Re: [PATCH v4] riscv: lib: Fix ZBB strnlen wrap-around regression on huge counts

Paul Walmsley pjw at kernel.org
Mon Oct 5 10:13:16 PDT 2026


Hi Shao Mingyin,

On Mon, 28 Sep 2026, shao.mingyin at zte.com.cn wrote:

> Hi Paul,
> 
> Gentle ping on this one - it has picked up more tags since posting, and
> should be ready to be picked up:
> 
>   Acked-by:     Michael Neuling <mikey at neuling.org>
>   Reviewed-by:  Aurelien Jarno <aurelien at aurel32.net>
>   Tested-by:    Troy Mitchell <troy.mitchell at linux.dev>
>   Suggested-by: David Laight <david.laight.linux at gmail.com>
>   Suggested-by: Qingfang Deng <qingfang.deng at linux.dev>
> 
> It stays a minimal fix: only the two boundary-computation instructions
> in the ZBB path are replaced (18 insertions, 2 deletions, no new
> registers), so the scanning loop itself is unchanged.
> 
> This one matters for stable - the regression is in v7.1.10+ and v7.2:
> strnlen(s, SIZE_MAX) returns 8 for any 8+-byte aligned string and
> truncates names built through FORTIFY strcat/strlcat (device-mapper's
> sysfs name "live-base" becomes "live-bas"), which broke blivet/anaconda
> installs and LVM on RISC-V systems.  It has since been reproduced
> independently on a Fedora 45 riscv64 image with ZBB enabled, where the
> fix restores correct behaviour.
> 
> Cc: stable is set, and the minimal form should backport cleanly to
> 7.1.y.  Happy to rebase onto riscv/fixes or adjust anything if needed.

Thanks, queued for v7.3-rc.  Rather than posting a new patch, it would 
have been better for you to comment on Gao Rui's patch:

https://lore.kernel.org/linux-riscv/20260819161821053fNUWuvdGIo4HUBmxlcNfG@zte.com.cn/

However, since time is short to get something into v7.3-rc fixes, and the 
approach you took in your patch seems better, I've queued yours instead.


- Paul



More information about the linux-riscv mailing list