All of lore.kernel.org
 help / color / mirror / Atom feed
From: Steven Rostedt <rostedt@goodmis.org>
To: Vincent Donnefort <vdonnefort@google.com>
Cc: mhiramat@kernel.org, linux-trace-kernel@vger.kernel.org,
	mathieu.desnoyers@efficios.com, kernel-team@android.com,
	linux-kernel@vger.kernel.org
Subject: Re: [PATCH v4 06/18] tracing/remotes: Add dmesg tracefs file
Date: Mon, 10 Aug 2026 18:42:16 -0400	[thread overview]
Message-ID: <20260810184216.3484cfd6@robin> (raw)
In-Reply-To: <20260804140333.797210-7-vdonnefort@google.com>

Adding Sashiko review: https://sashiko.dev/#/patchset/20260804140333.797210-2-vdonnefort%40google.com

> --- Patch [6]: [PATCH v4 06/18] tracing/remotes: Add dmesg tracefs file ---
> commit b6a4c19257d91807c612baa19691b2d602bb0670
> Author: Vincent Donnefort <vdonnefort@google.com>
> 
> tracing/remotes: Add dmesg tracefs file
> 
> When enabled, the dmesg tracefs file enables the redirection of all
> events to dmesg. This is similar to tp_printk.
> 
> > diff --git a/kernel/trace/trace_remote.c b/kernel/trace/trace_remote.c
> > index 1fbe2f3f20e99..58a38f3d49024 100644
> > --- a/kernel/trace/trace_remote.c
> > +++ b/kernel/trace/trace_remote.c
> 
> > [ ... ]
> 
> > @@ -882,6 +908,87 @@ static const struct file_operations trace_fops = {
> >  	.release	= trace_release,
> >  };
> >  
> > +static bool trace_remote_do_dmesg(struct trace_remote *remote)
> > +{
> > +	struct trace_remote_iterator *iter = smp_load_acquire(&remote->dmesg);
> > +	unsigned int max_events = 1000;
> > +
> > +	if (!iter)
> > +		return false;
> > +
> > +	trace_remote_iter_read_start(iter);
> > +
> > +	while (trace_remote_iter_read_event(iter)) {
> > +		trace_seq_init(&iter->seq);
> > +
> > +		trace_remote_iter_print_event(iter);
> > +		trace_seq_putc(&iter->seq, 0);
> > +		if (!pr_info("%s", iter->seq.buffer))
> 
> If the remote trace event exceeds the PAGE_SIZE sequence buffer, does
> trace_seq_putc() in trace_remote_do_dmesg() fail to append the null byte?
> 
> Since iter->seq.buffer might not be null-terminated in this case, could this
> lead to an out-of-bounds read when pr_info() prints the string?

Yeah, we may want to have it be:

		if (!pr_info("%s", seq_buf_str(&iter->seq))

Which will make sure the buffer is nul terminated.


> 
> This isn't a bug introduced by this patch, but the same pattern appears
> to exist in the pre-existing trace_remote_panic_handler() with pr_emerg().
> 
> If the kernel is built with CONFIG_PRINTK disabled, pr_info() evaluates to 0.
> 
> Will this cause the loop in trace_remote_do_dmesg() to break without calling
> trace_remote_iter_move(), leaving the event unconsumed and permanently
> stalling the workqueue?
> 
> > +			break;
> > +
> > +		trace_remote_iter_move(iter);
> > +
> > +		if (!(--max_events))
> > +			break;
> > +	}
> > +
> > +	trace_remote_iter_read_finished(iter);
> > +
> > +	return !max_events;
> > +}
> 
> While reviewing this, I also noticed a pre-existing issue in trace_pipe_read()
> when handling oversized events:
> 
> kernel/trace/trace_remote.c:trace_pipe_read() {
>         ...
>         if (trace_remote_iter_print_event(iter)) {
>                 iter->seq.seq.len = prev_len;
>                 break;
>         }
>         ...
> }
> 
> This is a pre-existing issue, but if an oversized event causes
> trace_remote_iter_print_event() to return -EOVERFLOW, will this break
> the loop without calling trace_remote_iter_move()?
> 
> Since the event is left unconsumed in the buffer, could this lead to an
> uninterruptible infinite loop (hard lockup) when reading the trace pipe?

I'll let you answer the above.

-- Steve

  reply	other threads:[~2026-08-10 22:42 UTC|newest]

Thread overview: 22+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-08-04 14:03 [PATCH v4 00/18] tracing/remotes: Add printk, dump_on_panic and boot parameters Vincent Donnefort
2026-08-04 14:03 ` [PATCH v4 01/18] tracing/remotes: Gate tracefs files opening on trace remote registration Vincent Donnefort
2026-08-04 14:03 ` [PATCH v4 02/18] tracing/remotes: Release tracefs,eventfs on registration failure Vincent Donnefort
2026-08-04 14:03 ` [PATCH v4 03/18] tracing/remotes: Use kstrtobool for boolean tracefs files Vincent Donnefort
2026-08-04 14:03 ` [PATCH v4 04/18] tracing/remotes: Use a single per-remote polling work Vincent Donnefort
2026-08-04 14:03 ` [PATCH v4 05/18] tracing/simple_ring_buffer: Add support for compressed length Vincent Donnefort
2026-08-04 14:03 ` [PATCH v4 06/18] tracing/remotes: Add dmesg tracefs file Vincent Donnefort
2026-08-10 22:42   ` Steven Rostedt [this message]
2026-08-11  9:09     ` Vincent Donnefort
2026-08-04 14:03 ` [PATCH v4 07/18] tracing/remotes: selftests: Add a test for the " Vincent Donnefort
2026-08-10 22:46   ` Steven Rostedt
2026-08-04 14:03 ` [PATCH v4 08/18] tracing/remotes: selftests: Prefix hypervisor folder Vincent Donnefort
2026-08-04 14:03 ` [PATCH v4 09/18] ring-buffer: Use irqsave for the reader lock in ring_buffer_poll_remote Vincent Donnefort
2026-08-04 14:03 ` [PATCH v4 10/18] ring-buffer: Use panic-friendly locking in ring_buffer_iter interface Vincent Donnefort
2026-08-04 14:03 ` [PATCH v4 11/18] ring-buffer: Add ring_buffer_read_remote_meta_page() Vincent Donnefort
2026-08-04 14:03 ` [PATCH v4 12/18] ring-buffer: Add kerneldoc for ring_buffer_poll_remote Vincent Donnefort
2026-08-04 14:03 ` [PATCH v4 13/18] tracing/remotes: Add dump_on_panic tracefs file Vincent Donnefort
2026-08-04 14:03 ` [PATCH v4 14/18] tracing/remotes: selftests: Add a test for the " Vincent Donnefort
2026-08-04 14:03 ` [PATCH v4 15/18] tracing/remotes: Add poll_ms " Vincent Donnefort
2026-08-04 14:03 ` [PATCH v4 16/18] tracing/remotes: Add trace_remote cmdline options Vincent Donnefort
2026-08-04 14:03 ` [PATCH v4 17/18] Documentation: tracing/remotes: Add detailed tracefs layout Vincent Donnefort
2026-08-04 14:03 ` [PATCH v4 18/18] Documentation/kernel-parameters: Add trace_remote Vincent Donnefort

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260810184216.3484cfd6@robin \
    --to=rostedt@goodmis.org \
    --cc=kernel-team@android.com \
    --cc=linux-kernel@vger.kernel.org \
    --cc=linux-trace-kernel@vger.kernel.org \
    --cc=mathieu.desnoyers@efficios.com \
    --cc=mhiramat@kernel.org \
    --cc=vdonnefort@google.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.