Re: [PATCH 1/1] zram: reject disksizes that exceed slot index range
Andrew Morton <[email protected]> Wed, 5 Aug 2026 11:54:24 -0700
| Newsgroups | org.kernel.vger.linux-block,org.kernel.vger.linux-kernel,org.kernel.vger.stable |
|---|---|
| Message-ID | <[email protected]> |
On Tue, 4 Aug 2026 22:38:32 +0800 Longlong Xia <[email protected]> wrote: > From: Longlong Xia <[email protected]> > > zram uses u32 slot indexes, while disksize_store() accepts a u64 > size. On 32-bit systems, a disksize larger than U32_MAX pages is > truncated when zram_meta_alloc() assigns the page count to size_t. > array_size() then sees only the truncated count, so a small table can > be allocated while the original capacity is published. Valid I/O > within that capacity can subsequently access beyond zram->table. > > The same oversized capacity also lets full-device scanners compare a > u32 index with an upper bound larger than U32_MAX, so the index can > wrap instead of terminating. > > Reject disksizes larger than U32_MAX pages before aligning and > allocating the table. This keeps the table size, published capacity and > slot index range consistent. Oh. Rejecting large devices sounds severe. Can't we just fix the 32-bit trucation issues? > --- a/drivers/block/zram/zram_drv.c > +++ b/drivers/block/zram/zram_drv.c > @@ -2876,6 +2876,9 @@ static ssize_t disksize_store(struct device *dev, struct device_attribute *attr, > return -EBUSY; > } > > + if (disksize > (u64)U32_MAX << PAGE_SHIFT) > + return -EINVAL; > + It would be helpful to have a comment explaining why we're doing this. AI review appears to have found a similar issue in mark_idle(), although it could be that your patch accidentally prevents it from occurring: https://sashiko.dev/#/patchset/[email protected]