dri-devel Archive on lore.kernel.org
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Jim Cromie" <jim.cromie@gmail.com>
Cc: dri-devel@lists.freedesktop.org, linux-modules@vger.kernel.org
Subject: Re: [PATCH v11 32/38] dyndbg: resolve "protection" of class'd pr_debug
Date: Wed, 23 Sep 2026 22:53:17 +0000	[thread overview]
Message-ID: <20260923225318.68FA81F000FF@smtp.kernel.org> (raw)
In-Reply-To: <20260923-dd-cmap-part2-clean-v11-32-9b6c217fdf2f@gmail.com>

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [Medium] dyndbg: race during module load bypasses ABI protection permanently
--

commit c8a052c030fff7b63aa2d9e4c2dc3aa455948704
Author: Jim Cromie <jim.cromie@gmail.com>

dyndbg: resolve "protection" of class'd pr_debug

This patch implements an ABI protection mechanism for dynamically debugged
classes by binding a controlling sysfs parameter to classmaps. If a module
parameter is configured, it protects class'd callsites from being
accidentally modified by un-classed wildcard queries.

> diff --git a/lib/dynamic_debug.c b/lib/dynamic_debug.c
> index 636a88994a774..d300d44c1a82e 100644
> --- a/lib/dynamic_debug.c
> +++ b/lib/dynamic_debug.c

[ ... ]

> @@ -252,7 +294,28 @@ static bool ddebug_match_desc(const struct ddebug_query *query,
>  	    dp->lineno > query->last_lineno)
>  		return false;
>  
> -	return true;
> +	/*
> +	 * above are all satisfied, so we can make final decisions:
> +	 * 1- class FOO or implied class __DEFAULT__
> +	 * 2- site.is_classed or not
> +	 */
> +	if (query->class_string) {
> +		/* class FOO given, exact match required */
> +		return (dp->class_id == selected_class);
> +	}
> +	/* query class __DEFAULT__ by omission. */
> +	if (dp->class_id == _DPRINTK_CLASS_DFLT) {
> +		/* un-classed site */
> +		return true;
> +	}
> +	/* site is class'd */
> +	site_map = ddebug_find_map_by_class_id(di, dp->class_id);
> +	if (!site_map) {
> +		WARN_ONCE(1, "unknown class_id %d, check %s's CLASSMAP definitions", dp->class_id, di->mod_name);
> +		return false;
> +	}
> +	/* module(-param) decides protection */
> +	return !ddebug_class_wants_protection(site_map);
>  }

[Severity: Medium]
Does this code expose a race condition when a module is loading?

Looking at ddebug_add_module(), the module is added to ddebug_tables and the
ddebug_lock is dropped before map->controlling_param is initialized:

lib/dynamic_debug.c:ddebug_add_module() {
	...
	mutex_lock(&ddebug_lock);
	list_add_tail(&dt->link, &ddebug_tables);
	mutex_unlock(&ddebug_lock);

	if (dt->info.maps.len)
		ddebug_apply_class_maps(&dt->info);
	...
}

If a concurrent wildcard query (like echo -p > /proc/dynamic_debug/control)
is processed while the lock is dropped but before ddebug_apply_class_maps()
finishes binding the parameter, site_map->controlling_param will be NULL.

This causes ddebug_class_wants_protection() to return false, bypassing the
protection and erroneously enabling the callsites.

[ ... ]

> @@ -772,11 +833,14 @@ static int param_set_dyndbg_module_classes(const char *instr,
>  					   const struct kernel_param *kp,
>  					   const char *mod_name)
>  {
> -	const struct ddebug_class_param *dcp = kp->arg;
> -	const struct ddebug_class_map *map = dcp->map;
> +	struct ddebug_class_param *dcp = kp->arg;
> +	struct ddebug_class_map *map = dcp->map;
>  	u32 inrep, new_bits, old_bits, old_val;
>  	int rc, totct = 0;
>  
> +	if (map && !map->controlling_param)
> +		map->controlling_param = dcp;

[Severity: Medium]
Is it safe to assign map->controlling_param here without holding
ddebug_lock or using WRITE_ONCE()?

Since this shared state is accessed by concurrent queries, could this
cause a data race?

[ ... ]

> @@ -1332,25 +1395,40 @@ static void ddebug_sync_classbits(const struct kernel_param *kp, const char *mod
>  	}
>  }
>  
> -static void ddebug_match_apply_kparam(const struct kernel_param *kp,
> -				      const struct ddebug_class_map *map,
> -				      const char *mod_name)
> +static struct ddebug_class_param *
> +ddebug_get_classmap_kparam(const struct kernel_param *kp,
> +			   const struct ddebug_class_map *map)
> +{
> +	struct ddebug_class_param *dcp;
> +
> +	if (kp->ops != &param_ops_dyndbg_classes)
> +		return NULL;
> +
> +	dcp = (struct ddebug_class_param *)kp->arg;
> +	return (map == dcp->map)
> +		? dcp : (struct ddebug_class_param *)NULL;
> +}
> +
> +static void ddebug_match_apply_kparam(const struct kernel_param *kp,
> +				      struct ddebug_class_map *map,
> +				      const char *mod_name)
>  {
> +	struct ddebug_class_param *dcp = ddebug_get_classmap_kparam(kp, map);
>  
>  	if (dcp && dcp->map == map) {
> +		/*
> +		 * Bind controlling_param to activate ABI protection in
> +		 * ddebug_match_desc(), shielding callsites from non-class
> +		 * wildcard (>control) queries.
> +		 */
> +		map->controlling_param = dcp;
>  		v2pr_info(" kp:%s.%s =0x%x", mod_name, kp->name, *dcp->bits);
>  		vpr_cm_info(map, " %s maps ", mod_name);
>  		ddebug_sync_classbits(kp, mod_name);
>  	}
>  }

[Severity: Medium]
Can the delayed assignment of map->controlling_param combined with
ddebug_sync_classbits() result in permanent desynchronization?

During the race window in ddebug_add_module() mentioned above, callsites
can be erroneously enabled by a concurrent query. Once the module loading
thread resumes, it binds map->controlling_param here and calls
ddebug_sync_classbits().

However, ddebug_sync_classbits() passes 0 for old_bits:

lib/dynamic_debug.c:ddebug_sync_classbits() {
	...
	case DD_CLASS_TYPE_DISJOINT_BITS:
		val = READ_ONCE(*dcp->bits);
		new_bits = val;
		v2pr_info("  %s: classbits: 0x%x\n", KP_NAME(kp), new_bits);
		ddebug_apply_class_bitmap(dcp, &new_bits, 0, modname);
	...
}

Because old_bits is 0, the function skips resetting any class bits that are
supposed to be off (since it sees new_bits (0) == old_bits (0)). Doesn't this
prevent the synchronizer from noticing and clearing the erroneously enabled
callsites?

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260923-dd-cmap-part2-clean-v11-0-9b6c217fdf2f@gmail.com?part=32

  reply	other threads:[~2026-09-23 22:53 UTC|newest]

Thread overview: 58+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-23 22:34 [PATCH v11 00/38] dyndbg: Fix classmaps API for subsystems, query extensions, selftests Jim Cromie
2026-09-23 22:34 ` [PATCH v11 01/38] selftests/dyndbg: Add kselftest script to verify dynamic-debug Jim Cromie
2026-09-23 22:34 ` [PATCH v11 02/38] vmlinux.lds.h: refactor BOUNDED_SECTION_* macros into bounded_sections.lds.h Jim Cromie
2026-09-23 22:34 ` [PATCH v11 03/38] vmlinux.lds.h: drop unused HEADERED_SECTION* macros Jim Cromie
2026-09-23 22:34 ` [PATCH v11 04/38] vmlinux.lds.h: Fix ALIGN(8) omission causing NULL ptr on i386 Jim Cromie
2026-09-23 22:34 ` [PATCH v11 05/38] vmlinux.lds.h: remove redundant ALIGN(8) directives Jim Cromie
2026-09-23 22:34 ` [PATCH v11 06/38] dyndbg.lds.S: fix lost dyndbg sections in modules Jim Cromie
2026-09-23 22:34 ` [PATCH v11 07/38] dyndbg: factor ddebug_match_desc out from ddebug_change Jim Cromie
2026-09-23 22:34 ` [PATCH v11 08/38] dyndbg: add stub macro for DECLARE_DYNDBG_CLASSMAP Jim Cromie
2026-09-23 22:34 ` [PATCH v11 09/38] dyndbg: reword "class unknown," to "class:_UNKNOWN_" Jim Cromie
2026-09-23 22:34 ` [PATCH v11 10/38] dyndbg-API: remove DD_CLASS_TYPE_(DISJOINT|LEVEL)_NAMES and code Jim Cromie
2026-09-23 22:34 ` [PATCH v11 11/38] dyndbg: drop NUM_TYPE_ARGS Jim Cromie
2026-09-23 22:34 ` [PATCH v11 12/38] dyndbg: bump num-tokens in a query-cmd from 9 to 15 Jim Cromie
2026-09-23 22:34 ` [PATCH v11 13/38] dyndbg: reduce verbose/debug clutter Jim Cromie
2026-09-23 22:34 ` [PATCH v11 14/38] dyndbg: Bind callsites and classmaps to DDEBUG_MODNAME Jim Cromie
2026-09-23 22:45   ` sashiko-bot
2026-10-01 22:15     ` jim.cromie
2026-09-23 22:34 ` [PATCH v11 15/38] dyndbg: refactor param_set_dyndbg_classes and below Jim Cromie
2026-09-23 22:34 ` [PATCH v11 16/38] dyndbg: tighten fn-sig of ddebug_apply_class_bitmap Jim Cromie
2026-09-23 22:34 ` [PATCH v11 17/38] dyndbg: replace classmap list with an array-slice Jim Cromie
2026-09-23 22:47   ` sashiko-bot
2026-10-01 20:48     ` jim.cromie
2026-09-23 22:34 ` [PATCH v11 18/38] dyndbg: macrofy a 2-index for-loop pattern Jim Cromie
2026-09-23 22:34 ` [PATCH v11 19/38] dyndbg: reduce class param storage to u32 Jim Cromie
2026-09-23 22:34 ` [PATCH v11 20/38] dyndbg,module: make proper substructs in _ddebug_info Jim Cromie
2026-09-25  9:28   ` Petr Pavlu
2026-09-23 22:34 ` [PATCH v11 21/38] dyndbg: move mod_name down from struct ddebug_table to _ddebug_info Jim Cromie
2026-09-23 22:34 ` [PATCH v11 22/38] dyndbg: hoist classmap-filter-by-modname up to ddebug_add_module Jim Cromie
2026-09-23 22:34 ` [PATCH v11 23/38] dyndbg-API: replace DECLARE_DYNDBG_CLASSMAP Jim Cromie
2026-09-23 22:49   ` sashiko-bot
2026-10-01 22:53     ` jim.cromie
2026-09-23 22:34 ` [PATCH v11 24/38] selftests/dyndbg: Enable FT_classmap_inheritance Jim Cromie
2026-09-23 22:45   ` sashiko-bot
2026-10-01 23:24     ` jim.cromie
2026-09-23 22:34 ` [PATCH v11 25/38] dyndbg: detect class_id reservation conflicts Jim Cromie
2026-09-23 22:34 ` [PATCH v11 26/38] dyndbg: check DYNAMIC_DEBUG_CLASSMAP_{DEFINE,USE_} args at compile-time Jim Cromie
2026-09-23 22:34 ` [PATCH v11 27/38] dyndbg-test: add do_bulk testpoint, rename do_prints to do_classes Jim Cromie
2026-09-23 22:34 ` [PATCH v11 28/38] dyndbg-API: promote DYNAMIC_DEBUG_CLASSMAP_PARAM to API Jim Cromie
2026-09-23 22:34 ` [PATCH v11 29/38] dyndbg: control-parser: treat comma as a token separator Jim Cromie
2026-09-23 22:46   ` sashiko-bot
2026-10-01 22:02     ` jim.cromie
2026-09-23 22:34 ` [PATCH v11 30/38] selftests: enable comma-terminator tests Jim Cromie
2026-09-23 22:34 ` [PATCH v11 31/38] dyndbg: split multi-query strings with @ Jim Cromie
2026-09-23 22:47   ` sashiko-bot
2026-10-01 22:07     ` jim.cromie
2026-09-23 22:34 ` [PATCH v11 32/38] dyndbg: resolve "protection" of class'd pr_debug Jim Cromie
2026-09-23 22:53   ` sashiko-bot [this message]
2026-10-01 21:48     ` jim.cromie
2026-09-23 22:34 ` [PATCH v11 33/38] dyndbg: harden classmap and descriptor validation Jim Cromie
2026-09-23 22:34 ` [PATCH v11 34/38] docs/dyndbg: add classmap info to howto Jim Cromie
2026-09-23 22:34 ` [PATCH v11 35/38] dyndbg: Ignore additional arguments from pr_fmt Jim Cromie
2026-09-23 22:35 ` [PATCH v11 36/38] dyndbg: add epilogue to dynamic_debug/control file Jim Cromie
2026-09-23 22:35 ` [PATCH v11 37/38] dyndbg: add +c flag to count pr_debug calls without printing Jim Cromie
2026-09-23 22:52   ` sashiko-bot
2026-10-01 21:53     ` jim.cromie
2026-09-23 22:35 ` [PATCH v11 38/38] dyndbg: add DEBUG-biased fallback stubs for _dynamic_func_call_cls Jim Cromie
2026-09-23 22:53 ` [PATCH v11 00/38] dyndbg: Fix classmaps API for subsystems, query extensions, selftests Andrew Morton
2026-09-25 20:30   ` jim.cromie

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260923225318.68FA81F000FF@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=dri-devel@lists.freedesktop.org \
    --cc=jim.cromie@gmail.com \
    --cc=linux-modules@vger.kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox