selftests/mm: fix unchecked ftruncate return value in soft-dirty test
authorAnshuman <anshumantewari123@gmail.com>
Tue, 18 Aug 2026 13:32:06 +0000 (19:02 +0530)
committerAndrew Morton <akpm@linux-foundation.org>
Tue, 25 Aug 2026 01:43:27 +0000 (18:43 -0700)
test_mprotect() calls ftruncate() to resize the backing file before
mmap()'ing it, but never checks the return value.  If ftruncate() fails,
the file may remain shorter than the requested mapping size.  The
subsequent mmap() with MAP_SHARED can still succeed in this case, but the
very next line writes directly into the mapped memory (*map = 1), which
can trigger SIGBUS if the mapping extends beyond the actual file size.

Check the return value and fail cleanly with ksft_exit_fail_msg() if
ftruncate() fails, matching the error-handling style already used for the
mmap() call immediately below it.

Link: https://lore.kernel.org/20260818133206.39503-1-anshumantewari123@gmail.com
Signed-off-by: Anshuman <anshumantewari123@gmail.com>
Reviewed-by: Andrew Morton <akpm@linux-foundation.org>
Reviewed-by: Sarthak Sharma <sarthak.sharma@arm.com>
Cc: David Hildenbrand <david@kernel.org>
Cc: Shuah Khan <shuah@kernel.org>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
tools/testing/selftests/mm/soft-dirty.c

index e198fac..5f27891 100644 (file)
@@ -152,7 +152,8 @@ static void test_mprotect(int pagemap_fd, int pagesize, bool anon)
                        return;
                }
                unlink(fname);
-               ftruncate(test_fd, pagesize);
+               if (ftruncate(test_fd, pagesize) != 0)
+                       ksft_exit_fail_msg("ftruncate failed\n");
                map = mmap(NULL, pagesize, PROT_READ|PROT_WRITE,
                           MAP_SHARED, test_fd, 0);
                if (map == MAP_FAILED)