From: sashiko-bot@kernel.org
To: "Jim Cromie" <jim.cromie@gmail.com>
Cc: linux-modules@vger.kernel.org, dri-devel@lists.freedesktop.org
Subject: Re: [PATCH v9 33/39] dyndbg: resolve "protection" of class'd pr_debug
Date: Wed, 09 Sep 2026 01:17:21 +0000 [thread overview]
Message-ID: <20260909011721.BBC081F00A3A@smtp.kernel.org> (raw)
In-Reply-To: <20260908-dd-cmap-part2-clean-v9-33-3a3f621f4a10@gmail.com>
Thank you for your contribution! Sashiko AI review found 2 potential issue(s) to consider:
- [High] The function `ddebug_apply_class_maps` is enclosed in an `#if 0` block, preventing `controlling_param` from being initialized for defining modules. This breaks the protection mechanism for parameterized classmaps and fails to apply boot/load-time kernel parameters to the defining module's callsites.
- [Medium] The module is exposed to userspace queries via `ddebug_tables` before its `map->controlling_param` protection state is initialized, creating a data race and TOCTOU vulnerability where concurrent classless queries can bypass protection.
--
commit 3a846cbf484a221d77612af005e27faf83c306df
Author: Jim Cromie <jim.cromie@gmail.com>
dyndbg: resolve "protection" of class'd pr_debug
This commit adds protection for dynamically debugged classes against
class-less queries by using sysfs parameters. It sets a controlling
parameter for parameterized classmaps to prevent accidental modification
from queries that lack a specific class identifier.
> diff --git a/lib/dynamic_debug.c b/lib/dynamic_debug.c
> index e6f5a524d63b6..8c90b1e4cd33e 100644
> --- a/lib/dynamic_debug.c
> +++ b/lib/dynamic_debug.c
[ ... ]
> @@ -1297,25 +1358,35 @@ static void ddebug_sync_classbits(const struct kernel_param *kp, const char *mod
> }
> }
>
> -static void ddebug_match_apply_kparam(const struct kernel_param *kp,
> - const struct ddebug_class_map *map,
> - const char *mod_name)
> +static struct ddebug_class_param *
> +ddebug_get_classmap_kparam(const struct kernel_param *kp,
> + const struct ddebug_class_map *map)
> {
> struct ddebug_class_param *dcp;
>
> if (kp->ops != ¶m_ops_dyndbg_classes)
> - return;
> + return NULL;
>
> dcp = (struct ddebug_class_param *)kp->arg;
> + return (map == dcp->map)
> + ? dcp : (struct ddebug_class_param *)NULL;
> +}
> +
> +static void ddebug_match_apply_kparam(const struct kernel_param *kp,
> + struct ddebug_class_map *map,
> + const char *mod_name)
> +{
> + struct ddebug_class_param *dcp = ddebug_get_classmap_kparam(kp, map);
>
> if (dcp && dcp->map == map) {
> + map->controlling_param = dcp;
[Severity: Medium]
Could this lockless write to map->controlling_param cause a data race?
When a module is loaded, ddebug_add_module() adds the module to the
ddebug_tables list under the ddebug_lock:
mutex_lock(&ddebug_lock);
list_add_tail(&dt->link, &ddebug_tables);
mutex_unlock(&ddebug_lock);
It then drops the lock and calls ddebug_apply_class_users(), which reaches
this code and locklessly writes to map->controlling_param.
Since the module is already visible in ddebug_tables before this
initialization completes, could a concurrent classless sysfs query bypass
protection by evaluating ddebug_class_wants_protection() on a newly added
module before controlling_param is set?
> + v2pr_info(" kp:%s.%s =0x%x", mod_name, kp->name, *dcp->bits);
> + vpr_cm_info(map, " %s maps ", mod_name);
> + ddebug_sync_classbits(kp, mod_name);
> }
> }
[ ... ]
> @@ -1338,6 +1409,26 @@ static void ddebug_apply_params(const struct ddebug_class_map *cm, const char *m
> }
> }
>
> +#if 0
> +/*
> + * called from add_module, ie early. it can find controlling kparams,
> + * which can/does? enable protection of this classmap from class-less
> + * queries, on the grounds that the user created the kparam, means to
> + * use it, and expects it to reflect reality. We should oblige him,
> + * and protect those classmaps from classless "-p" changes.
> + */
> +static void ddebug_apply_class_maps(const struct _ddebug_info *di)
> +{
> + struct ddebug_class_map *cm;
> + int i;
> +
> + for_subvec(i, cm, di, maps)
> + ddebug_apply_params(cm, cm->mod_name);
> +
> + v2pr_di_info(di, "attached %d class-maps to ", i);
> +}
> +#endif
[Severity: High]
Does this disabled code block break the intended protection for parameterized
classmaps defined within the module?
Because ddebug_apply_class_maps() is enclosed in an #if 0 block, the
controlling_param is never initialized for the module defining the classmap.
As a result, ddebug_class_wants_protection() will evaluate to false because
site_map->controlling_param is NULL.
Will this cause boot and load-time kernel parameters (like drm.debug=VAL)
to not be applied to the defining module's callsites, allowing class-less
queries to improperly modify them?
> +
> static void ddebug_apply_class_users(const struct _ddebug_info *di)
> {
> struct ddebug_class_user *cli;
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260908-dd-cmap-part2-clean-v9-0-3a3f621f4a10@gmail.com?part=33
next prev parent reply other threads:[~2026-09-09 1:17 UTC|newest]
Thread overview: 56+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-09 0:54 [PATCH v9 00/39] dyndbg: fix classmaps API for subsystems, query extensions, and selftests Jim Cromie via B4 Relay
2026-09-09 0:54 ` [PATCH v9 01/39] selftests/dyndbg: Add kselftest script to verify dynamic-debug Jim Cromie via B4 Relay
2026-09-09 0:54 ` [PATCH v9 02/39] vmlinux.lds.h: refactor BOUNDED_SECTION_* macros into bounded_sections.lds.h Jim Cromie via B4 Relay
2026-09-09 0:54 ` [PATCH v9 03/39] vmlinux.lds.h: drop unused HEADERED_SECTION* macros Jim Cromie via B4 Relay
2026-09-09 0:55 ` [PATCH v9 04/39] vmlinux.lds.h: Fix ALIGN(8) omission causing NULL ptr on i386 Jim Cromie via B4 Relay
2026-09-09 0:55 ` [PATCH v9 05/39] vmlinux.lds.h: remove redundant ALIGN(8) directives Jim Cromie via B4 Relay
2026-09-09 0:55 ` [PATCH v9 06/39] dyndbg.lds.S: fix lost dyndbg sections in modules Jim Cromie via B4 Relay
2026-09-09 0:55 ` [PATCH v9 07/39] dyndbg: factor ddebug_match_desc out from ddebug_change Jim Cromie via B4 Relay
2026-09-09 1:03 ` sashiko-bot
2026-09-09 0:55 ` [PATCH v9 08/39] dyndbg: add stub macro for DECLARE_DYNDBG_CLASSMAP Jim Cromie via B4 Relay
2026-09-09 1:10 ` sashiko-bot
2026-09-09 0:55 ` [PATCH v9 09/39] dyndbg: reword "class unknown," to "class:_UNKNOWN_" Jim Cromie via B4 Relay
2026-09-09 0:55 ` [PATCH v9 10/39] dyndbg-API: remove DD_CLASS_TYPE_(DISJOINT|LEVEL)_NAMES and code Jim Cromie via B4 Relay
2026-09-09 0:55 ` [PATCH v9 11/39] dyndbg: drop NUM_TYPE_ARGS Jim Cromie via B4 Relay
2026-09-09 0:55 ` [PATCH v9 12/39] dyndbg: bump num-tokens in a query-cmd from 9 to 15 Jim Cromie via B4 Relay
2026-09-09 0:55 ` [PATCH v9 13/39] dyndbg: reduce verbose/debug clutter Jim Cromie via B4 Relay
2026-09-09 0:55 ` [PATCH v9 14/39] lib/parser: add match_wildcard_hyphen() for agnostic matching Jim Cromie via B4 Relay
2026-09-09 0:55 ` [PATCH v9 15/39] kbuild, dyndbg: Clean up builtin module-name ambiguities Jim Cromie via B4 Relay
2026-09-09 15:50 ` Nicolas Schier
2026-09-11 18:20 ` jim.cromie
2026-09-09 0:55 ` [PATCH v9 16/39] dyndbg: refactor param_set_dyndbg_classes and below Jim Cromie via B4 Relay
2026-09-09 0:55 ` [PATCH v9 17/39] dyndbg: tighten fn-sig of ddebug_apply_class_bitmap Jim Cromie via B4 Relay
2026-09-09 0:55 ` [PATCH v9 18/39] dyndbg: replace classmap list with an array-slice Jim Cromie via B4 Relay
2026-09-09 0:55 ` [PATCH v9 19/39] dyndbg: macrofy a 2-index for-loop pattern Jim Cromie via B4 Relay
2026-09-09 0:55 ` [PATCH v9 20/39] dyndbg: reduce class param storage to u32 Jim Cromie via B4 Relay
2026-09-09 0:55 ` [PATCH v9 21/39] dyndbg,module: make proper substructs in _ddebug_info Jim Cromie via B4 Relay
2026-09-09 0:55 ` [PATCH v9 22/39] dyndbg: move mod_name down from struct ddebug_table to _ddebug_info Jim Cromie via B4 Relay
2026-09-09 0:55 ` [PATCH v9 23/39] dyndbg: hoist classmap-filter-by-modname up to ddebug_add_module Jim Cromie via B4 Relay
2026-09-09 0:55 ` [PATCH v9 24/39] dyndbg-API: replace DECLARE_DYNDBG_CLASSMAP Jim Cromie via B4 Relay
2026-09-09 1:13 ` sashiko-bot
2026-09-09 20:56 ` jim.cromie
2026-09-09 0:55 ` [PATCH v9 25/39] selftests/dyndbg: enable FT_classmap_inheritance Jim Cromie via B4 Relay
2026-09-09 0:55 ` [PATCH v9 26/39] dyndbg: detect class_id reservation conflicts Jim Cromie via B4 Relay
2026-09-09 0:55 ` [PATCH v9 27/39] dyndbg: check DYNAMIC_DEBUG_CLASSMAP_{DEFINE,USE_} args at compile-time Jim Cromie via B4 Relay
2026-09-09 1:07 ` sashiko-bot
2026-09-09 0:55 ` [PATCH v9 28/39] dyndbg-test: add do_bulk testpoint, rename do_prints to do_classes Jim Cromie via B4 Relay
2026-09-09 1:08 ` sashiko-bot
2026-09-09 0:55 ` [PATCH v9 29/39] dyndbg-API: promote DYNAMIC_DEBUG_CLASSMAP_PARAM to API Jim Cromie via B4 Relay
2026-09-09 1:08 ` sashiko-bot
2026-09-09 0:55 ` [PATCH v9 30/39] dyndbg: control-parser: treat comma as a token separator Jim Cromie via B4 Relay
2026-09-09 0:55 ` [PATCH v9 31/39] selftests: enable comma-terminator tests Jim Cromie via B4 Relay
2026-09-09 0:55 ` [PATCH v9 32/39] dyndbg: split multi-query strings with @ Jim Cromie via B4 Relay
2026-09-09 1:06 ` sashiko-bot
2026-09-09 0:55 ` [PATCH v9 33/39] dyndbg: resolve "protection" of class'd pr_debug Jim Cromie via B4 Relay
2026-09-09 1:17 ` sashiko-bot [this message]
2026-09-09 0:55 ` [PATCH v9 34/39] dyndbg: harden classmap and descriptor validation Jim Cromie via B4 Relay
2026-09-09 1:13 ` sashiko-bot
2026-09-09 0:55 ` [PATCH v9 35/39] docs/dyndbg: add classmap info to howto Jim Cromie via B4 Relay
2026-09-09 0:55 ` [PATCH v9 36/39] dyndbg: Ignore additional arguments from pr_fmt Jim Cromie via B4 Relay
2026-09-09 1:14 ` sashiko-bot
2026-09-09 0:55 ` [PATCH v9 37/39] dyndbg: add epilogue to dynamic_debug/control file Jim Cromie via B4 Relay
2026-09-09 1:09 ` sashiko-bot
2026-09-09 0:55 ` [PATCH v9 38/39] dyndbg: add +c flag to count advantage of classmaps for DRM Jim Cromie via B4 Relay
2026-09-09 1:11 ` sashiko-bot
2026-09-09 0:55 ` [PATCH v9 39/39] dyndbg: add DEBUG-biased fallback stubs for _dynamic_func_call_cls Jim Cromie via B4 Relay
2026-09-09 1:12 ` sashiko-bot
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260909011721.BBC081F00A3A@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=dri-devel@lists.freedesktop.org \
--cc=jim.cromie@gmail.com \
--cc=linux-modules@vger.kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox