Re: [PATCH] dlm: validate node weights before building member array
From: Alexander Aring
Date: Thu Oct 01 2026 - 19:08:13 EST
Hi,
On Thu, Sep 10, 2026 at 4:07 AM Qing Ming <a0yami@xxxxxxxxxxx> wrote:
>
> DLM node weights are parsed as signed integers and copied into the member
> list. make_member_array() uses their sum as the allocation count, but only
> positive weights contribute entries to the array. A negative weight can
> therefore reduce the allocation without reducing the number of writes.
>
> The issue was found through static analysis of the configfs input and
> member array construction. With two recovery members weighted -31 and 32,
> the sum is 1, so recovery allocates one int and then writes the positive
> member's node ID 32 times. A reproducer using dlm_controld and dlm_tool
> triggered the same report on a KASAN kernel:
>
> BUG: KASAN: slab-out-of-bounds in dlm_recover_members [dlm]
> Write of size 4 by task dlm_recoverd
>
> Call Trace:
> dlm_recover_members
> dlm_recoverd
> kthread
> ret_from_fork
>
> Reject negative weights at the configfs input boundary. Also detect
> overflow when adding non-negative weights to the signed allocation count,
> and propagate array construction errors to the recovery path.
>
> Fixes: e7fd41792fc0 ("[DLM] The core of the DLM for GFS2/CLVM")
> Signed-off-by: Qing Ming <a0yami@xxxxxxxxxxx>
> Assisted-by: Codex:gpt-5
Acked-by: Alexander Aring <aahringo@xxxxxxxxxx>
- Alex