From nobody Tue Sep 22 14:49:22 2026 X-Original-To: dev-commits-src-all@mlmmj.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mlmmj.nyi.freebsd.org (Postfix) with ESMTP id 4hq3072gs6z6sK8B for ; Tue, 22 Sep 2026 14:49:27 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from mxrelay.nyi.freebsd.org (mxrelay.nyi.freebsd.org [IPv6:2610:1c1:1:606c::19:3]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature RSA-PSS (4096 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "mxrelay.nyi.freebsd.org", Issuer "YR2" (not verified)) by mx1.freebsd.org (Postfix) with ESMTPS id 4hq3071pKkz4hBX for ; Tue, 22 Sep 2026 14:49:27 +0000 (UTC) (envelope-from git@FreeBSD.org) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1790088567; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=ZA1i51AIjv6NSjVWUSE473ZlyN0OG0Mi0AFWRTFtNgs=; b=FDN537Y9jskJsxSDJ1Ay6bPUNi4xMpbdAOAAkT5Yjoa2uDZ6NnMXFtFgCD1Je6HYWGWaKz bSt2JeVq1qMHX6nEq1iV10bNyr/BwUv0a041O0neVVQxmIQwfFhtLRXOIgPAS4pkVpPoqe AcbC8zf1j+roQPIUW2QtDwlBsrQX5yh0gDMiQIOznbIhcbDZ95okkO/W+CvT8Y7vn7a72k vewfvks8gEHNL+gLTimN39yoslksxFgXyKNdCgx5SskZHhsMfqnhrlF7ZwQjAQ1ySzi4yc GFx5/R214ljxiLw5KQcrRt2gfE5AQz37Yu/n0cbn5tbk6netxpLTvUqCtfsjOA== ARC-Seal: i=1; a=rsa-sha256; d=freebsd.org; s=dkim; cv=none; t=1790088567; b=RI/jwlld17p4wSZqHtYaubPAFTopwIEnrjir9hCawHprDBvpeCZDMqbUhim+gdQ668iRwT kNGCesnHrr7YXzomvjQyifwGlPojEVp+Z/SkeVYRBdQff6QzDC+GJDRiU6/jKd9o4tanca dsFvE+weMc9FBX+6wTgqRlQkg39P2sIZ1mEKmX+ZZPt3u7eF6glYC9O2iXmLAXOvA9HoXA pnb/e/UlejGNWibw+dpq/0LzNi5TAIrydgkG0HVntaTSsLBh0WKyByH8s2VQSW7G73PpTP Wi28KqzoMqxKfAVVIsZuZWFSz8gtUMkjy26EGF3I3H2Mw+BIHGyykEgULqXvmw== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1790088567; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=ZA1i51AIjv6NSjVWUSE473ZlyN0OG0Mi0AFWRTFtNgs=; b=e/omHCDJzIVTit4BmExtcZYXfzECjBtQjy40oHmzmbjVB4MJ7P6BW3viz24IwUdjdH5+/x kZyErM7iBK0ekmJp9v3sSyQwhkomQeassZNgT5CiZOfiRoTadVmnIembseB1Moh7RL0De2 sbQEBHQznsY+u71bYzuHEZ+ZiOinPCh2qWrtOxuQaJPb/LkIRJG2mFQIkLGMDuxj8wWx4T uCQp2OZgo0PK4f2lnEYvA0ME4qErQnasIs6BhZnMruvEOT059pMuAWEDbz8bL8rABfANNf 3rQbgDoSsdbftElY6h5ZrydKQUzUJiPOdxxtQv58nWOdIgAkU9dCrP+DYB4Gpw== ARC-Authentication-Results: i=1; mx1.freebsd.org; none Received: from gitrepo.freebsd.org (gitrepo.freebsd.org [IPv6:2610:1c1:1:6068::e6a:5]) by mxrelay.nyi.freebsd.org (Postfix) with ESMTP id 4hq3070mlzz19xH for ; Tue, 22 Sep 2026 14:49:27 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from git (uid 1279) (envelope-from git@FreeBSD.org) id 277b1 by gitrepo.freebsd.org (DragonFly Mail Agent v0.13+ on gitrepo.freebsd.org); Tue, 22 Sep 2026 14:49:22 +0000 To: src-committers@FreeBSD.org, dev-commits-src-all@FreeBSD.org, dev-commits-src-branches@FreeBSD.org From: Mark Johnston Subject: git: 65a5b32c225a - stable/14 - buf: Avoid calling bufdomain() on newly initialized bufs List-Id: Commit messages for all branches of the src repository List-Archive: https://lists.freebsd.org/archives/dev-commits-src-all List-Help: List-Post: List-Subscribe: List-Unsubscribe: X-BeenThere: dev-commits-src-all@freebsd.org Sender: owner-dev-commits-src-all@FreeBSD.org List-Id: List-Post: List-Help: List-Subscribe: List-Unsubscribe: List-Owner: Precedence: list MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 8bit X-Git-Committer: markj X-Git-Repository: src X-Git-Refname: refs/heads/stable/14 X-Git-Reftype: branch X-Git-Commit: 65a5b32c225a2d6845d6f90470f9b01ba52c432a Auto-Submitted: auto-generated Date: Tue, 22 Sep 2026 14:49:22 +0000 Message-Id: <6ab29572.277b1.299b98d4@gitrepo.freebsd.org> The branch stable/14 has been updated by markj: URL: https://cgit.FreeBSD.org/src/commit/?id=65a5b32c225a2d6845d6f90470f9b01ba52c432a commit 65a5b32c225a2d6845d6f90470f9b01ba52c432a Author: Mark Johnston AuthorDate: 2026-09-04 12:46:29 +0000 Commit: Mark Johnston CommitDate: 2026-09-22 13:01:16 +0000 buf: Avoid calling bufdomain() on newly initialized bufs bufinit() inserts newly initialized bufs into the QUEUE_EMPTY queue, at which point they haven't yet been assigned a domain. Thus, bufdomain() returns &bdomain[-1], which trips the array-bounds sanitizer. This is harmless since we don't use the result in that case, but let's avoid the invalid access to begin with. This is sufficient to let an amd64 kernel boot to a login prompt with -fsanitize=array-bounds configured. Reported by: Andrew Griffiths Reviewed by: rlibby, kib MFC after: 1 week Differential Revision: https://reviews.freebsd.org/D59381 (cherry picked from commit e1d903bbfaf91060c43209b35b78a9992fbffe5e) --- sys/kern/vfs_bio.c | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/sys/kern/vfs_bio.c b/sys/kern/vfs_bio.c index 62d70c04f6ea..ea86b8589bfa 100644 --- a/sys/kern/vfs_bio.c +++ b/sys/kern/vfs_bio.c @@ -2024,16 +2024,13 @@ bd_flushall(struct bufdomain *bd) static void bq_insert(struct bufqueue *bq, struct buf *bp, bool unlock) { - struct bufdomain *bd; - if (bp->b_qindex != QUEUE_NONE) panic("bq_insert: free buffer %p onto another queue?", bp); - bd = bufdomain(bp); if (bp->b_flags & B_AGE) { /* Place this buf directly on the real queue. */ if (bq->bq_index == QUEUE_CLEAN) - bq = bd->bd_cleanq; + bq = bufdomain(bp)->bd_cleanq; BQ_LOCK(bq); TAILQ_INSERT_HEAD(&bq->bq_queue, bp, b_freelist); } else { @@ -2053,9 +2050,12 @@ bq_insert(struct bufqueue *bq, struct buf *bp, bool unlock) BUF_UNLOCK(bp); if (bp->b_qindex == QUEUE_CLEAN) { + struct bufdomain *bd; + /* * Flush the per-cpu queue and notify any waiters. */ + bd = bufdomain(bp); if (bd->bd_wanted || (bq != bd->bd_cleanq && bq->bq_len >= bd->bd_lim)) bd_flush(bd, bq);