[PATCH] lib/test_hmm: fix NULL deref and wrong direction in devmem fault debug message

liuqiangneo@163.com posted 1 patch 1 month, 2 weeks ago
lib/test_hmm.c | 5 ++---
1 file changed, 2 insertions(+), 3 deletions(-)
[PATCH] lib/test_hmm: fix NULL deref and wrong direction in devmem fault debug message
Posted by liuqiangneo@163.com 1 month, 2 weeks ago
From: Qiang Liu <liuqiang@kylinos.cn>

Move pr_debug() inside the `if (dpage)` block to avoid a NULL deref,
and fix the direction label from "sys to dev" to "dev to sys" to match
the device-to-system copy.

Assisted-by: Qoder:Qwen-3.8-MAX-Preview
Signed-off-by: Qiang Liu <liuqiang@kylinos.cn>
---
 lib/test_hmm.c | 5 ++---
 1 file changed, 2 insertions(+), 3 deletions(-)

diff --git a/lib/test_hmm.c b/lib/test_hmm.c
index 6e72a0d8a53d..1dae93ab1e93 100644
--- a/lib/test_hmm.c
+++ b/lib/test_hmm.c
@@ -1151,10 +1151,9 @@ static vm_fault_t dmirror_devmem_fault_alloc_and_copy(struct migrate_vma *args,
 		if (!dpage && !order)
 			return VM_FAULT_OOM;
 
-		pr_debug("migrating from sys to dev pfn src: 0x%lx pfn dst: 0x%lx\n",
-				page_to_pfn(spage), page_to_pfn(dpage));
-
 		if (dpage) {
+			pr_debug("migrating from dev to sys pfn src: 0x%lx pfn dst: 0x%lx\n",
+				 page_to_pfn(spage), page_to_pfn(dpage));
 			lock_page(dpage);
 			*dst |= migrate_pfn(page_to_pfn(dpage));
 		}
-- 
2.43.0


No virus found
		Checked by Hillstone Network AntiVirus
Re: [PATCH] lib/test_hmm: fix NULL deref and wrong direction in devmem fault debug message
Posted by Andrew Morton 1 month, 2 weeks ago
On Tue, 11 Aug 2026 17:22:55 +0800 liuqiangneo@163.com wrote:

> From: Qiang Liu <liuqiang@kylinos.cn>
> 
> Move pr_debug() inside the `if (dpage)` block to avoid a NULL deref,
> and fix the direction label from "sys to dev" to "dev to sys" to match
> the device-to-system copy.
> 
> ...
>
> --- a/lib/test_hmm.c
> +++ b/lib/test_hmm.c
> @@ -1151,10 +1151,9 @@ static vm_fault_t dmirror_devmem_fault_alloc_and_copy(struct migrate_vma *args,
>  		if (!dpage && !order)
>  			return VM_FAULT_OOM;
>  
> -		pr_debug("migrating from sys to dev pfn src: 0x%lx pfn dst: 0x%lx\n",
> -				page_to_pfn(spage), page_to_pfn(dpage));
> -
>  		if (dpage) {
> +			pr_debug("migrating from dev to sys pfn src: 0x%lx pfn dst: 0x%lx\n",
> +				 page_to_pfn(spage), page_to_pfn(dpage));
>  			lock_page(dpage);
>  			*dst |= migrate_pfn(page_to_pfn(dpage));
>  		}

Current kernel code doesn't look like this?