Page MenuHomeFreeBSD

vm_phys: Make sure that vm_phys_enq_chunk() stays in bounds
ClosedPublic

Authored by markj on Jun 14 2024, 4:03 PM.
Tags
None
Referenced Files
Unknown Object (File)
Mon, Oct 20, 10:33 PM
Unknown Object (File)
Fri, Oct 17, 9:25 PM
Unknown Object (File)
Fri, Oct 17, 1:06 PM
Unknown Object (File)
Fri, Oct 17, 1:21 AM
Unknown Object (File)
Mon, Oct 13, 12:35 AM
Unknown Object (File)
Sep 23 2025, 7:13 AM
Unknown Object (File)
Sep 20 2025, 11:51 AM
Unknown Object (File)
Aug 27 2025, 11:55 PM
Subscribers

Details

Reviewers
alc
dougm
kib
Summary

vm_phys_enq_chunk() inserts a run of pages into the buddy queues. When
lazy initialization is enabled, only the first page of each run is
initialized; vm_phys_enq_chunk() thus initializes the page following the
just-inserted run.

This fails to account for the possibility that the page following the
run doesn't belong to the segment. Handle that in vm_phys_enq_chunk().

Reported by: KASAN
Reported by: syzbot+1097ef4cee8dfb240e31@syzkaller.appspotmail.com
Fixes: b16b4c22d2d1 ("vm_page: Implement lazy page initialization")

Diff Detail

Repository
rG FreeBSD src repository
Lint
Lint Skipped
Unit
Tests Skipped
Build Status
Buildable 58175
Build 55063: arc lint + arc unit