From: sashiko-bot@kernel.org
To: "Jim Cromie" <jim.cromie@gmail.com>
Cc: linux-modules@vger.kernel.org, dri-devel@lists.freedesktop.org
Subject: Re: [PATCH v8 37/43] dyndbg: harden classmap and descriptor validation
Date: Sat, 05 Sep 2026 18:29:44 +0000 [thread overview]
Message-ID: <20260905182944.DECE31F00A3A@smtp.kernel.org> (raw)
In-Reply-To: <20260905-dd-cmap-part2-clean-v8-37-a4cc0674f6fd@gmail.com>
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [Medium] Off-by-one error in runtime classmap offset validation restricts the maximum valid class ID.
--
commit 9fc4489f7afee86c427de8b09e6f38f827d4fc24
Author: Jim Cromie <jim.cromie@gmail.com>
dyndbg: harden classmap and descriptor validation
This commit improves classmap and descriptor validation by mirroring
compile-time limits of _DEFINE and adding run-time overlap checks for _USEd
classmaps. It scans module descriptors at load time to warn about missing
class_ids instead of waiting for a user query.
> diff --git a/lib/dynamic_debug.c b/lib/dynamic_debug.c
> index a5d813ad323a1..b7ccf471b5efe 100644
> --- a/lib/dynamic_debug.c
> +++ b/lib/dynamic_debug.c
[ ... ]
> @@ -1524,10 +1543,47 @@ static int ddebug_add_module(struct _ddebug_info *di)
> dd_set_module_subrange(i, cm, &dt->info, maps);
> dd_set_module_subrange(i, cli, &dt->info, users);
>
> - /* insure 2+ classmaps share the per-module 0..62 class_id space */
> + /* validate the per-module shared 0..62 class_id space */
> for_subvec(i, cm, &dt->info, maps)
> if (ddebug_class_range_overlap(cm, &reserved_ids))
> - goto cleanup;
> + err = -EINVAL;
> +
> + for_subvec(i, cli, &dt->info, users) {
> + cm = cli->map;
> + if (!cm) {
> + pr_err("module %s: classmap not found for user\n", di->mod_name);
> + err = -EINVAL;
> + continue;
> + }
> +
> + if (cm->base + cm->length + cli->offset >= _DPRINTK_CLASS_DFLT) {
[Severity: Medium]
Does this condition have an off-by-one error that restricts the maximum valid
class ID?
The _DPRINTK_CLASS_DFLT macro is defined as 63, which means valid class IDs
range from 0 to 62. The maximum assigned class ID for a given map and offset is
base + length + offset - 1. If base + length + offset == 63, the maximum
assigned class ID is exactly 62, which should be valid.
Because the code checks if the sum is >= _DPRINTK_CLASS_DFLT, a valid
boundary case of 63 is erroneously flagged as an error. This shrinks the valid
class ID space to 0..61 instead of the expected 0..62.
> + pr_err("module %s: base:%d + classes.len:%d + cli.offset:%d must be < %d\n",
> + di->mod_name, cm->base, cm->length,
> + cli->offset, _DPRINTK_CLASS_DFLT);
> + err = -EINVAL;
> + continue;
> + }
> +
> + if (ddebug_class_user_overlap(cli, &reserved_ids))
> + err = -EINVAL;
> + }
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260905-dd-cmap-part2-clean-v8-0-a4cc0674f6fd@gmail.com?part=37
next prev parent reply other threads:[~2026-09-05 18:29 UTC|newest]
Thread overview: 106+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-05 18:13 [PATCH v8 00/43] dyndbg: fix classmaps API for DRM, query extensions, and selftests Jim Cromie via B4 Relay
2026-09-05 18:13 ` Jim Cromie
2026-09-05 18:13 ` [PATCH v8 01/43] selftests/dyndbg: Add kselftest script to verify dynamic-debug Jim Cromie via B4 Relay
2026-09-05 18:13 ` Jim Cromie
2026-09-05 18:22 ` sashiko-bot
2026-09-05 18:13 ` [PATCH v8 02/43] drm: Fix incorrect ccflags-y spelling inside Makefile Jim Cromie via B4 Relay
2026-09-05 18:13 ` Jim Cromie
2026-09-05 18:13 ` [PATCH v8 03/43] drm: fix config dependent unused variable warning Jim Cromie via B4 Relay
2026-09-05 18:13 ` Jim Cromie
2026-09-05 18:13 ` [PATCH v8 04/43] drm: Mark CONFIG_DRM_USE_DYNAMIC_DEBUG as unBROKEN Jim Cromie via B4 Relay
2026-09-05 18:13 ` Jim Cromie
2026-09-05 18:19 ` sashiko-bot
2026-09-05 18:13 ` [PATCH v8 05/43] vmlinux.lds.h: refactor BOUNDED_SECTION_* macros into bounded_sections.lds.h Jim Cromie via B4 Relay
2026-09-05 18:13 ` Jim Cromie
2026-09-05 18:13 ` [PATCH v8 06/43] vmlinux.lds.h: drop unused HEADERED_SECTION* macros Jim Cromie via B4 Relay
2026-09-05 18:13 ` Jim Cromie
2026-09-05 18:13 ` [PATCH v8 07/43] vmlinux.lds.h: Fix ALIGN(8) omission causing NULL ptr on i386 Jim Cromie via B4 Relay
2026-09-05 18:13 ` Jim Cromie
2026-09-05 18:13 ` [PATCH v8 08/43] vmlinux.lds.h: remove redundant ALIGN(8) directives Jim Cromie via B4 Relay
2026-09-05 18:13 ` Jim Cromie
2026-09-05 18:13 ` [PATCH v8 09/43] dyndbg.lds.S: fix lost dyndbg sections in modules Jim Cromie via B4 Relay
2026-09-05 18:13 ` Jim Cromie
2026-09-05 18:13 ` [PATCH v8 10/43] dyndbg: factor ddebug_match_desc out from ddebug_change Jim Cromie via B4 Relay
2026-09-05 18:13 ` Jim Cromie
2026-09-05 18:13 ` [PATCH v8 11/43] dyndbg: add stub macro for DECLARE_DYNDBG_CLASSMAP Jim Cromie via B4 Relay
2026-09-05 18:13 ` Jim Cromie
2026-09-05 18:13 ` [PATCH v8 12/43] dyndbg: reword "class unknown," to "class:_UNKNOWN_" Jim Cromie via B4 Relay
2026-09-05 18:13 ` Jim Cromie
2026-09-05 18:13 ` [PATCH v8 13/43] dyndbg-API: remove DD_CLASS_TYPE_(DISJOINT|LEVEL)_NAMES and code Jim Cromie via B4 Relay
2026-09-05 18:13 ` Jim Cromie
2026-09-05 18:13 ` [PATCH v8 14/43] dyndbg: drop NUM_TYPE_ARGS Jim Cromie via B4 Relay
2026-09-05 18:13 ` Jim Cromie
2026-09-05 18:13 ` [PATCH v8 15/43] dyndbg: bump num-tokens in a query-cmd from 9 to 15 Jim Cromie via B4 Relay
2026-09-05 18:13 ` Jim Cromie
2026-09-05 18:13 ` [PATCH v8 16/43] dyndbg: reduce verbose/debug clutter Jim Cromie via B4 Relay
2026-09-05 18:13 ` Jim Cromie
2026-09-05 18:13 ` [PATCH v8 17/43] lib/parser: add match_wildcard_hyphen() for agnostic matching Jim Cromie via B4 Relay
2026-09-05 18:13 ` Jim Cromie
2026-09-05 18:13 ` [PATCH v8 18/43] kbuild, dyndbg: clean up builtin module-name ambiguities Jim Cromie via B4 Relay
2026-09-05 18:13 ` Jim Cromie
2026-09-05 18:26 ` sashiko-bot
2026-09-05 18:13 ` [PATCH v8 19/43] dyndbg: refactor param_set_dyndbg_classes and below Jim Cromie via B4 Relay
2026-09-05 18:13 ` Jim Cromie
2026-09-05 18:13 ` [PATCH v8 20/43] dyndbg: tighten fn-sig of ddebug_apply_class_bitmap Jim Cromie via B4 Relay
2026-09-05 18:13 ` Jim Cromie
2026-09-05 18:13 ` [PATCH v8 21/43] dyndbg: replace classmap list with an array-slice Jim Cromie via B4 Relay
2026-09-05 18:13 ` Jim Cromie
2026-09-05 18:25 ` sashiko-bot
2026-09-05 18:13 ` [PATCH v8 22/43] dyndbg: macrofy a 2-index for-loop pattern Jim Cromie via B4 Relay
2026-09-05 18:13 ` Jim Cromie
2026-09-05 18:13 ` [PATCH v8 23/43] dyndbg: reduce class param storage to u32 Jim Cromie via B4 Relay
2026-09-05 18:13 ` Jim Cromie
2026-09-05 18:13 ` [PATCH v8 24/43] dyndbg,module: make proper substructs in _ddebug_info Jim Cromie via B4 Relay
2026-09-05 18:13 ` Jim Cromie
2026-09-05 18:13 ` [PATCH v8 25/43] dyndbg: move mod_name down from struct ddebug_table to _ddebug_info Jim Cromie via B4 Relay
2026-09-05 18:13 ` Jim Cromie
2026-09-05 18:13 ` [PATCH v8 26/43] dyndbg: hoist classmap-filter-by-modname up to ddebug_add_module Jim Cromie via B4 Relay
2026-09-05 18:13 ` Jim Cromie
2026-09-05 18:13 ` [PATCH v8 27/43] dyndbg-API: replace DECLARE_DYNDBG_CLASSMAP Jim Cromie via B4 Relay
2026-09-05 18:13 ` Jim Cromie
2026-09-05 18:31 ` sashiko-bot
2026-09-05 18:13 ` [PATCH v8 28/43] selftests/dyndbg: enable FT_classmap_inheritance Jim Cromie via B4 Relay
2026-09-05 18:13 ` Jim Cromie
2026-09-05 18:13 ` [PATCH v8 29/43] dyndbg: detect class_id reservation conflicts Jim Cromie via B4 Relay
2026-09-05 18:13 ` Jim Cromie
2026-09-05 18:30 ` sashiko-bot
2026-09-05 18:13 ` [PATCH v8 30/43] dyndbg: check DYNAMIC_DEBUG_CLASSMAP_{DEFINE,USE_} args at compile-time Jim Cromie via B4 Relay
2026-09-05 18:13 ` Jim Cromie
2026-09-05 18:27 ` sashiko-bot
2026-09-05 18:13 ` [PATCH v8 31/43] dyndbg-test: add do_bulk testpoint, rename do_prints to do_classes Jim Cromie via B4 Relay
2026-09-05 18:13 ` Jim Cromie
2026-09-05 18:31 ` sashiko-bot
2026-09-05 18:13 ` [PATCH v8 32/43] dyndbg-API: promote DYNAMIC_DEBUG_CLASSMAP_PARAM to API Jim Cromie via B4 Relay
2026-09-05 18:13 ` Jim Cromie
2026-09-05 18:28 ` sashiko-bot
2026-09-05 18:13 ` [PATCH v8 33/43] dyndbg: control-parser: treat comma as a token separator Jim Cromie via B4 Relay
2026-09-05 18:13 ` Jim Cromie
2026-09-05 18:13 ` [PATCH v8 34/43] selftests: enable comma-terminator tests Jim Cromie via B4 Relay
2026-09-05 18:13 ` Jim Cromie
2026-09-05 18:13 ` [PATCH v8 35/43] dyndbg: split multi-query strings with @ Jim Cromie via B4 Relay
2026-09-05 18:13 ` Jim Cromie
2026-09-05 18:24 ` sashiko-bot
2026-09-05 18:13 ` [PATCH v8 36/43] dyndbg: resolve "protection" of class'd pr_debug Jim Cromie via B4 Relay
2026-09-05 18:13 ` Jim Cromie
2026-09-05 18:33 ` sashiko-bot
2026-09-05 18:13 ` [PATCH v8 37/43] dyndbg: harden classmap and descriptor validation Jim Cromie via B4 Relay
2026-09-05 18:13 ` Jim Cromie
2026-09-05 18:29 ` sashiko-bot [this message]
2026-09-05 18:13 ` [PATCH v8 38/43] docs/dyndbg: add classmap info to howto Jim Cromie via B4 Relay
2026-09-05 18:13 ` Jim Cromie
2026-09-05 18:23 ` sashiko-bot
2026-09-05 18:13 ` [PATCH v8 39/43] dyndbg: Ignore additional arguments from pr_fmt Jim Cromie via B4 Relay
2026-09-05 18:13 ` Jim Cromie
2026-09-05 18:31 ` sashiko-bot
2026-09-05 18:13 ` [PATCH v8 40/43] dyndbg: add epilogue to dynamic_debug/control file Jim Cromie via B4 Relay
2026-09-05 18:13 ` Jim Cromie
2026-09-05 18:25 ` sashiko-bot
2026-09-05 18:13 ` [PATCH v8 41/43] dyndbg: add +c flag to count advantage of classmaps for DRM Jim Cromie via B4 Relay
2026-09-05 18:13 ` Jim Cromie
2026-09-05 18:29 ` sashiko-bot
2026-09-05 18:13 ` [PATCH v8 42/43] dyndbg: add DEBUG-biased fallback stubs for _dynamic_func_call_cls Jim Cromie via B4 Relay
2026-09-05 18:13 ` Jim Cromie
2026-09-05 18:31 ` sashiko-bot
2026-09-05 18:13 ` [PATCH v8 43/43] selftests/dynamic_debug: Prime params module with +p in FT_comma_terminators Jim Cromie via B4 Relay
2026-09-05 18:13 ` Jim Cromie
2026-09-05 18:27 ` sashiko-bot
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260905182944.DECE31F00A3A@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=dri-devel@lists.freedesktop.org \
--cc=jim.cromie@gmail.com \
--cc=linux-modules@vger.kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.