Re: [PATCH] drbd: Fix five use after free bugs in get_initial_state

From: kernel test robot
Date: Mon May 24 2021 - 09:50:38 EST


Hi Lv,

Thank you for the patch! Yet something to improve:

[auto build test ERROR on block/for-next]
[also build test ERROR on linux/master linus/master v5.13-rc3 next-20210524]
[If your patch is applied to the wrong git tree, kindly drop us a note.
And when submitting patch, we suggest to use '--base' as documented in
https://git-scm.com/docs/git-format-patch]

url: https://github.com/0day-ci/linux/commits/Lv-Yunlong/drbd-Fix-five-use-after-free-bugs-in-get_initial_state/20210524-191033
base: https://git.kernel.org/pub/scm/linux/kernel/git/axboe/linux-block.git for-next
config: m68k-allmodconfig (attached as .config)
compiler: m68k-linux-gcc (GCC) 9.3.0
reproduce (this is a W=1 build):
wget https://raw.githubusercontent.com/intel/lkp-tests/master/sbin/make.cross -O ~/bin/make.cross
chmod +x ~/bin/make.cross
# https://github.com/0day-ci/linux/commit/96d72dce0926dbbe4db1f95e5d04cc6b026d96f7
git remote add linux-review https://github.com/0day-ci/linux
git fetch --no-tags linux-review Lv-Yunlong/drbd-Fix-five-use-after-free-bugs-in-get_initial_state/20210524-191033
git checkout 96d72dce0926dbbe4db1f95e5d04cc6b026d96f7
# save the attached .config to linux build tree
COMPILER_INSTALL_PATH=$HOME/0day COMPILER=gcc-9.3.0 make.cross ARCH=m68k

If you fix the issue, kindly add following tag as appropriate
Reported-by: kernel test robot <lkp@xxxxxxxxx>

All error/warnings (new ones prefixed by >>):

>> drivers/block/drbd/drbd_state.c:1570:6: error: conflicting types for 'notify_device_state_change'
1570 | void notify_device_state_change(struct sk_buff *skb,
| ^~~~~~~~~~~~~~~~~~~~~~~~~~
In file included from drivers/block/drbd/drbd_state.c:20:
drivers/block/drbd/drbd_state_change.h:55:12: note: previous declaration of 'notify_device_state_change' was here
55 | extern int notify_device_state_change(struct sk_buff *,
| ^~~~~~~~~~~~~~~~~~~~~~~~~~
drivers/block/drbd/drbd_state.c: In function 'notify_device_state_change':
drivers/block/drbd/drbd_state.c:1580:9: error: 'return' with a value, in function returning void [-Werror=return-type]
1580 | return notify_device_state(skb, seq, device, &device_info, type);
| ^~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
drivers/block/drbd/drbd_state.c:1570:6: note: declared here
1570 | void notify_device_state_change(struct sk_buff *skb,
| ^~~~~~~~~~~~~~~~~~~~~~~~~~
drivers/block/drbd/drbd_state.c: In function 'broadcast_state_change':
>> drivers/block/drbd/drbd_state.c:1616:17: warning: cast between incompatible function types from 'int (*)(struct sk_buff *, unsigned int, struct drbd_resource_state_change *, enum drbd_notification_type)' to 'void (*)(struct sk_buff *, unsigned int, void *, enum drbd_notification_type)' [-Wcast-function-type]
1616 | last_func = (typeof(last_func))func; \
| ^
drivers/block/drbd/drbd_state.c:1629:3: note: in expansion of macro 'REMEMBER_STATE_CHANGE'
1629 | REMEMBER_STATE_CHANGE(notify_resource_state_change,
| ^~~~~~~~~~~~~~~~~~~~~
>> drivers/block/drbd/drbd_state.c:1616:17: warning: cast between incompatible function types from 'int (*)(struct sk_buff *, unsigned int, struct drbd_connection_state_change *, enum drbd_notification_type)' to 'void (*)(struct sk_buff *, unsigned int, void *, enum drbd_notification_type)' [-Wcast-function-type]
1616 | last_func = (typeof(last_func))func; \
| ^
drivers/block/drbd/drbd_state.c:1638:4: note: in expansion of macro 'REMEMBER_STATE_CHANGE'
1638 | REMEMBER_STATE_CHANGE(notify_connection_state_change,
| ^~~~~~~~~~~~~~~~~~~~~
>> drivers/block/drbd/drbd_state.c:1616:17: warning: cast between incompatible function types from 'int (*)(struct sk_buff *, unsigned int, struct drbd_peer_device_state_change *, enum drbd_notification_type)' to 'void (*)(struct sk_buff *, unsigned int, void *, enum drbd_notification_type)' [-Wcast-function-type]
1616 | last_func = (typeof(last_func))func; \
| ^
drivers/block/drbd/drbd_state.c:1661:4: note: in expansion of macro 'REMEMBER_STATE_CHANGE'
1661 | REMEMBER_STATE_CHANGE(notify_peer_device_state_change,
| ^~~~~~~~~~~~~~~~~~~~~
cc1: some warnings being treated as errors


vim +/notify_device_state_change +1570 drivers/block/drbd/drbd_state.c

a29728463b254c Andreas Gruenbacher 2014-07-31 1569
a29728463b254c Andreas Gruenbacher 2014-07-31 @1570 void notify_device_state_change(struct sk_buff *skb,
a29728463b254c Andreas Gruenbacher 2014-07-31 1571 unsigned int seq,
a29728463b254c Andreas Gruenbacher 2014-07-31 1572 struct drbd_device_state_change *device_state_change,
a29728463b254c Andreas Gruenbacher 2014-07-31 1573 enum drbd_notification_type type)
a29728463b254c Andreas Gruenbacher 2014-07-31 1574 {
a29728463b254c Andreas Gruenbacher 2014-07-31 1575 struct drbd_device *device = device_state_change->device;
a29728463b254c Andreas Gruenbacher 2014-07-31 1576 struct device_info device_info = {
a29728463b254c Andreas Gruenbacher 2014-07-31 1577 .dev_disk_state = device_state_change->disk_state[NEW],
a29728463b254c Andreas Gruenbacher 2014-07-31 1578 };
a29728463b254c Andreas Gruenbacher 2014-07-31 1579
96d72dce0926db Lv Yunlong 2021-05-24 1580 return notify_device_state(skb, seq, device, &device_info, type);
a29728463b254c Andreas Gruenbacher 2014-07-31 1581 }
a29728463b254c Andreas Gruenbacher 2014-07-31 1582
96d72dce0926db Lv Yunlong 2021-05-24 1583 int notify_peer_device_state_change(struct sk_buff *skb,
a29728463b254c Andreas Gruenbacher 2014-07-31 1584 unsigned int seq,
a29728463b254c Andreas Gruenbacher 2014-07-31 1585 struct drbd_peer_device_state_change *p,
a29728463b254c Andreas Gruenbacher 2014-07-31 1586 enum drbd_notification_type type)
a29728463b254c Andreas Gruenbacher 2014-07-31 1587 {
a29728463b254c Andreas Gruenbacher 2014-07-31 1588 struct drbd_peer_device *peer_device = p->peer_device;
a29728463b254c Andreas Gruenbacher 2014-07-31 1589 struct peer_device_info peer_device_info = {
a29728463b254c Andreas Gruenbacher 2014-07-31 1590 .peer_repl_state = p->repl_state[NEW],
a29728463b254c Andreas Gruenbacher 2014-07-31 1591 .peer_disk_state = p->disk_state[NEW],
a29728463b254c Andreas Gruenbacher 2014-07-31 1592 .peer_resync_susp_user = p->resync_susp_user[NEW],
a29728463b254c Andreas Gruenbacher 2014-07-31 1593 .peer_resync_susp_peer = p->resync_susp_peer[NEW],
a29728463b254c Andreas Gruenbacher 2014-07-31 1594 .peer_resync_susp_dependency = p->resync_susp_dependency[NEW],
a29728463b254c Andreas Gruenbacher 2014-07-31 1595 };
a29728463b254c Andreas Gruenbacher 2014-07-31 1596
96d72dce0926db Lv Yunlong 2021-05-24 1597 return notify_peer_device_state(skb, seq, peer_device, &peer_device_info, type);
a29728463b254c Andreas Gruenbacher 2014-07-31 1598 }
a29728463b254c Andreas Gruenbacher 2014-07-31 1599
a29728463b254c Andreas Gruenbacher 2014-07-31 1600 static void broadcast_state_change(struct drbd_state_change *state_change)
a29728463b254c Andreas Gruenbacher 2014-07-31 1601 {
a29728463b254c Andreas Gruenbacher 2014-07-31 1602 struct drbd_resource_state_change *resource_state_change = &state_change->resource[0];
a29728463b254c Andreas Gruenbacher 2014-07-31 1603 bool resource_state_has_changed;
a29728463b254c Andreas Gruenbacher 2014-07-31 1604 unsigned int n_device, n_connection, n_peer_device, n_peer_devices;
a29728463b254c Andreas Gruenbacher 2014-07-31 1605 void (*last_func)(struct sk_buff *, unsigned int, void *,
a29728463b254c Andreas Gruenbacher 2014-07-31 1606 enum drbd_notification_type) = NULL;
805cdb8bc6da87 Kees Cook 2020-06-03 1607 void *last_arg = NULL;
a29728463b254c Andreas Gruenbacher 2014-07-31 1608
a29728463b254c Andreas Gruenbacher 2014-07-31 1609 #define HAS_CHANGED(state) ((state)[OLD] != (state)[NEW])
a29728463b254c Andreas Gruenbacher 2014-07-31 1610 #define FINAL_STATE_CHANGE(type) \
a29728463b254c Andreas Gruenbacher 2014-07-31 1611 ({ if (last_func) \
a29728463b254c Andreas Gruenbacher 2014-07-31 1612 last_func(NULL, 0, last_arg, type); \
a29728463b254c Andreas Gruenbacher 2014-07-31 1613 })
a29728463b254c Andreas Gruenbacher 2014-07-31 1614 #define REMEMBER_STATE_CHANGE(func, arg, type) \
a29728463b254c Andreas Gruenbacher 2014-07-31 1615 ({ FINAL_STATE_CHANGE(type | NOTIFY_CONTINUES); \
a29728463b254c Andreas Gruenbacher 2014-07-31 @1616 last_func = (typeof(last_func))func; \
a29728463b254c Andreas Gruenbacher 2014-07-31 1617 last_arg = arg; \
a29728463b254c Andreas Gruenbacher 2014-07-31 1618 })
a29728463b254c Andreas Gruenbacher 2014-07-31 1619
a29728463b254c Andreas Gruenbacher 2014-07-31 1620 mutex_lock(&notification_mutex);
a29728463b254c Andreas Gruenbacher 2014-07-31 1621
a29728463b254c Andreas Gruenbacher 2014-07-31 1622 resource_state_has_changed =
a29728463b254c Andreas Gruenbacher 2014-07-31 1623 HAS_CHANGED(resource_state_change->role) ||
a29728463b254c Andreas Gruenbacher 2014-07-31 1624 HAS_CHANGED(resource_state_change->susp) ||
a29728463b254c Andreas Gruenbacher 2014-07-31 1625 HAS_CHANGED(resource_state_change->susp_nod) ||
a29728463b254c Andreas Gruenbacher 2014-07-31 1626 HAS_CHANGED(resource_state_change->susp_fen);
a29728463b254c Andreas Gruenbacher 2014-07-31 1627
a29728463b254c Andreas Gruenbacher 2014-07-31 1628 if (resource_state_has_changed)
a29728463b254c Andreas Gruenbacher 2014-07-31 1629 REMEMBER_STATE_CHANGE(notify_resource_state_change,
a29728463b254c Andreas Gruenbacher 2014-07-31 1630 resource_state_change, NOTIFY_CHANGE);
a29728463b254c Andreas Gruenbacher 2014-07-31 1631
a29728463b254c Andreas Gruenbacher 2014-07-31 1632 for (n_connection = 0; n_connection < state_change->n_connections; n_connection++) {
a29728463b254c Andreas Gruenbacher 2014-07-31 1633 struct drbd_connection_state_change *connection_state_change =
a29728463b254c Andreas Gruenbacher 2014-07-31 1634 &state_change->connections[n_connection];
a29728463b254c Andreas Gruenbacher 2014-07-31 1635
a29728463b254c Andreas Gruenbacher 2014-07-31 1636 if (HAS_CHANGED(connection_state_change->peer_role) ||
a29728463b254c Andreas Gruenbacher 2014-07-31 1637 HAS_CHANGED(connection_state_change->cstate))
a29728463b254c Andreas Gruenbacher 2014-07-31 1638 REMEMBER_STATE_CHANGE(notify_connection_state_change,
a29728463b254c Andreas Gruenbacher 2014-07-31 1639 connection_state_change, NOTIFY_CHANGE);
a29728463b254c Andreas Gruenbacher 2014-07-31 1640 }
a29728463b254c Andreas Gruenbacher 2014-07-31 1641
a29728463b254c Andreas Gruenbacher 2014-07-31 1642 for (n_device = 0; n_device < state_change->n_devices; n_device++) {
a29728463b254c Andreas Gruenbacher 2014-07-31 1643 struct drbd_device_state_change *device_state_change =
a29728463b254c Andreas Gruenbacher 2014-07-31 1644 &state_change->devices[n_device];
a29728463b254c Andreas Gruenbacher 2014-07-31 1645
a29728463b254c Andreas Gruenbacher 2014-07-31 1646 if (HAS_CHANGED(device_state_change->disk_state))
a29728463b254c Andreas Gruenbacher 2014-07-31 1647 REMEMBER_STATE_CHANGE(notify_device_state_change,
a29728463b254c Andreas Gruenbacher 2014-07-31 1648 device_state_change, NOTIFY_CHANGE);
a29728463b254c Andreas Gruenbacher 2014-07-31 1649 }
a29728463b254c Andreas Gruenbacher 2014-07-31 1650
a29728463b254c Andreas Gruenbacher 2014-07-31 1651 n_peer_devices = state_change->n_devices * state_change->n_connections;
a29728463b254c Andreas Gruenbacher 2014-07-31 1652 for (n_peer_device = 0; n_peer_device < n_peer_devices; n_peer_device++) {
a29728463b254c Andreas Gruenbacher 2014-07-31 1653 struct drbd_peer_device_state_change *p =
a29728463b254c Andreas Gruenbacher 2014-07-31 1654 &state_change->peer_devices[n_peer_device];
a29728463b254c Andreas Gruenbacher 2014-07-31 1655
a29728463b254c Andreas Gruenbacher 2014-07-31 1656 if (HAS_CHANGED(p->disk_state) ||
a29728463b254c Andreas Gruenbacher 2014-07-31 1657 HAS_CHANGED(p->repl_state) ||
a29728463b254c Andreas Gruenbacher 2014-07-31 1658 HAS_CHANGED(p->resync_susp_user) ||
a29728463b254c Andreas Gruenbacher 2014-07-31 1659 HAS_CHANGED(p->resync_susp_peer) ||
a29728463b254c Andreas Gruenbacher 2014-07-31 1660 HAS_CHANGED(p->resync_susp_dependency))
a29728463b254c Andreas Gruenbacher 2014-07-31 1661 REMEMBER_STATE_CHANGE(notify_peer_device_state_change,
a29728463b254c Andreas Gruenbacher 2014-07-31 1662 p, NOTIFY_CHANGE);
a29728463b254c Andreas Gruenbacher 2014-07-31 1663 }
a29728463b254c Andreas Gruenbacher 2014-07-31 1664
a29728463b254c Andreas Gruenbacher 2014-07-31 1665 FINAL_STATE_CHANGE(NOTIFY_CHANGE);
a29728463b254c Andreas Gruenbacher 2014-07-31 1666 mutex_unlock(&notification_mutex);
a29728463b254c Andreas Gruenbacher 2014-07-31 1667

---
0-DAY CI Kernel Test Service, Intel Corporation
https://lists.01.org/hyperkitty/list/kbuild-all@xxxxxxxxxxxx

Attachment: .config.gz
Description: application/gzip