Page MenuHomeFreeBSD

vm_phys: Make sure that vm_phys_enq_chunk() stays in bounds
AcceptedPublic

Authored by markj on Jun 14 2024, 4:03 PM.
Tags
None
Referenced Files
Unknown Object (File)
Fri, Sep 27, 6:34 AM
Unknown Object (File)
Thu, Sep 26, 2:51 PM
Unknown Object (File)
Mon, Sep 23, 4:04 PM
Unknown Object (File)
Sun, Sep 22, 2:09 PM
Unknown Object (File)
Sat, Sep 21, 5:09 PM
Unknown Object (File)
Sat, Sep 21, 4:51 PM
Unknown Object (File)
Wed, Sep 18, 6:13 PM
Unknown Object (File)
Wed, Sep 18, 10:16 AM
Subscribers

Details

Reviewers
alc
dougm
kib
Summary

vm_phys_enq_chunk() inserts a run of pages into the buddy queues. When
lazy initialization is enabled, only the first page of each run is
initialized; vm_phys_enq_chunk() thus initializes the page following the
just-inserted run.

This fails to account for the possibility that the page following the
run doesn't belong to the segment. Handle that in vm_phys_enq_chunk().

Reported by: KASAN
Reported by: syzbot+1097ef4cee8dfb240e31@syzkaller.appspotmail.com
Fixes: b16b4c22d2d1 ("vm_page: Implement lazy page initialization")

Diff Detail

Repository
rG FreeBSD src repository
Lint
Lint Skipped
Unit
Tests Skipped
Build Status
Buildable 58175
Build 55063: arc lint + arc unit