HomeFreeBSD

vm_phys: Check `RB_FIND()` return value in case it is NULL

Description

vm_phys: Check RB_FIND() return value in case it is NULL

When trying to unregister a fictitious range in
vm_phys_fictitious_unreg_range(), the function checks the properties
of the looked up segment, but it does not check if a segment was found
in the first place.

This can happen with the amdgpu DRM driver which could call
vm_phys_fictitious_unreg_range() without a fictitious range registered
if the initialisation of the driver failed (for example because
firmwares are unavailable).

The code in the DRM driver was improved to avoid that, but
vm_phys_fictitious_unreg_range() should still check the return value
of RB_FIND() before trying to dereference the segment pointer and
panic with a page fault.

Reviewed by: emaste
Sponsored by: The FreeBSD Foundation
Differential Revision: https://reviews.freebsd.org/D55076

Details

Provenance
dumbbellAuthored on Feb 3 2026, 12:04 PM
Reviewer
emaste
Differential Revision
D55076: vm_phys: Check `RB_FIND()` return value in case it is NULL
Parents
rGd70b9eb74fc4: libc/tests: Clean up *dir() tests
Branches
Unknown
Tags
Unknown