virtuozzo.com header.s=relay header.b=TPKhaC3O; spf=pass (google.com: domain of kui.liu@virtuozzo.com designates 130.117.225.111 as permitted sender) smtp.mailfrom=kui.liu@virtuozzo.com; dmarc=pass (p=QUARANTINE sp=QUARANTINE dis=NONE) header.from=virtuozzo.com Received: from relay.virtuozzo.com (relay.virtuozzo.com. [130.117.225.111]) by mx.google.com with ESMTPS id ffacd0b85a97d-485885b8bd1si2333579f8f.189.2026.09.03.18.57.42 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 03 Sep 2026 18:57:42 -0700 (PDT) Received-SPF: pass (google.com: domain of kui.liu@virtuozzo.com designates 130.117.225.111 as permitted sender) client-ip=130.117.225.111; Authentication-Results: mx.google.com; dkim=pass header.i=@virtuozzo.com header.s=relay header.b=TPKhaC3O; spf=pass (google.com: domain of kui.liu@virtuozzo.com designates 130.117.225.111 as permitted sender) smtp.mailfrom=kui.liu@virtuozzo.com; dmarc=pass (p=QUARANTINE sp=QUARANTINE dis=NONE) header.from=virtuozzo.com DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=virtuozzo.com; s=relay; h=MIME-Version:Message-ID:Date:Subject:From: Content-Type; bh=WRSPn64XfPqptV7dTmQ8UtO/V6JN02VWkhkj3zuvEI0=; b=TPKhaC3OTHqJ 0Gsgj7Tskn4B18TMBGznzmfM6NTiREcQ3wGpKI/jUvS8Y324AV7d1BNlPPd5Tl/KXEc2c6AuntOn6 R+it7tq8XK1K+1rV3SYjRlU4wkzB1QpSGzZNWIEkqpWor2+8X9MOmZ996UPe2CuDKLv7OyqgLRytY RW0/PwGMwo8cJLjXdgaaxzIvuD5X7ikE+7EWgMsDcoJXxcLryslGWsbXCvUVJdNxE2zzcEzR6kn1A o2cKXa2uqSwNzmo/gLOgdx0rv+RKYxBYa2LS9f5MKLbRfCON/yFianRClxOZ0iGUprgnySdFIp9ne OTXXXugk06uuz6AxHiMZzw==; Received: from ch-vpn.virtuozzo.com ([130.117.225.6] helo=localhost.localdomain) by relay.virtuozzo.com with esmtp (Exim 4.96) (envelope-from ) id 1x2J93-008rqv-2p; Fri, 04 Sep 2026 03:57:39 +0200 From: Liu Kui To: devel@openvz.org Date: Fri, 4 Sep 2026 09:57:33 +0800 Message-ID: <20260904015733.23940-1-kui.liu@virtuozzo.com> X-Mailer: git-send-email 2.50.1 MIME-Version: 1.0 X-OZ-Fwd: true Cc: azaitsev@virtuozzo.com, Liu Kui Subject: [Devel] [PATCH VZ10] fs/fuse kio: fix use of uninitialized data chunk counter on error path X-BeenThere: devel@openvz.org X-Mailman-Version: 2.1.12 Precedence: list List-Id: OpenVZ development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: 7bit Sender: devel-bounces@openvz.org Errors-To: devel-bounces@openvz.org In kreq_make_sendmsg(), the data chunk counter nr_data_chunks is reset only after the header chunk has been set up. If mapping the header chunk fails, the error path calls kreq_release_data_chunks() with an uninitialized counter value, so it walks garbage chunk entries, triggering the "Invalid chunk type" warning and potentially freeing the wrong memory . Fix this by resetting the counter before the first error exit. https://virtuozzo.atlassian.net/browse/VSTOR-143521 Signed-off-by: Liu Kui --- fs/fuse/kio/pcs/pcs_krpc.c | 7 ++++--- 1 file changed, 4 insertions(+), 3 deletions(-) diff --git a/fs/fuse/kio/pcs/pcs_krpc.c b/fs/fuse/kio/pcs/pcs_krpc.c index 0930fb4adf12..fc7bddf6bb97 100644 --- a/fs/fuse/kio/pcs/pcs_krpc.c +++ b/fs/fuse/kio/pcs/pcs_krpc.c @@ -499,6 +499,10 @@ static int kreq_make_sendmsg(struct krpc_req *kreq) kreq->data_chunks = &kreq->inline_data_chunks[0]; } + kreq->data_len = 0; + kreq->nr_data_chunks = 0; + kreq->nr_data_bvecs = 0; + /* * Header buff is exactly one page, used for staging message header. Will be used for * receiving header of response message as well. @@ -523,9 +527,6 @@ static int kreq_make_sendmsg(struct krpc_req *kreq) kreq->hdr_kv.iov_len = chunk->len; /* data chunk buf descriptors are placed at end of header buf, grow backwards */ - kreq->data_len = 0; - kreq->nr_data_chunks = 0; - kreq->nr_data_bvecs = 0; chunk_bd = (struct pcs_krpc_buf_desc *)(kreq->hdr_buf + PAGE_SIZE) - 1; chunk = kreq->data_chunks; -- 2.50.1 (Apple Git-155) _______________________________________________ Devel mailing list Devel@openvz.org https://lists.openvz.org/mailman/listinfo/devel