All of lore.kernel.org
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Jim Cromie" <jim.cromie@gmail.com>
Cc: dri-devel@lists.freedesktop.org, linux-modules@vger.kernel.org
Subject: Re: [PATCH v8 36/43] dyndbg: resolve "protection" of class'd pr_debug
Date: Sat, 05 Sep 2026 18:33:13 +0000	[thread overview]
Message-ID: <20260905183314.541AC1F00A3D@smtp.kernel.org> (raw)
In-Reply-To: <20260905-dd-cmap-part2-clean-v8-36-a4cc0674f6fd@gmail.com>

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [Medium] The 'controlling_param' field in 'struct ddebug_class_map' is never assigned and its initialization path is disabled, completely breaking the intended protection mechanism for class'd pr_debugs.
--

commit 6f4d594fc681c54264d43b5caa68a2316a8b157d
Author: Jim Cromie <jim.cromie@gmail.com>

dyndbg: resolve "protection" of class'd pr_debug

This commit aims to protect class'd pr_debugs from unintended changes by
unclassed legacy queries (like `echo -p > /proc/dynamic_debug/control`).
It introduces a link from `ddebug_class_map` to `controlling_param` and
intends to check it to decide whether to protect the class map.

> diff --git a/lib/dynamic_debug.c b/lib/dynamic_debug.c
> index 93a5a481c8b8c..a5d813ad323a1 100644
> --- a/lib/dynamic_debug.c
> +++ b/lib/dynamic_debug.c

[ ... ]

> +static inline bool ddebug_class_has_param(const struct ddebug_class_map *map)
> +{
> +	return !!(map->controlling_param);
> +}
> +
> +/* re-framed as a policy choice */
> +#define ddebug_class_wants_protection(map) (ddebug_class_has_param(map))
> +
>  /*
>   * Search the tables for _ddebug's which match the given `query' and
>   * apply the `flags' and `mask' to them.  Returns number of matching

[ ... ]

> @@ -256,7 +299,28 @@ static bool ddebug_match_desc(const struct ddebug_query *query,
>  	    dp->lineno > query->last_lineno)
>  		return false;
>  
> -	return true;
> +	/*
> +	 * above are all satisfied, so we can make final decisions:
> +	 * 1- class FOO or implied class __DEFAULT__
> +	 * 2- site.is_classed or not
> +	 */
> +	if (query->class_string) {
> +		/* class FOO given, exact match required */
> +		return (dp->class_id == selected_class);
> +	}
> +	/* query class __DEFAULT__ by omission. */
> +	if (dp->class_id == _DPRINTK_CLASS_DFLT) {
> +		/* un-classed site */
> +		return true;
> +	}
> +	/* site is class'd */
> +	site_map = ddebug_find_map_by_class_id(di, dp->class_id);
> +	if (!site_map) {
> +		WARN_ONCE(1, "unknown class_id %d, check %s's CLASSMAP definitions", dp->class_id, di->mod_name);
> +		return false;
> +	}
> +	/* module(-param) decides protection */
> +	return !ddebug_class_wants_protection(site_map);
>  }

[Severity: Medium]
Will `ddebug_class_wants_protection()` always evaluate to false?

Because `map->controlling_param` appears to never be initialized, it seems
this will always return false, which causes the function to return true
and bypass the intended protection for class'd pr_debugs against unclassed
legacy queries.

[ ... ]

> @@ -1298,16 +1359,25 @@ static void ddebug_sync_classbits(const struct kernel_param *kp, const char *mod
>  	}
>  }
>  
> -static void ddebug_match_apply_kparam(const struct kernel_param *kp,
> -				      const struct ddebug_class_map *map,
> -				      const char *mod_name)
> +static struct ddebug_class_param *
> +ddebug_get_classmap_kparam(const struct kernel_param *kp,
> +			   const struct ddebug_class_map *map)
>  {
>  	struct ddebug_class_param *dcp;
>  
>  	if (kp->ops != &param_ops_dyndbg_classes)
> -		return;
> +		return NULL;
>  
>  	dcp = (struct ddebug_class_param *)kp->arg;
> +	return (map == dcp->map)
> +		? dcp : (struct ddebug_class_param *)NULL;
> +}
> +
> +static void ddebug_match_apply_kparam(const struct kernel_param *kp,
> +				      struct ddebug_class_map *map,
> +				      const char *mod_name)
> +{
> +	struct ddebug_class_param *dcp = ddebug_get_classmap_kparam(kp, map);
>  
>  	if (dcp && dcp->map == map) {
>  		v2pr_info(" kp:%s.%s =0x%x", mod_name, kp->name, *dcp->bits);
>  		vpr_cm_info(map, " %s maps ", mod_name);
>  		ddebug_sync_classbits(kp, mod_name);
>  	}
>  }

[Severity: Medium]
Was the assignment `map->controlling_param = dcp;` intended to be added here?

The commit message states that the patch "sets it in
ddebug_match_apply_kparam()", but the assignment seems to be missing.
Adding the assignment locklessly could also introduce a data race here.

[ ... ]

> @@ -1339,6 +1409,26 @@ static void ddebug_apply_params(const struct ddebug_class_map *cm, const char *m
>  	}
>  }
>  
> +#if 0
> +/*
> + * called from add_module, ie early. it can find controlling kparams,
> + * which can/does? enable protection of this classmap from class-less
> + * queries, on the grounds that the user created the kparam, means to
> + * use it, and expects it to reflect reality.  We should oblige him,
> + * and protect those classmaps from classless "-p" changes.
> + */
> +static void ddebug_apply_class_maps(const struct _ddebug_info *di)
> +{
> +	struct ddebug_class_map *cm;
> +	int i;
> +
> +	for_subvec(i, cm, di, maps)
> +		ddebug_apply_params(cm, cm->mod_name);
> +
> +	v2pr_di_info(di, "attached %d class-maps to ", i);
> +}
> +#endif
> +
>  static void ddebug_apply_class_users(const struct _ddebug_info *di)
>  {

[Severity: Medium]
Does the `#if 0` block around `ddebug_apply_class_maps()` prevent
`ddebug_match_apply_kparam()` from ever being called for the defining module?

If this function is disabled, the parameter initialization appears unreachable
for the defining module's map, even if the assignment was added to
`ddebug_match_apply_kparam()`.

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260905-dd-cmap-part2-clean-v8-0-a4cc0674f6fd@gmail.com?part=36

  reply	other threads:[~2026-09-05 18:33 UTC|newest]

Thread overview: 106+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-05 18:13 [PATCH v8 00/43] dyndbg: fix classmaps API for DRM, query extensions, and selftests Jim Cromie via B4 Relay
2026-09-05 18:13 ` Jim Cromie
2026-09-05 18:13 ` [PATCH v8 01/43] selftests/dyndbg: Add kselftest script to verify dynamic-debug Jim Cromie via B4 Relay
2026-09-05 18:13   ` Jim Cromie
2026-09-05 18:22   ` sashiko-bot
2026-09-05 18:13 ` [PATCH v8 02/43] drm: Fix incorrect ccflags-y spelling inside Makefile Jim Cromie via B4 Relay
2026-09-05 18:13   ` Jim Cromie
2026-09-05 18:13 ` [PATCH v8 03/43] drm: fix config dependent unused variable warning Jim Cromie via B4 Relay
2026-09-05 18:13   ` Jim Cromie
2026-09-05 18:13 ` [PATCH v8 04/43] drm: Mark CONFIG_DRM_USE_DYNAMIC_DEBUG as unBROKEN Jim Cromie via B4 Relay
2026-09-05 18:13   ` Jim Cromie
2026-09-05 18:19   ` sashiko-bot
2026-09-05 18:13 ` [PATCH v8 05/43] vmlinux.lds.h: refactor BOUNDED_SECTION_* macros into bounded_sections.lds.h Jim Cromie via B4 Relay
2026-09-05 18:13   ` Jim Cromie
2026-09-05 18:13 ` [PATCH v8 06/43] vmlinux.lds.h: drop unused HEADERED_SECTION* macros Jim Cromie via B4 Relay
2026-09-05 18:13   ` Jim Cromie
2026-09-05 18:13 ` [PATCH v8 07/43] vmlinux.lds.h: Fix ALIGN(8) omission causing NULL ptr on i386 Jim Cromie via B4 Relay
2026-09-05 18:13   ` Jim Cromie
2026-09-05 18:13 ` [PATCH v8 08/43] vmlinux.lds.h: remove redundant ALIGN(8) directives Jim Cromie via B4 Relay
2026-09-05 18:13   ` Jim Cromie
2026-09-05 18:13 ` [PATCH v8 09/43] dyndbg.lds.S: fix lost dyndbg sections in modules Jim Cromie via B4 Relay
2026-09-05 18:13   ` Jim Cromie
2026-09-05 18:13 ` [PATCH v8 10/43] dyndbg: factor ddebug_match_desc out from ddebug_change Jim Cromie via B4 Relay
2026-09-05 18:13   ` Jim Cromie
2026-09-05 18:13 ` [PATCH v8 11/43] dyndbg: add stub macro for DECLARE_DYNDBG_CLASSMAP Jim Cromie via B4 Relay
2026-09-05 18:13   ` Jim Cromie
2026-09-05 18:13 ` [PATCH v8 12/43] dyndbg: reword "class unknown," to "class:_UNKNOWN_" Jim Cromie via B4 Relay
2026-09-05 18:13   ` Jim Cromie
2026-09-05 18:13 ` [PATCH v8 13/43] dyndbg-API: remove DD_CLASS_TYPE_(DISJOINT|LEVEL)_NAMES and code Jim Cromie via B4 Relay
2026-09-05 18:13   ` Jim Cromie
2026-09-05 18:13 ` [PATCH v8 14/43] dyndbg: drop NUM_TYPE_ARGS Jim Cromie via B4 Relay
2026-09-05 18:13   ` Jim Cromie
2026-09-05 18:13 ` [PATCH v8 15/43] dyndbg: bump num-tokens in a query-cmd from 9 to 15 Jim Cromie via B4 Relay
2026-09-05 18:13   ` Jim Cromie
2026-09-05 18:13 ` [PATCH v8 16/43] dyndbg: reduce verbose/debug clutter Jim Cromie via B4 Relay
2026-09-05 18:13   ` Jim Cromie
2026-09-05 18:13 ` [PATCH v8 17/43] lib/parser: add match_wildcard_hyphen() for agnostic matching Jim Cromie via B4 Relay
2026-09-05 18:13   ` Jim Cromie
2026-09-05 18:13 ` [PATCH v8 18/43] kbuild, dyndbg: clean up builtin module-name ambiguities Jim Cromie via B4 Relay
2026-09-05 18:13   ` Jim Cromie
2026-09-05 18:26   ` sashiko-bot
2026-09-05 18:13 ` [PATCH v8 19/43] dyndbg: refactor param_set_dyndbg_classes and below Jim Cromie via B4 Relay
2026-09-05 18:13   ` Jim Cromie
2026-09-05 18:13 ` [PATCH v8 20/43] dyndbg: tighten fn-sig of ddebug_apply_class_bitmap Jim Cromie via B4 Relay
2026-09-05 18:13   ` Jim Cromie
2026-09-05 18:13 ` [PATCH v8 21/43] dyndbg: replace classmap list with an array-slice Jim Cromie via B4 Relay
2026-09-05 18:13   ` Jim Cromie
2026-09-05 18:25   ` sashiko-bot
2026-09-05 18:13 ` [PATCH v8 22/43] dyndbg: macrofy a 2-index for-loop pattern Jim Cromie via B4 Relay
2026-09-05 18:13   ` Jim Cromie
2026-09-05 18:13 ` [PATCH v8 23/43] dyndbg: reduce class param storage to u32 Jim Cromie via B4 Relay
2026-09-05 18:13   ` Jim Cromie
2026-09-05 18:13 ` [PATCH v8 24/43] dyndbg,module: make proper substructs in _ddebug_info Jim Cromie via B4 Relay
2026-09-05 18:13   ` Jim Cromie
2026-09-05 18:13 ` [PATCH v8 25/43] dyndbg: move mod_name down from struct ddebug_table to _ddebug_info Jim Cromie via B4 Relay
2026-09-05 18:13   ` Jim Cromie
2026-09-05 18:13 ` [PATCH v8 26/43] dyndbg: hoist classmap-filter-by-modname up to ddebug_add_module Jim Cromie via B4 Relay
2026-09-05 18:13   ` Jim Cromie
2026-09-05 18:13 ` [PATCH v8 27/43] dyndbg-API: replace DECLARE_DYNDBG_CLASSMAP Jim Cromie via B4 Relay
2026-09-05 18:13   ` Jim Cromie
2026-09-05 18:31   ` sashiko-bot
2026-09-05 18:13 ` [PATCH v8 28/43] selftests/dyndbg: enable FT_classmap_inheritance Jim Cromie via B4 Relay
2026-09-05 18:13   ` Jim Cromie
2026-09-05 18:13 ` [PATCH v8 29/43] dyndbg: detect class_id reservation conflicts Jim Cromie via B4 Relay
2026-09-05 18:13   ` Jim Cromie
2026-09-05 18:30   ` sashiko-bot
2026-09-05 18:13 ` [PATCH v8 30/43] dyndbg: check DYNAMIC_DEBUG_CLASSMAP_{DEFINE,USE_} args at compile-time Jim Cromie via B4 Relay
2026-09-05 18:13   ` Jim Cromie
2026-09-05 18:27   ` sashiko-bot
2026-09-05 18:13 ` [PATCH v8 31/43] dyndbg-test: add do_bulk testpoint, rename do_prints to do_classes Jim Cromie via B4 Relay
2026-09-05 18:13   ` Jim Cromie
2026-09-05 18:31   ` sashiko-bot
2026-09-05 18:13 ` [PATCH v8 32/43] dyndbg-API: promote DYNAMIC_DEBUG_CLASSMAP_PARAM to API Jim Cromie via B4 Relay
2026-09-05 18:13   ` Jim Cromie
2026-09-05 18:28   ` sashiko-bot
2026-09-05 18:13 ` [PATCH v8 33/43] dyndbg: control-parser: treat comma as a token separator Jim Cromie via B4 Relay
2026-09-05 18:13   ` Jim Cromie
2026-09-05 18:13 ` [PATCH v8 34/43] selftests: enable comma-terminator tests Jim Cromie via B4 Relay
2026-09-05 18:13   ` Jim Cromie
2026-09-05 18:13 ` [PATCH v8 35/43] dyndbg: split multi-query strings with @ Jim Cromie via B4 Relay
2026-09-05 18:13   ` Jim Cromie
2026-09-05 18:24   ` sashiko-bot
2026-09-05 18:13 ` [PATCH v8 36/43] dyndbg: resolve "protection" of class'd pr_debug Jim Cromie via B4 Relay
2026-09-05 18:13   ` Jim Cromie
2026-09-05 18:33   ` sashiko-bot [this message]
2026-09-05 18:13 ` [PATCH v8 37/43] dyndbg: harden classmap and descriptor validation Jim Cromie via B4 Relay
2026-09-05 18:13   ` Jim Cromie
2026-09-05 18:29   ` sashiko-bot
2026-09-05 18:13 ` [PATCH v8 38/43] docs/dyndbg: add classmap info to howto Jim Cromie via B4 Relay
2026-09-05 18:13   ` Jim Cromie
2026-09-05 18:23   ` sashiko-bot
2026-09-05 18:13 ` [PATCH v8 39/43] dyndbg: Ignore additional arguments from pr_fmt Jim Cromie via B4 Relay
2026-09-05 18:13   ` Jim Cromie
2026-09-05 18:31   ` sashiko-bot
2026-09-05 18:13 ` [PATCH v8 40/43] dyndbg: add epilogue to dynamic_debug/control file Jim Cromie via B4 Relay
2026-09-05 18:13   ` Jim Cromie
2026-09-05 18:25   ` sashiko-bot
2026-09-05 18:13 ` [PATCH v8 41/43] dyndbg: add +c flag to count advantage of classmaps for DRM Jim Cromie via B4 Relay
2026-09-05 18:13   ` Jim Cromie
2026-09-05 18:29   ` sashiko-bot
2026-09-05 18:13 ` [PATCH v8 42/43] dyndbg: add DEBUG-biased fallback stubs for _dynamic_func_call_cls Jim Cromie via B4 Relay
2026-09-05 18:13   ` Jim Cromie
2026-09-05 18:31   ` sashiko-bot
2026-09-05 18:13 ` [PATCH v8 43/43] selftests/dynamic_debug: Prime params module with +p in FT_comma_terminators Jim Cromie via B4 Relay
2026-09-05 18:13   ` Jim Cromie
2026-09-05 18:27   ` sashiko-bot

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260905183314.541AC1F00A3D@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=dri-devel@lists.freedesktop.org \
    --cc=jim.cromie@gmail.com \
    --cc=linux-modules@vger.kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.