All of lore.kernel.org
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Jim Cromie" <jim.cromie@gmail.com>
Cc: linux-modules@vger.kernel.org, dri-devel@lists.freedesktop.org
Subject: Re: [PATCH v9 33/39] dyndbg: resolve "protection" of class'd pr_debug
Date: Wed, 09 Sep 2026 01:17:21 +0000	[thread overview]
Message-ID: <20260909011721.BBC081F00A3A@smtp.kernel.org> (raw)
In-Reply-To: <20260908-dd-cmap-part2-clean-v9-33-3a3f621f4a10@gmail.com>

Thank you for your contribution! Sashiko AI review found 2 potential issue(s) to consider:
- [High] The function `ddebug_apply_class_maps` is enclosed in an `#if 0` block, preventing `controlling_param` from being initialized for defining modules. This breaks the protection mechanism for parameterized classmaps and fails to apply boot/load-time kernel parameters to the defining module's callsites.
- [Medium] The module is exposed to userspace queries via `ddebug_tables` before its `map->controlling_param` protection state is initialized, creating a data race and TOCTOU vulnerability where concurrent classless queries can bypass protection.
--

commit 3a846cbf484a221d77612af005e27faf83c306df
Author: Jim Cromie <jim.cromie@gmail.com>

dyndbg: resolve "protection" of class'd pr_debug

This commit adds protection for dynamically debugged classes against
class-less queries by using sysfs parameters. It sets a controlling
parameter for parameterized classmaps to prevent accidental modification
from queries that lack a specific class identifier.

> diff --git a/lib/dynamic_debug.c b/lib/dynamic_debug.c
> index e6f5a524d63b6..8c90b1e4cd33e 100644
> --- a/lib/dynamic_debug.c
> +++ b/lib/dynamic_debug.c

[ ... ]

> @@ -1297,25 +1358,35 @@ static void ddebug_sync_classbits(const struct kernel_param *kp, const char *mod
>  	}
>  }
>  
> -static void ddebug_match_apply_kparam(const struct kernel_param *kp,
> -				      const struct ddebug_class_map *map,
> -				      const char *mod_name)
> +static struct ddebug_class_param *
> +ddebug_get_classmap_kparam(const struct kernel_param *kp,
> +			   const struct ddebug_class_map *map)
>  {
>  	struct ddebug_class_param *dcp;
>  
>  	if (kp->ops != &param_ops_dyndbg_classes)
> -		return;
> +		return NULL;
>  
>  	dcp = (struct ddebug_class_param *)kp->arg;
> +	return (map == dcp->map)
> +		? dcp : (struct ddebug_class_param *)NULL;
> +}
> +
> +static void ddebug_match_apply_kparam(const struct kernel_param *kp,
> +				      struct ddebug_class_map *map,
> +				      const char *mod_name)
> +{
> +	struct ddebug_class_param *dcp = ddebug_get_classmap_kparam(kp, map);
>  
>  	if (dcp && dcp->map == map) {
> +		map->controlling_param = dcp;

[Severity: Medium]
Could this lockless write to map->controlling_param cause a data race?

When a module is loaded, ddebug_add_module() adds the module to the
ddebug_tables list under the ddebug_lock:

mutex_lock(&ddebug_lock);
list_add_tail(&dt->link, &ddebug_tables);
mutex_unlock(&ddebug_lock);

It then drops the lock and calls ddebug_apply_class_users(), which reaches
this code and locklessly writes to map->controlling_param.

Since the module is already visible in ddebug_tables before this
initialization completes, could a concurrent classless sysfs query bypass
protection by evaluating ddebug_class_wants_protection() on a newly added
module before controlling_param is set?

> +		v2pr_info(" kp:%s.%s =0x%x", mod_name, kp->name, *dcp->bits);
> +		vpr_cm_info(map, " %s maps ", mod_name);
> +		ddebug_sync_classbits(kp, mod_name);
>  	}
>  }

[ ... ]

> @@ -1338,6 +1409,26 @@ static void ddebug_apply_params(const struct ddebug_class_map *cm, const char *m
>  	}
>  }
>  
> +#if 0
> +/*
> + * called from add_module, ie early. it can find controlling kparams,
> + * which can/does? enable protection of this classmap from class-less
> + * queries, on the grounds that the user created the kparam, means to
> + * use it, and expects it to reflect reality.  We should oblige him,
> + * and protect those classmaps from classless "-p" changes.
> + */
> +static void ddebug_apply_class_maps(const struct _ddebug_info *di)
> +{
> +	struct ddebug_class_map *cm;
> +	int i;
> +
> +	for_subvec(i, cm, di, maps)
> +		ddebug_apply_params(cm, cm->mod_name);
> +
> +	v2pr_di_info(di, "attached %d class-maps to ", i);
> +}
> +#endif

[Severity: High]
Does this disabled code block break the intended protection for parameterized
classmaps defined within the module?

Because ddebug_apply_class_maps() is enclosed in an #if 0 block, the
controlling_param is never initialized for the module defining the classmap.
As a result, ddebug_class_wants_protection() will evaluate to false because
site_map->controlling_param is NULL.

Will this cause boot and load-time kernel parameters (like drm.debug=VAL)
to not be applied to the defining module's callsites, allowing class-less
queries to improperly modify them?

> +
>  static void ddebug_apply_class_users(const struct _ddebug_info *di)
>  {
>  	struct ddebug_class_user *cli;

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260908-dd-cmap-part2-clean-v9-0-3a3f621f4a10@gmail.com?part=33

  reply	other threads:[~2026-09-09  1:17 UTC|newest]

Thread overview: 96+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-09  0:54 [PATCH v9 00/39] dyndbg: fix classmaps API for subsystems, query extensions, and selftests Jim Cromie
2026-09-09  0:54 ` Jim Cromie via B4 Relay
2026-09-09  0:54 ` [PATCH v9 01/39] selftests/dyndbg: Add kselftest script to verify dynamic-debug Jim Cromie via B4 Relay
2026-09-09  0:54   ` Jim Cromie
2026-09-09  0:54 ` [PATCH v9 02/39] vmlinux.lds.h: refactor BOUNDED_SECTION_* macros into bounded_sections.lds.h Jim Cromie via B4 Relay
2026-09-09  0:54   ` Jim Cromie
2026-09-09  0:54 ` [PATCH v9 03/39] vmlinux.lds.h: drop unused HEADERED_SECTION* macros Jim Cromie via B4 Relay
2026-09-09  0:54   ` Jim Cromie
2026-09-09  0:55 ` [PATCH v9 04/39] vmlinux.lds.h: Fix ALIGN(8) omission causing NULL ptr on i386 Jim Cromie via B4 Relay
2026-09-09  0:55   ` Jim Cromie
2026-09-09  0:55 ` [PATCH v9 05/39] vmlinux.lds.h: remove redundant ALIGN(8) directives Jim Cromie
2026-09-09  0:55   ` Jim Cromie via B4 Relay
2026-09-09  0:55 ` [PATCH v9 06/39] dyndbg.lds.S: fix lost dyndbg sections in modules Jim Cromie
2026-09-09  0:55   ` Jim Cromie via B4 Relay
2026-09-09  0:55 ` [PATCH v9 07/39] dyndbg: factor ddebug_match_desc out from ddebug_change Jim Cromie via B4 Relay
2026-09-09  0:55   ` Jim Cromie
2026-09-09  1:03   ` sashiko-bot
2026-09-09  0:55 ` [PATCH v9 08/39] dyndbg: add stub macro for DECLARE_DYNDBG_CLASSMAP Jim Cromie
2026-09-09  0:55   ` Jim Cromie via B4 Relay
2026-09-09  1:10   ` sashiko-bot
2026-09-09  0:55 ` [PATCH v9 09/39] dyndbg: reword "class unknown," to "class:_UNKNOWN_" Jim Cromie
2026-09-09  0:55   ` Jim Cromie via B4 Relay
2026-09-09  0:55 ` [PATCH v9 10/39] dyndbg-API: remove DD_CLASS_TYPE_(DISJOINT|LEVEL)_NAMES and code Jim Cromie
2026-09-09  0:55   ` Jim Cromie via B4 Relay
2026-09-09  0:55 ` [PATCH v9 11/39] dyndbg: drop NUM_TYPE_ARGS Jim Cromie
2026-09-09  0:55   ` Jim Cromie via B4 Relay
2026-09-09  0:55 ` [PATCH v9 12/39] dyndbg: bump num-tokens in a query-cmd from 9 to 15 Jim Cromie
2026-09-09  0:55   ` Jim Cromie via B4 Relay
2026-09-09  0:55 ` [PATCH v9 13/39] dyndbg: reduce verbose/debug clutter Jim Cromie
2026-09-09  0:55   ` Jim Cromie via B4 Relay
2026-09-09  0:55 ` [PATCH v9 14/39] lib/parser: add match_wildcard_hyphen() for agnostic matching Jim Cromie
2026-09-09  0:55   ` Jim Cromie via B4 Relay
2026-09-09  0:55 ` [PATCH v9 15/39] kbuild, dyndbg: Clean up builtin module-name ambiguities Jim Cromie
2026-09-09  0:55   ` Jim Cromie via B4 Relay
2026-09-09 15:50   ` Nicolas Schier
2026-09-11 18:20     ` jim.cromie
2026-09-09  0:55 ` [PATCH v9 16/39] dyndbg: refactor param_set_dyndbg_classes and below Jim Cromie
2026-09-09  0:55   ` Jim Cromie via B4 Relay
2026-09-09  0:55 ` [PATCH v9 17/39] dyndbg: tighten fn-sig of ddebug_apply_class_bitmap Jim Cromie
2026-09-09  0:55   ` Jim Cromie via B4 Relay
2026-09-09  0:55 ` [PATCH v9 18/39] dyndbg: replace classmap list with an array-slice Jim Cromie
2026-09-09  0:55   ` Jim Cromie via B4 Relay
2026-09-09  0:55 ` [PATCH v9 19/39] dyndbg: macrofy a 2-index for-loop pattern Jim Cromie
2026-09-09  0:55   ` Jim Cromie via B4 Relay
2026-09-09  0:55 ` [PATCH v9 20/39] dyndbg: reduce class param storage to u32 Jim Cromie
2026-09-09  0:55   ` Jim Cromie via B4 Relay
2026-09-09  0:55 ` [PATCH v9 21/39] dyndbg,module: make proper substructs in _ddebug_info Jim Cromie via B4 Relay
2026-09-09  0:55   ` Jim Cromie
2026-09-09  0:55 ` [PATCH v9 22/39] dyndbg: move mod_name down from struct ddebug_table to _ddebug_info Jim Cromie
2026-09-09  0:55   ` Jim Cromie via B4 Relay
2026-09-09  0:55 ` [PATCH v9 23/39] dyndbg: hoist classmap-filter-by-modname up to ddebug_add_module Jim Cromie via B4 Relay
2026-09-09  0:55   ` Jim Cromie
2026-09-09  0:55 ` [PATCH v9 24/39] dyndbg-API: replace DECLARE_DYNDBG_CLASSMAP Jim Cromie
2026-09-09  0:55   ` Jim Cromie via B4 Relay
2026-09-09  1:13   ` sashiko-bot
2026-09-09 20:56     ` jim.cromie
2026-09-09  0:55 ` [PATCH v9 25/39] selftests/dyndbg: enable FT_classmap_inheritance Jim Cromie
2026-09-09  0:55   ` Jim Cromie via B4 Relay
2026-09-09  0:55 ` [PATCH v9 26/39] dyndbg: detect class_id reservation conflicts Jim Cromie
2026-09-09  0:55   ` Jim Cromie via B4 Relay
2026-09-09  0:55 ` [PATCH v9 27/39] dyndbg: check DYNAMIC_DEBUG_CLASSMAP_{DEFINE,USE_} args at compile-time Jim Cromie via B4 Relay
2026-09-09  0:55   ` Jim Cromie
2026-09-09  1:07   ` sashiko-bot
2026-09-09  0:55 ` [PATCH v9 28/39] dyndbg-test: add do_bulk testpoint, rename do_prints to do_classes Jim Cromie
2026-09-09  0:55   ` Jim Cromie via B4 Relay
2026-09-09  1:08   ` sashiko-bot
2026-09-09  0:55 ` [PATCH v9 29/39] dyndbg-API: promote DYNAMIC_DEBUG_CLASSMAP_PARAM to API Jim Cromie
2026-09-09  0:55   ` Jim Cromie via B4 Relay
2026-09-09  1:08   ` sashiko-bot
2026-09-09  0:55 ` [PATCH v9 30/39] dyndbg: control-parser: treat comma as a token separator Jim Cromie
2026-09-09  0:55   ` Jim Cromie via B4 Relay
2026-09-09  0:55 ` [PATCH v9 31/39] selftests: enable comma-terminator tests Jim Cromie
2026-09-09  0:55   ` Jim Cromie via B4 Relay
2026-09-09  0:55 ` [PATCH v9 32/39] dyndbg: split multi-query strings with @ Jim Cromie
2026-09-09  0:55   ` Jim Cromie via B4 Relay
2026-09-09  1:06   ` sashiko-bot
2026-09-09  0:55 ` [PATCH v9 33/39] dyndbg: resolve "protection" of class'd pr_debug Jim Cromie
2026-09-09  0:55   ` Jim Cromie via B4 Relay
2026-09-09  1:17   ` sashiko-bot [this message]
2026-09-09  0:55 ` [PATCH v9 34/39] dyndbg: harden classmap and descriptor validation Jim Cromie
2026-09-09  0:55   ` Jim Cromie via B4 Relay
2026-09-09  1:13   ` sashiko-bot
2026-09-09  0:55 ` [PATCH v9 35/39] docs/dyndbg: add classmap info to howto Jim Cromie
2026-09-09  0:55   ` Jim Cromie via B4 Relay
2026-09-09  0:55 ` [PATCH v9 36/39] dyndbg: Ignore additional arguments from pr_fmt Jim Cromie
2026-09-09  0:55   ` Jim Cromie via B4 Relay
2026-09-09  1:14   ` sashiko-bot
2026-09-09  0:55 ` [PATCH v9 37/39] dyndbg: add epilogue to dynamic_debug/control file Jim Cromie
2026-09-09  0:55   ` Jim Cromie via B4 Relay
2026-09-09  1:09   ` sashiko-bot
2026-09-09  0:55 ` [PATCH v9 38/39] dyndbg: add +c flag to count advantage of classmaps for DRM Jim Cromie
2026-09-09  0:55   ` Jim Cromie via B4 Relay
2026-09-09  1:11   ` sashiko-bot
2026-09-09  0:55 ` [PATCH v9 39/39] dyndbg: add DEBUG-biased fallback stubs for _dynamic_func_call_cls Jim Cromie
2026-09-09  0:55   ` Jim Cromie via B4 Relay
2026-09-09  1:12   ` sashiko-bot

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260909011721.BBC081F00A3A@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=dri-devel@lists.freedesktop.org \
    --cc=jim.cromie@gmail.com \
    --cc=linux-modules@vger.kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.