Re: [PATCH v2] riscv: fix strnlen() overflow in Zbb implementation
Jason Montleon
jmontleo at redhat.com
Thu Sep 24 19:47:22 PDT 2026
On Thu, Sep 24, 2026 at 12:50 AM Aurelien Jarno <aurelien at aurel32.net> wrote:
>
> Hi,
>
> On 2026-09-24 10:57, gao.rui at zte.com.cn wrote:
> > The RISC-V Zbb optimized strnlen() implementation can return incorrect
> > results when very large count values are supplied.
> >
> > The previous implementation calculates an end address based on the
> > input pointer and count. When count is close to SIZE_MAX, the address
> > calculation may overflow, resulting in incorrect termination checks and
> > wrong return values.
> >
> > This issue was observed while running device-mapper tests:
> >
> > dmsetup create testname9 --table "0 8 zero"
> > cat /sys/block/dm-*/dm/name
> > dmsetup remove testname9
> >
> > Rework the Zbb implementation to use a decrementing word counter.
> > This removes the dependency on end-address calculations,
> > avoids overflow entirely, and simplifies the word scanning loop.
> >
> > Performance was evaluated with string_bench_strnlen:
> >
> > New Implementation Previous Implementation
> >
> > len=0 : 70 ns/call 70 ns/call
> > len=1 : 81 ns/call 81 ns/call
> > len=7 : 81 ns/call 81 ns/call
> > len=8 : 81 ns/call 81 ns/call
> > len=16 : 97 ns/call 90 ns/call
> > len=31 : 119 ns/call 113 ns/call
> > len=64 : 174 ns/call 162 ns/call
> > len=127 : 264 ns/call 258 ns/call
> > len=512 : 801 ns/call 824 ns/call
> > len=1024 : 1578 ns/call 1550 ns/call
> > len=3173 : 4541 ns/call 4703 ns/call
> > len=4096 : 5984 ns/call 5982 ns/call
> >
> > Results show comparable performance to the previous implementation
> > while fixing the overflow issue.
> >
> > Fixes: 5ba15d419fab ("riscv: lib: add strnlen() implementation")
> > Signed-off-by: Gao Rui <gao.rui at zte.com.cn>
> >
> > ---
> > v2:
> > - Rework the Zbb implementation to eliminate end-address overflow
> > instead of falling back to the generic path.
> > - Use a decrementing word counter for word scanning.
> > - Replace numeric labels with descriptive local labels.
> > - Add comments describing the loop structure.
> > - Run KUnit string tests successfully.
> > - Add string_bench_strnlen benchmark results.
> > ---
> > arch/riscv/lib/strnlen.S | 111 +++++++++++++++++----------------------
> > 1 file changed, 48 insertions(+), 63 deletions(-)
>
> Note that the following patch was also posted, to what I believe is the
> same issue:
>
> https://lore.kernel.org/linux-riscv/DLLJDLKPZ4S3.1KQ5O4OQBBTEW@linux.dev
>
I tried a build with the patch from this thread and another build with
the one from the thread you linked. In both cases the UUID is no
longer truncated and I successfully booted the affected image with ZBB
enabled. I do not know which is preferable.
Thank you,
Jason Montleon
> Regards
> Aurelien
>
> --
> Aurelien Jarno GPG: 4096R/1DDD8C9B
> aurelien at aurel32.net http://aurel32.net
>
More information about the linux-riscv
mailing list