Re: [PATCH v4] riscv: lib: Fix ZBB strnlen wrap-around regression on huge counts

From: Paul Walmsley

Date: Mon Oct 05 2026 - 13:14:58 EST


Hi Shao Mingyin,

On Mon, 28 Sep 2026, shao.mingyin@xxxxxxxxxx wrote:

> Hi Paul,
>
> Gentle ping on this one - it has picked up more tags since posting, and
> should be ready to be picked up:
>
> Acked-by: Michael Neuling <mikey@xxxxxxxxxxx>
> Reviewed-by: Aurelien Jarno <aurelien@xxxxxxxxxxx>
> Tested-by: Troy Mitchell <troy.mitchell@xxxxxxxxx>
> Suggested-by: David Laight <david.laight.linux@xxxxxxxxx>
> Suggested-by: Qingfang Deng <qingfang.deng@xxxxxxxxx>
>
> It stays a minimal fix: only the two boundary-computation instructions
> in the ZBB path are replaced (18 insertions, 2 deletions, no new
> registers), so the scanning loop itself is unchanged.
>
> This one matters for stable - the regression is in v7.1.10+ and v7.2:
> strnlen(s, SIZE_MAX) returns 8 for any 8+-byte aligned string and
> truncates names built through FORTIFY strcat/strlcat (device-mapper's
> sysfs name "live-base" becomes "live-bas"), which broke blivet/anaconda
> installs and LVM on RISC-V systems. It has since been reproduced
> independently on a Fedora 45 riscv64 image with ZBB enabled, where the
> fix restores correct behaviour.
>
> Cc: stable is set, and the minimal form should backport cleanly to
> 7.1.y. Happy to rebase onto riscv/fixes or adjust anything if needed.

Thanks, queued for v7.3-rc. Rather than posting a new patch, it would
have been better for you to comment on Gao Rui's patch:

https://lore.kernel.org/linux-riscv/20260819161821053fNUWuvdGIo4HUBmxlcNfG@xxxxxxxxxx/

However, since time is short to get something into v7.3-rc fixes, and the
approach you took in your patch seems better, I've queued yours instead.


- Paul