Re: [PATCH v4] riscv: lib: Fix ZBB strnlen wrap-around regression on huge counts

From: shao.mingyin

Date: Sun Sep 27 2026 - 23:27:47 EST


Hi Paul,

Gentle ping on this one - it has picked up more tags since posting, and
should be ready to be picked up:

  Acked-by:     Michael Neuling <mikey@xxxxxxxxxxx>
  Reviewed-by:  Aurelien Jarno <aurelien@xxxxxxxxxxx>
  Tested-by:    Troy Mitchell <troy.mitchell@xxxxxxxxx>
  Suggested-by: David Laight <david.laight.linux@xxxxxxxxx>
  Suggested-by: Qingfang Deng <qingfang.deng@xxxxxxxxx>

It stays a minimal fix: only the two boundary-computation instructions
in the ZBB path are replaced (18 insertions, 2 deletions, no new
registers), so the scanning loop itself is unchanged.

This one matters for stable - the regression is in v7.1.10+ and v7.2:
strnlen(s, SIZE_MAX) returns 8 for any 8+-byte aligned string and
truncates names built through FORTIFY strcat/strlcat (device-mapper's
sysfs name "live-base" becomes "live-bas"), which broke blivet/anaconda
installs and LVM on RISC-V systems.  It has since been reproduced
independently on a Fedora 45 riscv64 image with ZBB enabled, where the
fix restores correct behaviour.

Cc: stable is set, and the minimal form should backport cleanly to
7.1.y.  Happy to rebase onto riscv/fixes or adjust anything if needed.

Thanks,
Shao Mingyin