All of lore.kernel.org
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Jim Cromie" <jim.cromie@gmail.com>
Cc: linux-modules@vger.kernel.org, dri-devel@lists.freedesktop.org
Subject: Re: [PATCH v8 41/43] dyndbg: add +c flag to count advantage of classmaps for DRM
Date: Sat, 05 Sep 2026 18:29:23 +0000	[thread overview]
Message-ID: <20260905182924.4BB3B1F00A3A@smtp.kernel.org> (raw)
In-Reply-To: <20260905-dd-cmap-part2-clean-v8-41-a4cc0674f6fd@gmail.com>

Thank you for your contribution! Sashiko AI review found 4 potential issue(s) to consider:
- [High] Memory leak of the user-provided buffer `tmpbuf` in `ddebug_proc_write()` when handling the `reset_stats` command.
- [High] The `+c` (call counting) flag fails to operate when `CONFIG_JUMP_LABEL` is disabled, unless the `+p` flag is also set.
- [Medium] Call counts from offlined CPUs are dropped from the total, resulting in inaccurate statistics.
- [Low] Data race when resetting per-CPU call counts from another CPU locklessly.
--

commit 5f4a75e3669c0fca15e2071c6b6911a58fe6a5ab
Author: Jim Cromie <jim.cromie@gmail.com>
Subject: dyndbg: add +c flag to count advantage of classmaps for DRM

This commit introduces a +c flag to dynamic debug to count per-cpu hits
for flagged pr_debug() callsites. The counts can be reset via a
reset_stats command and read from the control file.

> diff --git a/include/linux/dynamic_debug.h b/include/linux/dynamic_debug.h
> --- a/include/linux/dynamic_debug.h
> +++ b/include/linux/dynamic_debug.h
[ ... ]
> @@ -420,11 +430,15 @@ void __dynamic_ibdev_dbg(struct _ddebug *descriptor,
>   * (|_cls):	adds in _DPRINT_CLASS_DFLT as needed
>   * (|_no_desc):	former gets callsite descriptor as 1st arg (for prdbgs)
>   */
> +
>  #define __dynamic_func_call_cls(id, cls, fmt, func, ...) do {	\
>  	DEFINE_DYNAMIC_DEBUG_METADATA_CLS(id, cls, fmt);	\
>  	if (DYNAMIC_DEBUG_BRANCH(id)) {				\

[Severity: High]
Will the +c (call counting) flag operate correctly when CONFIG_JUMP_LABEL
is disabled?

If CONFIG_JUMP_LABEL is not set, the fallback DYNAMIC_DEBUG_BRANCH(descriptor)
macros check only for _DPRINTK_FLAGS_PRINT.

When a user enables counting with +c but leaves printing disabled (-p),
the branch evaluates to false, and DYNAMIC_DEBUG_COUNT() is bypassed
completely.

> -		func(&id, ##__VA_ARGS__);			\
> -		__dynamic_dump_stack(id);			\
> +		DYNAMIC_DEBUG_COUNT(id);			\
> +		if (id.flags & _DPRINTK_FLAGS_ACTIVE) {		\
> +			func(&id, ##__VA_ARGS__);		\
> +			__dynamic_dump_stack(id);		\
> +		}						\
>  	}							\
>  } while (0)

[ ... ]
> diff --git a/lib/dynamic_debug.c b/lib/dynamic_debug.c
> --- a/lib/dynamic_debug.c
> +++ b/lib/dynamic_debug.c
[ ... ]
> @@ -1083,6 +1093,14 @@ static __init int dyndbg_setup(char *str)
>  
>  __setup("dyndbg=", dyndbg_setup);
>  
> +static void reset_ddebug_call_count(void)
> +{
> +	int cpu;
> +
> +	for_each_possible_cpu(cpu)
> +		per_cpu(ddebug_call_count, cpu) = 0;
> +}
> +

[Severity: Low]
Can this lockless reset cause a data race?

This logic locklessly writes 0 to the per-CPU variable of all possible
CPUs. If another CPU is concurrently executing this_cpu_inc(), which is
atomic only with respect to local interrupts, a data race occurs.

This can result in a lost reset or a lost increment in the call count
statistics.

>  /*
>   * File_ops->write method for <debugfs>/dynamic_debug/control.  Gathers the
>   * command text from userspace, parses and executes it.
> @@ -1105,6 +1123,10 @@ static ssize_t ddebug_proc_write(struct file *file, const char __user *ubuf,
>  		return PTR_ERR(tmpbuf);
>  	v2pr_info("read %zu bytes from userspace\n", len);
>  
> +	if (len >= 11 && !strncmp(tmpbuf, "reset_stats", 11)) {
> +		reset_ddebug_call_count();
> +		return len;
> +	}

[Severity: High]
Does this code leak tmpbuf?

When handling the reset_stats command, this early return path bypasses
the standard cleanup and skips the kfree(tmpbuf) call required to free the
dynamically allocated buffer.

This allows a privileged user to leak memory (up to PAGE_SIZE per write)
on every successful reset_stats command.

>  	ret = ddebug_exec_queries(tmpbuf, NULL);
>  	kfree(tmpbuf);
>  	if (ret < 0)
[ ... ]
> @@ -1238,6 +1260,16 @@ static const char *ddebug_class_name(struct _ddebug_info *di, struct _ddebug *dp
>  	return NULL;
>  }
>  
> +static unsigned long get_ddebug_call_count(void)
> +{
> +	unsigned long total = 0;
> +	int cpu;
> +
> +	for_each_online_cpu(cpu)
> +		total += per_cpu(ddebug_call_count, cpu);
> +	return total;
> +}

[Severity: Medium]
Is it intentional to sum only the online CPUs here?

The reset logic in reset_ddebug_call_count() expects all possible CPUs
to be managed, but this read logic drops accumulated counts from CPUs
that are currently offline.

If a CPU was online, accumulated hits, and is subsequently offlined, its
counts are excluded from the total, making the metric fluctuate and
become unreliable across CPU hotplug events.

> +
>  /*
>   * Seq_ops show method.  Called several times within a read()
>   * call from userspace, with ddebug_lock held.  Formats the

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260905-dd-cmap-part2-clean-v8-0-a4cc0674f6fd@gmail.com?part=41

  reply	other threads:[~2026-09-05 18:29 UTC|newest]

Thread overview: 106+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-05 18:13 [PATCH v8 00/43] dyndbg: fix classmaps API for DRM, query extensions, and selftests Jim Cromie via B4 Relay
2026-09-05 18:13 ` Jim Cromie
2026-09-05 18:13 ` [PATCH v8 01/43] selftests/dyndbg: Add kselftest script to verify dynamic-debug Jim Cromie via B4 Relay
2026-09-05 18:13   ` Jim Cromie
2026-09-05 18:22   ` sashiko-bot
2026-09-05 18:13 ` [PATCH v8 02/43] drm: Fix incorrect ccflags-y spelling inside Makefile Jim Cromie via B4 Relay
2026-09-05 18:13   ` Jim Cromie
2026-09-05 18:13 ` [PATCH v8 03/43] drm: fix config dependent unused variable warning Jim Cromie via B4 Relay
2026-09-05 18:13   ` Jim Cromie
2026-09-05 18:13 ` [PATCH v8 04/43] drm: Mark CONFIG_DRM_USE_DYNAMIC_DEBUG as unBROKEN Jim Cromie via B4 Relay
2026-09-05 18:13   ` Jim Cromie
2026-09-05 18:19   ` sashiko-bot
2026-09-05 18:13 ` [PATCH v8 05/43] vmlinux.lds.h: refactor BOUNDED_SECTION_* macros into bounded_sections.lds.h Jim Cromie via B4 Relay
2026-09-05 18:13   ` Jim Cromie
2026-09-05 18:13 ` [PATCH v8 06/43] vmlinux.lds.h: drop unused HEADERED_SECTION* macros Jim Cromie via B4 Relay
2026-09-05 18:13   ` Jim Cromie
2026-09-05 18:13 ` [PATCH v8 07/43] vmlinux.lds.h: Fix ALIGN(8) omission causing NULL ptr on i386 Jim Cromie via B4 Relay
2026-09-05 18:13   ` Jim Cromie
2026-09-05 18:13 ` [PATCH v8 08/43] vmlinux.lds.h: remove redundant ALIGN(8) directives Jim Cromie via B4 Relay
2026-09-05 18:13   ` Jim Cromie
2026-09-05 18:13 ` [PATCH v8 09/43] dyndbg.lds.S: fix lost dyndbg sections in modules Jim Cromie via B4 Relay
2026-09-05 18:13   ` Jim Cromie
2026-09-05 18:13 ` [PATCH v8 10/43] dyndbg: factor ddebug_match_desc out from ddebug_change Jim Cromie via B4 Relay
2026-09-05 18:13   ` Jim Cromie
2026-09-05 18:13 ` [PATCH v8 11/43] dyndbg: add stub macro for DECLARE_DYNDBG_CLASSMAP Jim Cromie via B4 Relay
2026-09-05 18:13   ` Jim Cromie
2026-09-05 18:13 ` [PATCH v8 12/43] dyndbg: reword "class unknown," to "class:_UNKNOWN_" Jim Cromie via B4 Relay
2026-09-05 18:13   ` Jim Cromie
2026-09-05 18:13 ` [PATCH v8 13/43] dyndbg-API: remove DD_CLASS_TYPE_(DISJOINT|LEVEL)_NAMES and code Jim Cromie via B4 Relay
2026-09-05 18:13   ` Jim Cromie
2026-09-05 18:13 ` [PATCH v8 14/43] dyndbg: drop NUM_TYPE_ARGS Jim Cromie via B4 Relay
2026-09-05 18:13   ` Jim Cromie
2026-09-05 18:13 ` [PATCH v8 15/43] dyndbg: bump num-tokens in a query-cmd from 9 to 15 Jim Cromie via B4 Relay
2026-09-05 18:13   ` Jim Cromie
2026-09-05 18:13 ` [PATCH v8 16/43] dyndbg: reduce verbose/debug clutter Jim Cromie via B4 Relay
2026-09-05 18:13   ` Jim Cromie
2026-09-05 18:13 ` [PATCH v8 17/43] lib/parser: add match_wildcard_hyphen() for agnostic matching Jim Cromie via B4 Relay
2026-09-05 18:13   ` Jim Cromie
2026-09-05 18:13 ` [PATCH v8 18/43] kbuild, dyndbg: clean up builtin module-name ambiguities Jim Cromie via B4 Relay
2026-09-05 18:13   ` Jim Cromie
2026-09-05 18:26   ` sashiko-bot
2026-09-05 18:13 ` [PATCH v8 19/43] dyndbg: refactor param_set_dyndbg_classes and below Jim Cromie via B4 Relay
2026-09-05 18:13   ` Jim Cromie
2026-09-05 18:13 ` [PATCH v8 20/43] dyndbg: tighten fn-sig of ddebug_apply_class_bitmap Jim Cromie via B4 Relay
2026-09-05 18:13   ` Jim Cromie
2026-09-05 18:13 ` [PATCH v8 21/43] dyndbg: replace classmap list with an array-slice Jim Cromie via B4 Relay
2026-09-05 18:13   ` Jim Cromie
2026-09-05 18:25   ` sashiko-bot
2026-09-05 18:13 ` [PATCH v8 22/43] dyndbg: macrofy a 2-index for-loop pattern Jim Cromie via B4 Relay
2026-09-05 18:13   ` Jim Cromie
2026-09-05 18:13 ` [PATCH v8 23/43] dyndbg: reduce class param storage to u32 Jim Cromie via B4 Relay
2026-09-05 18:13   ` Jim Cromie
2026-09-05 18:13 ` [PATCH v8 24/43] dyndbg,module: make proper substructs in _ddebug_info Jim Cromie via B4 Relay
2026-09-05 18:13   ` Jim Cromie
2026-09-05 18:13 ` [PATCH v8 25/43] dyndbg: move mod_name down from struct ddebug_table to _ddebug_info Jim Cromie via B4 Relay
2026-09-05 18:13   ` Jim Cromie
2026-09-05 18:13 ` [PATCH v8 26/43] dyndbg: hoist classmap-filter-by-modname up to ddebug_add_module Jim Cromie via B4 Relay
2026-09-05 18:13   ` Jim Cromie
2026-09-05 18:13 ` [PATCH v8 27/43] dyndbg-API: replace DECLARE_DYNDBG_CLASSMAP Jim Cromie via B4 Relay
2026-09-05 18:13   ` Jim Cromie
2026-09-05 18:31   ` sashiko-bot
2026-09-05 18:13 ` [PATCH v8 28/43] selftests/dyndbg: enable FT_classmap_inheritance Jim Cromie via B4 Relay
2026-09-05 18:13   ` Jim Cromie
2026-09-05 18:13 ` [PATCH v8 29/43] dyndbg: detect class_id reservation conflicts Jim Cromie via B4 Relay
2026-09-05 18:13   ` Jim Cromie
2026-09-05 18:30   ` sashiko-bot
2026-09-05 18:13 ` [PATCH v8 30/43] dyndbg: check DYNAMIC_DEBUG_CLASSMAP_{DEFINE,USE_} args at compile-time Jim Cromie via B4 Relay
2026-09-05 18:13   ` Jim Cromie
2026-09-05 18:27   ` sashiko-bot
2026-09-05 18:13 ` [PATCH v8 31/43] dyndbg-test: add do_bulk testpoint, rename do_prints to do_classes Jim Cromie via B4 Relay
2026-09-05 18:13   ` Jim Cromie
2026-09-05 18:31   ` sashiko-bot
2026-09-05 18:13 ` [PATCH v8 32/43] dyndbg-API: promote DYNAMIC_DEBUG_CLASSMAP_PARAM to API Jim Cromie via B4 Relay
2026-09-05 18:13   ` Jim Cromie
2026-09-05 18:28   ` sashiko-bot
2026-09-05 18:13 ` [PATCH v8 33/43] dyndbg: control-parser: treat comma as a token separator Jim Cromie via B4 Relay
2026-09-05 18:13   ` Jim Cromie
2026-09-05 18:13 ` [PATCH v8 34/43] selftests: enable comma-terminator tests Jim Cromie via B4 Relay
2026-09-05 18:13   ` Jim Cromie
2026-09-05 18:13 ` [PATCH v8 35/43] dyndbg: split multi-query strings with @ Jim Cromie via B4 Relay
2026-09-05 18:13   ` Jim Cromie
2026-09-05 18:24   ` sashiko-bot
2026-09-05 18:13 ` [PATCH v8 36/43] dyndbg: resolve "protection" of class'd pr_debug Jim Cromie via B4 Relay
2026-09-05 18:13   ` Jim Cromie
2026-09-05 18:33   ` sashiko-bot
2026-09-05 18:13 ` [PATCH v8 37/43] dyndbg: harden classmap and descriptor validation Jim Cromie via B4 Relay
2026-09-05 18:13   ` Jim Cromie
2026-09-05 18:29   ` sashiko-bot
2026-09-05 18:13 ` [PATCH v8 38/43] docs/dyndbg: add classmap info to howto Jim Cromie via B4 Relay
2026-09-05 18:13   ` Jim Cromie
2026-09-05 18:23   ` sashiko-bot
2026-09-05 18:13 ` [PATCH v8 39/43] dyndbg: Ignore additional arguments from pr_fmt Jim Cromie via B4 Relay
2026-09-05 18:13   ` Jim Cromie
2026-09-05 18:31   ` sashiko-bot
2026-09-05 18:13 ` [PATCH v8 40/43] dyndbg: add epilogue to dynamic_debug/control file Jim Cromie via B4 Relay
2026-09-05 18:13   ` Jim Cromie
2026-09-05 18:25   ` sashiko-bot
2026-09-05 18:13 ` [PATCH v8 41/43] dyndbg: add +c flag to count advantage of classmaps for DRM Jim Cromie via B4 Relay
2026-09-05 18:13   ` Jim Cromie
2026-09-05 18:29   ` sashiko-bot [this message]
2026-09-05 18:13 ` [PATCH v8 42/43] dyndbg: add DEBUG-biased fallback stubs for _dynamic_func_call_cls Jim Cromie via B4 Relay
2026-09-05 18:13   ` Jim Cromie
2026-09-05 18:31   ` sashiko-bot
2026-09-05 18:13 ` [PATCH v8 43/43] selftests/dynamic_debug: Prime params module with +p in FT_comma_terminators Jim Cromie via B4 Relay
2026-09-05 18:13   ` Jim Cromie
2026-09-05 18:27   ` sashiko-bot

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260905182924.4BB3B1F00A3A@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=dri-devel@lists.freedesktop.org \
    --cc=jim.cromie@gmail.com \
    --cc=linux-modules@vger.kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.