All of lore.kernel.org
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "John Hubbard" <jhubbard@nvidia.com>,
	"Danilo Krummrich" <dakr@kernel.org>,
	"Alexandre Courbot" <acourbot@nvidia.com>
Cc: "Alex Gaynor" <alex.gaynor@gmail.com>,
	"Zhi Wang" <zhiw@nvidia.com>, "Boqun Feng" <boqun.feng@gmail.com>,
	"Danilo Krummrich" <dakr@kernel.org>,
	"David Airlie" <airlied@gmail.com>,
	"Alistair Popple" <apopple@nvidia.com>,
	"Benno Lossin" <lossin@kernel.org>,
	LKML <linux-kernel@vger.kernel.org>,
	"Alice Ryhl" <aliceryhl@google.com>,
	"Miguel Ojeda" <ojeda@kernel.org>,
	"Timur Tabi" <ttabi@nvidia.com>,
	"Eliot Courtney" <ecourtney@nvidia.com>,
	"Trevor Gross" <tmgross@umich.edu>,
	"Andreas Hindborg" <a.hindborg@kernel.org>,
	nova-gpu@lists.linux.dev,
	"Björn Roy Baron" <bjorn3_gh@protonmail.com>,
	"Alexandre Courbot" <acourbot@nvidia.com>,
	"Joel Fernandes" <joelagnelf@nvidia.com>,
	"Simona Vetter" <simona@ffwll.ch>, "Gary Guo" <gary@garyguo.net>,
	"Bjorn Helgaas" <bhelgaas@google.com>
Subject: Re: [PATCH v5 02/15] rust: sync: completion: add wait_for_completion_timeout()
Date: Wed, 30 Sep 2026 03:59:00 +0000	[thread overview]
Message-ID: <20260930035901.6E6F21F000FF@smtp.kernel.org> (raw)
In-Reply-To: <20260930034148.590687-3-jhubbard@nvidia.com>

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [Medium] rust: sync: wait_for_completion_timeout stack dump on large timeouts
--

commit f89eb4d12071b7e3c61766cd1bbbd5c2cfee1ea5
Author: Joel Fernandes <joelagnelf@nvidia.com>

rust: sync: completion: add wait_for_completion_timeout()

This commit adds wait_for_completion_timeout() to the Rust sync completion
primitives. It provides a way to wait for a completion with a specified
timeout in jiffies, preventing indefinite stalls in drivers.

> diff --git a/rust/kernel/sync/completion.rs b/rust/kernel/sync/completion.rs
> --- a/rust/kernel/sync/completion.rs
> +++ b/rust/kernel/sync/completion.rs
[ ... ]
> @@ -111,4 +116,20 @@ pub fn wait_for_completion(&self) {
>          // SAFETY: `self.as_raw()` is a pointer to a valid `struct completion`.
>          unsafe { bindings::wait_for_completion(self.as_raw()) };
>      }
> +
> +    /// Wait for completion of a task, with a timeout.
[ ... ]
> +    #[inline]
> +    pub fn wait_for_completion_timeout(&self, timeout: Jiffies) -> Option<Jiffies> {
> +        // SAFETY: `self.as_raw()` is a pointer to a valid `struct completion`.
> +        match unsafe { bindings::wait_for_completion_timeout(self.as_raw(), timeout) } {

[Severity: Medium]
Does this code overflow the timeout parameter if large values are provided?

The timeout parameter is passed directly to the C API without bounds checking.
Because C implicitly casts it to a signed long downstream, values greater than
LONG_MAX can lead to an immediate unhandled timeout and a kernel stack dump.

For example, passing Jiffies::MAX causes the unsigned timeout to overflow into
a negative long inside the C wait_for_common() and schedule_timeout()
functions. This triggers a kernel stack dump (printk(KERN_ERR ...);
dump_stack();) and causes the function to return immediately without waiting,
violating the safe function's contract.

Could this be clamped to MAX_SCHEDULE_TIMEOUT to prevent unexpected behavior
from excessively large timeouts?

> +            0 => None,
> +            remaining => Some(remaining),
> +        }
> +    }
>  }

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260930034148.590687-1-jhubbard@nvidia.com?part=2

  reply	other threads:[~2026-09-30  3:59 UTC|newest]

Thread overview: 33+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-30  3:41 [PATCH v5 00/15] nova-core: GPU interrupt support and GSP event delivery John Hubbard
2026-09-30  3:41 ` [PATCH v5 01/15] rust: pci: declare IrqType and IrqTypes with impl_flags John Hubbard
2026-10-01 14:06   ` Alexandre Courbot
2026-09-30  3:41 ` [PATCH v5 02/15] rust: sync: completion: add wait_for_completion_timeout() John Hubbard
2026-09-30  3:59   ` sashiko-bot [this message]
2026-10-01 14:06   ` Alexandre Courbot
2026-10-02  8:21   ` Alice Ryhl
2026-10-02  9:11     ` John Hubbard
2026-10-02  9:50   ` Gary Guo
2026-10-02 10:55     ` Alexandre Courbot
2026-10-02 11:13       ` John Hubbard
2026-10-02 12:12         ` Alexandre Courbot
2026-10-02 13:01           ` Gary Guo
2026-10-02 12:20       ` Danilo Krummrich
2026-09-30  3:41 ` [PATCH v5 03/15] gpu: nova-core: add the GIN vector, leaf and subtree types John Hubbard
2026-09-30  3:41 ` [PATCH v5 04/15] gpu: nova-core: add the GIN CPU interrupt tree and MSI EOI registers John Hubbard
2026-09-30  3:41 ` [PATCH v5 05/15] gpu: nova-core: add the per-architecture GIN CPU interrupt HAL John Hubbard
2026-09-30  3:41 ` [PATCH v5 06/15] gpu: nova-core: add the GIN interrupt tree and allocate its vectors John Hubbard
2026-09-30  3:41 ` [PATCH v5 07/15] gpu: nova-core: wait for GFW boot in probe, not in the Gpu constructor John Hubbard
2026-09-30 12:51   ` Danilo Krummrich
2026-10-01 14:07     ` Alexandre Courbot
2026-09-30  3:41 ` [PATCH v5 08/15] gpu: nova-core: add an interrupt delivery self-test John Hubbard
2026-09-30  3:41 ` [PATCH v5 09/15] gpu: nova-core: log GSP events instead of discarding them John Hubbard
2026-09-30  3:41 ` [PATCH v5 10/15] gpu: nova-core: return ENOMSG for an unmatched GSP message John Hubbard
2026-09-30  3:41 ` [PATCH v5 11/15] gpu: nova-core: bound a GSP wait by a single deadline John Hubbard
2026-09-30  3:41 ` [PATCH v5 12/15] gpu: nova-core: add the falcon interrupt registers and HAL methods John Hubbard
2026-09-30  3:41 ` [PATCH v5 13/15] gpu: nova-core: service GSP events from the SWGEN0 interrupt John Hubbard
2026-09-30  3:41 ` [PATCH v5 14/15] gpu: nova-core: add KUnit tests for the interrupt tree John Hubbard
2026-09-30  3:41 ` [PATCH v5 15/15] gpu: nova-core: document the GIN interrupt controller and GSP events John Hubbard
2026-10-02 13:33   ` Alexandre Courbot
2026-10-01 14:09 ` [PATCH v5 00/15] nova-core: GPU interrupt support and GSP event delivery Danilo Krummrich
2026-10-01 14:10 ` Alexandre Courbot
2026-10-02 13:19 ` Alexandre Courbot

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260930035901.6E6F21F000FF@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=a.hindborg@kernel.org \
    --cc=acourbot@nvidia.com \
    --cc=airlied@gmail.com \
    --cc=alex.gaynor@gmail.com \
    --cc=aliceryhl@google.com \
    --cc=apopple@nvidia.com \
    --cc=bhelgaas@google.com \
    --cc=bjorn3_gh@protonmail.com \
    --cc=boqun.feng@gmail.com \
    --cc=dakr@kernel.org \
    --cc=ecourtney@nvidia.com \
    --cc=gary@garyguo.net \
    --cc=jhubbard@nvidia.com \
    --cc=joelagnelf@nvidia.com \
    --cc=linux-kernel@vger.kernel.org \
    --cc=lossin@kernel.org \
    --cc=nova-gpu@lists.linux.dev \
    --cc=ojeda@kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    --cc=simona@ffwll.ch \
    --cc=tmgross@umich.edu \
    --cc=ttabi@nvidia.com \
    --cc=zhiw@nvidia.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.