Re: [PATCH] md/raid5-ppl: check for NULL ppl_conf in ppl_write_stripe_run()

From: yu kuai

Date: Sat Oct 03 2026 - 23:54:41 EST


Hi,

在 2026/9/25 0:26, Svyatoslav Nikolenko 写道:
> Syzbot reported a general protection fault
> due to a NULL pointer dereference in ppl_write_stripe_run().
>
> When a RAID 5 array operates without Partial Parity Log (PPL) enabled or
> before its initialization, conf->log_private remains NULL.
> ppl_write_stripe_run() assigns ppl_conf = conf->log_private and
> immediately attempts to access ppl_conf->count in the loop header.
> This triggers a NULL pointer dereference.
>
> Fix this by returning early
> from ppl_write_stripe_run() if ppl_conf is NULL.
>
> Tested-by: syzbot+75d7e96ad03ac2dbbd9f@xxxxxxxxxxxxxxxxxxxxxxxxx
> Reported-by: syzbot+75d7e96ad03ac2dbbd9f@xxxxxxxxxxxxxxxxxxxxxxxxx
> Closes: https://syzkaller.appspot.com/bug?extid=75d7e96ad03ac2dbbd9f
> Fixes: 3418d036c81d ("raid5-ppl: Partial Parity Log write logging implementation")
> Signed-off-by: Svyatoslav Nikolenko <nsvatoslav515@xxxxxxxxx>
> ---
> drivers/md/raid5-ppl.c | 3 +++
> 1 file changed, 3 insertions(+)

Another patch is applied for this problem, you can check the notes:

[PATCH] md: take reconfig_mutex when enabling PPL on an inactive array -
Nguyen Ngoc Thang <https://lore.kernel.org/linux-raid/20260924171345.75894-1-ngocthang2710.1999@xxxxxxxxx/>

>
> diff --git a/drivers/md/raid5-ppl.c b/drivers/md/raid5-ppl.c
> index 7f8a9d3fd578..e54ed4e44b0f 100644
> --- a/drivers/md/raid5-ppl.c
> +++ b/drivers/md/raid5-ppl.c
> @@ -535,6 +535,9 @@ void ppl_write_stripe_run(struct r5conf *conf)
> struct ppl_log *log;
> int i;
>
> + if (!ppl_conf)
> + return;
> +
> for (i = 0; i < ppl_conf->count; i++) {
> log = &ppl_conf->child_logs[i];
>

--
Thanks,
Kuai