From: Dave Jiang <dave.jiang@intel.com>
To: linux-cxl@vger.kernel.org, linux-perf-users@vger.kernel.org
Cc: jic23@kernel.org, will@kernel.org, mark.rutland@arm.com,
dave@stgolabs.net, sashiko-bot@kernel.org
Subject: [PATCH 9/9] perf/cxl: Avoid cpumask_of(-1) when no CPU is assigned
Date: Tue, 28 Jul 2026 14:05:51 -0700 [thread overview]
Message-ID: <20260728210551.2449093-10-dave.jiang@intel.com> (raw)
In-Reply-To: <20260728210551.2449093-1-dave.jiang@intel.com>
cpumask_show() feeds info->on_cpu straight into cpumask_of() for the
world-readable cpumask sysfs attribute. on_cpu is -1 before the first
hotplug online callback and transiently in cxl_pmu_offline_cpu() before a
new target is chosen. cpumask_of(-1) treats the CPU number as unsigned and
does out-of-bounds pointer arithmetic in get_cpu_mask(), so a concurrent
read of the attribute dereferences a wild pointer and can fault -- a local
denial of service.
Read on_cpu once and emit an empty mask when it is negative.
Fixes: 5d7107c72796 ("perf: CXL Performance Monitoring Unit driver")
Reported-by: sashiko-bot@kernel.org
Closes: https://sashiko.dev/#/patchset/20260715191454.459673-1-dave@stgolabs.net?part=1
Assisted-by: Claude:claude-opus-4-8
Signed-off-by: Dave Jiang <dave.jiang@intel.com>
---
drivers/perf/cxl_pmu.c | 11 ++++++++++-
1 file changed, 10 insertions(+), 1 deletion(-)
diff --git a/drivers/perf/cxl_pmu.c b/drivers/perf/cxl_pmu.c
index f1110c5029d6..80145e85fe36 100644
--- a/drivers/perf/cxl_pmu.c
+++ b/drivers/perf/cxl_pmu.c
@@ -501,8 +501,17 @@ static ssize_t cpumask_show(struct device *dev, struct device_attribute *attr,
char *buf)
{
struct cxl_pmu_info *info = dev_get_drvdata(dev);
+ int cpu = READ_ONCE(info->on_cpu);
- return cpumap_print_to_pagebuf(true, buf, cpumask_of(info->on_cpu));
+ /*
+ * on_cpu is -1 before the first online callback and transiently during
+ * cxl_pmu_offline_cpu(). cpumask_of(-1) computes an out-of-bounds
+ * pointer, so report an empty mask instead.
+ */
+ if (cpu < 0)
+ return sysfs_emit(buf, "\n");
+
+ return cpumap_print_to_pagebuf(true, buf, cpumask_of(cpu));
}
static DEVICE_ATTR_RO(cpumask);
--
2.55.0
next prev parent reply other threads:[~2026-07-28 21:06 UTC|newest]
Thread overview: 16+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-07-28 21:05 [PATCH 0/9] perf/cxlpmu: Misc sashiko raised issues fixes Dave Jiang
2026-07-28 21:05 ` [PATCH 1/9] perf/cxl: Program the requested event group on configurable counters Dave Jiang
2026-07-28 21:32 ` sashiko-bot
2026-07-28 21:05 ` [PATCH 2/9] perf/cxl: Clear stale event fields before reprogramming a counter Dave Jiang
2026-07-28 21:26 ` sashiko-bot
2026-07-28 21:05 ` [PATCH 3/9] perf/cxl: Drop bogus counter overflow fixup Dave Jiang
2026-07-28 21:14 ` sashiko-bot
2026-07-29 0:27 ` Dave Jiang
2026-07-28 21:05 ` [PATCH 4/9] perf/cxl: Accept an overflow interrupt on MSI message number 0 Dave Jiang
2026-07-28 21:05 ` [PATCH 5/9] perf/cxl: Keep the overflow interrupt pinned to the managed CPU Dave Jiang
2026-07-28 21:29 ` sashiko-bot
2026-07-28 21:05 ` [PATCH 6/9] perf/cxl: Unfreeze counters after handling an overflow interrupt Dave Jiang
2026-07-28 21:05 ` [PATCH 7/9] perf/cxl: Validate the hardware-reported counter width Dave Jiang
2026-07-28 21:05 ` [PATCH 8/9] perf/cxl: Don't use pmu.dev in IRQ and hotplug callbacks after unregister Dave Jiang
2026-07-28 21:05 ` Dave Jiang [this message]
2026-07-28 21:31 ` [PATCH 9/9] perf/cxl: Avoid cpumask_of(-1) when no CPU is assigned sashiko-bot
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260728210551.2449093-10-dave.jiang@intel.com \
--to=dave.jiang@intel.com \
--cc=dave@stgolabs.net \
--cc=jic23@kernel.org \
--cc=linux-cxl@vger.kernel.org \
--cc=linux-perf-users@vger.kernel.org \
--cc=mark.rutland@arm.com \
--cc=sashiko-bot@kernel.org \
--cc=will@kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.