Re: [PATCH v2] mm/gup: document unlocked invariant in fixup_user_fault

From: David Hildenbrand (Arm)

Date: Wed Oct 07 2026 - 07:58:31 EST


On 10/5/26 13:22, Nhật Anh Nguyễn Duy wrote:
> Hi David,
>

Hi,

> Thanks for taking the time to review.
>
> My motivation came from running Smatch over fixup_user_fault(), which flagged

just like the (at least) 2 previous reports. One from them from 2021 IIRC where
Linus even rejected a code change.

> the dereference as a potential NULL pointer issue. Because the relationship
> between FAULT_FLAG_ALLOW_RETRY and the unlocked pointer is subtle when
> first reading through the path, I initially misread it as an unguarded
> dereference in v1.
>
> When Andrew pointed out the invariant, I thought documenting it might help
> future readers or newer contributors who hit the same static analysis warning.
>
> If adding a comment isn't the right approach here, would you prefer leaving
> the implicit contract as-is, or is an explicit runtime check (such as
> VM_WARN_ON_ONCE) something more fitting?
We want to silence smatch. Either fix smatch or find a reasonable way to stop it
from reporting things that are simply not true.

--
Cheers,

David