From: sashiko-bot@kernel.org
To: "Jim Cromie" <jim.cromie@gmail.com>
Cc: dri-devel@lists.freedesktop.org, linux-modules@vger.kernel.org
Subject: Re: [PATCH v10 23/38] dyndbg-API: replace DECLARE_DYNDBG_CLASSMAP
Date: Wed, 16 Sep 2026 16:28:13 +0000 [thread overview]
Message-ID: <20260916162814.434551F000FF@smtp.kernel.org> (raw)
In-Reply-To: <20260916-dd-cmap-part2-clean-v10-23-af4cf4767707@gmail.com>
Thank you for your contribution! Sashiko AI review found 2 potential issue(s) to consider:
- [High] dyndbg: init_bits relies on _DPRINTK_FLAGS_DEFAULT evaluated in wrong translation unit
- [Medium] dyndbg: TOCTOU race in ddebug_sync_classbits() causes out-of-sync debug state
--
commit 3b29729057e8a4b4e0401fd7f3a74205f701c129
Author: Jim Cromie <jim.cromie@gmail.com>
dyndbg-API: replace DECLARE_DYNDBG_CLASSMAP
This commit replaces DECLARE_DYNDBG_CLASSMAP with an explicit client-server
model using DYNAMIC_DEBUG_CLASSMAP_DEFINE and DYNAMIC_DEBUG_CLASSMAP_USE.
At module load time, it resolves reference records and automatically applies
the initial bitmap to the module.
Cc: linux-doc@vger.kernel.org
> diff --git a/lib/dynamic_debug.c b/lib/dynamic_debug.c
> index 03dc35af4faa1..566c3860d7bfb 100644
> --- a/lib/dynamic_debug.c
> +++ b/lib/dynamic_debug.c
[ ... ]
> +static void ddebug_sync_classbits(const struct kernel_param *kp, const char *modname)
> +{
> + const struct ddebug_class_param *dcp = kp->arg;
> + u32 val, new_bits, init_bits;
> +
> + if (!dcp || !dcp->map)
> + return;
> +
> + init_bits = (_DPRINTK_FLAGS_DEFAULT & _DPRINTK_FLAGS_PRINT) ?
> + CLASSMAP_BITMASK(dcp->map->length) : 0;
[Severity: High]
Does this evaluate _DPRINTK_FLAGS_DEFAULT in the context of the dynamic
debug library rather than the target module's translation unit? Since
dynamic_debug.c is not compiled with -DDEBUG, init_bits will always be
evaluated as 0 here. Could this prevent the system from properly disabling
callsites for modules that are loaded and compiled with -DDEBUG?
> +
> + switch (dcp->map->map_type) {
> + case DD_CLASS_TYPE_DISJOINT_BITS:
> + val = READ_ONCE(*dcp->bits);
> + new_bits = val;
> + v2pr_info(" %s: classbits: 0x%x\n", KP_NAME(kp), new_bits);
> + ddebug_apply_class_bitmap(dcp, &new_bits, init_bits, modname);
> + break;
[ ... ]
> @@ -1238,12 +1410,17 @@ static int ddebug_add_module(struct _ddebug_info *di)
[ ... ]
> mutex_lock(&ddebug_lock);
> list_add_tail(&dt->link, &ddebug_tables);
> mutex_unlock(&ddebug_lock);
>
> - vpr_info("%3u debug prints in module %s\n", di->descs.len, di->mod_name);
> + if (dt->info.users.len)
> + ddebug_apply_class_users(&dt->info);
[Severity: Medium]
Could this introduce a time-of-check to time-of-use (TOCTOU) race condition
between module loading and concurrent sysfs updates?
Once ddebug_add_module() adds the module to ddebug_tables and drops the
ddebug_lock, it proceeds to call ddebug_apply_class_users() (which then
calls ddebug_sync_classbits()).
In ddebug_sync_classbits(), the parameter value is read via
READ_ONCE(*dcp->bits) without holding the lock. If a concurrent sysfs write
updates the parameter and applies it to all modules in ddebug_tables
(including this newly added one), could the module load thread subsequently
resume and apply the stale value it just read, leaving this module's debug
state out-of-sync with the global parameter?
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260916-dd-cmap-part2-clean-v10-0-af4cf4767707@gmail.com?part=23
next prev parent reply other threads:[~2026-09-16 16:28 UTC|newest]
Thread overview: 53+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-16 15:32 [PATCH v10 00/38] dyndbg: Fix classmaps API for subsystems, query extensions, selftests Jim Cromie via B4 Relay
2026-09-16 15:32 ` [PATCH v10 01/38] selftests/dyndbg: Add kselftest script to verify dynamic-debug Jim Cromie via B4 Relay
2026-09-16 15:41 ` sashiko-bot
2026-09-16 15:32 ` [PATCH v10 02/38] vmlinux.lds.h: refactor BOUNDED_SECTION_* macros into bounded_sections.lds.h Jim Cromie via B4 Relay
2026-09-16 15:32 ` [PATCH v10 03/38] vmlinux.lds.h: drop unused HEADERED_SECTION* macros Jim Cromie via B4 Relay
2026-09-16 15:32 ` [PATCH v10 04/38] vmlinux.lds.h: Fix ALIGN(8) omission causing NULL ptr on i386 Jim Cromie via B4 Relay
2026-09-16 15:32 ` [PATCH v10 05/38] vmlinux.lds.h: remove redundant ALIGN(8) directives Jim Cromie via B4 Relay
2026-09-16 15:32 ` [PATCH v10 06/38] dyndbg.lds.S: fix lost dyndbg sections in modules Jim Cromie via B4 Relay
2026-09-16 15:32 ` [PATCH v10 07/38] dyndbg: factor ddebug_match_desc out from ddebug_change Jim Cromie via B4 Relay
2026-09-16 15:47 ` sashiko-bot
2026-09-16 15:33 ` [PATCH v10 08/38] dyndbg: add stub macro for DECLARE_DYNDBG_CLASSMAP Jim Cromie via B4 Relay
2026-09-16 16:00 ` sashiko-bot
2026-09-16 22:42 ` jim.cromie
2026-09-16 15:33 ` [PATCH v10 09/38] dyndbg: reword "class unknown," to "class:_UNKNOWN_" Jim Cromie via B4 Relay
2026-09-16 15:33 ` [PATCH v10 10/38] dyndbg-API: remove DD_CLASS_TYPE_(DISJOINT|LEVEL)_NAMES and code Jim Cromie via B4 Relay
2026-09-16 15:33 ` [PATCH v10 11/38] dyndbg: drop NUM_TYPE_ARGS Jim Cromie via B4 Relay
2026-09-16 15:33 ` [PATCH v10 12/38] dyndbg: bump num-tokens in a query-cmd from 9 to 15 Jim Cromie via B4 Relay
2026-09-16 15:33 ` [PATCH v10 13/38] dyndbg: reduce verbose/debug clutter Jim Cromie via B4 Relay
2026-09-16 15:33 ` [PATCH v10 14/38] dyndbg: Bind callsites and classmaps to DDEBUG_MODNAME Jim Cromie via B4 Relay
2026-09-16 16:05 ` sashiko-bot
2026-09-16 15:33 ` [PATCH v10 15/38] dyndbg: refactor param_set_dyndbg_classes and below Jim Cromie via B4 Relay
2026-09-16 15:33 ` [PATCH v10 16/38] dyndbg: tighten fn-sig of ddebug_apply_class_bitmap Jim Cromie via B4 Relay
2026-09-16 15:33 ` [PATCH v10 17/38] dyndbg: replace classmap list with an array-slice Jim Cromie via B4 Relay
2026-09-16 15:33 ` [PATCH v10 18/38] dyndbg: macrofy a 2-index for-loop pattern Jim Cromie via B4 Relay
2026-09-16 15:33 ` [PATCH v10 19/38] dyndbg: reduce class param storage to u32 Jim Cromie via B4 Relay
2026-09-16 15:33 ` [PATCH v10 20/38] dyndbg,module: make proper substructs in _ddebug_info Jim Cromie via B4 Relay
2026-09-16 15:33 ` [PATCH v10 21/38] dyndbg: move mod_name down from struct ddebug_table to _ddebug_info Jim Cromie via B4 Relay
2026-09-16 15:33 ` [PATCH v10 22/38] dyndbg: hoist classmap-filter-by-modname up to ddebug_add_module Jim Cromie via B4 Relay
2026-09-16 15:33 ` [PATCH v10 23/38] dyndbg-API: replace DECLARE_DYNDBG_CLASSMAP Jim Cromie via B4 Relay
2026-09-16 16:28 ` sashiko-bot [this message]
2026-09-20 20:26 ` jim.cromie
2026-09-16 15:33 ` [PATCH v10 24/38] selftests/dyndbg: Enable FT_classmap_inheritance Jim Cromie via B4 Relay
2026-09-16 16:24 ` sashiko-bot
2026-09-20 17:14 ` jim.cromie
2026-09-20 17:25 ` jim.cromie
2026-09-16 15:33 ` [PATCH v10 25/38] dyndbg: detect class_id reservation conflicts Jim Cromie via B4 Relay
2026-09-16 16:30 ` sashiko-bot
2026-09-16 15:33 ` [PATCH v10 26/38] dyndbg: check DYNAMIC_DEBUG_CLASSMAP_{DEFINE,USE_} args at compile-time Jim Cromie via B4 Relay
2026-09-16 15:33 ` [PATCH v10 27/38] dyndbg-test: add do_bulk testpoint, rename do_prints to do_classes Jim Cromie via B4 Relay
2026-09-16 16:37 ` sashiko-bot
2026-09-16 15:33 ` [PATCH v10 28/38] dyndbg-API: promote DYNAMIC_DEBUG_CLASSMAP_PARAM to API Jim Cromie via B4 Relay
2026-09-16 16:40 ` sashiko-bot
2026-09-16 15:33 ` [PATCH v10 29/38] dyndbg: control-parser: treat comma as a token separator Jim Cromie via B4 Relay
2026-09-16 15:33 ` [PATCH v10 30/38] selftests: enable comma-terminator tests Jim Cromie via B4 Relay
2026-09-16 15:33 ` [PATCH v10 31/38] dyndbg: split multi-query strings with @ Jim Cromie via B4 Relay
2026-09-16 15:33 ` [PATCH v10 32/38] dyndbg: resolve "protection" of class'd pr_debug Jim Cromie via B4 Relay
2026-09-16 16:56 ` sashiko-bot
2026-09-16 15:33 ` [PATCH v10 33/38] dyndbg: harden classmap and descriptor validation Jim Cromie via B4 Relay
2026-09-16 15:33 ` [PATCH v10 34/38] docs/dyndbg: add classmap info to howto Jim Cromie via B4 Relay
2026-09-16 15:33 ` [PATCH v10 35/38] dyndbg: Ignore additional arguments from pr_fmt Jim Cromie via B4 Relay
2026-09-16 15:33 ` [PATCH v10 36/38] dyndbg: add epilogue to dynamic_debug/control file Jim Cromie via B4 Relay
2026-09-16 15:33 ` [PATCH v10 37/38] dyndbg: add +c flag to count advantage of classmaps for DRM Jim Cromie via B4 Relay
2026-09-16 15:33 ` [PATCH v10 38/38] dyndbg: add DEBUG-biased fallback stubs for _dynamic_func_call_cls Jim Cromie via B4 Relay
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260916162814.434551F000FF@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=dri-devel@lists.freedesktop.org \
--cc=jim.cromie@gmail.com \
--cc=linux-modules@vger.kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox