From: Sebastian Andrzej Siewior <bigeasy@linutronix.de>
To: Sebastian Brzezinka <sebastian.brzezinka@intel.com>
Cc: intel-gfx@lists.freedesktop.org,
Jani Nikula <jani.nikula@linux.intel.com>,
Joonas Lahtinen <joonas.lahtinen@linux.intel.com>,
Rodrigo Vivi <rodrigo.vivi@intel.com>,
Tvrtko Ursulin <tursulin@ursulin.net>
Subject: Re: [PATCH] drm/i915: Use %p for pointer formatting
Date: Fri, 18 Sep 2026 14:36:35 +0200 [thread overview]
Message-ID: <20260918123635.aEFLyRcK@linutronix.de> (raw)
In-Reply-To: <DLIFC0Y2I5M0.2322C84W8AYDB@intel.com>
On 2026-09-18 14:00:15 [+0200], Sebastian Brzezinka wrote:
> Hi Sebastian,
Sebastian :)
> > --- a/drivers/gpu/drm/i915/i915_debugfs.c
> > +++ b/drivers/gpu/drm/i915/i915_debugfs.c
> > @@ -179,7 +179,7 @@ i915_debugfs_describe_obj(struct seq_file *m, struct drm_i915_gem_object *obj)
> > struct i915_vma *vma;
> > int pin_count = 0;
> >
> > - seq_printf(m, "%pK: %c%c%c %8zdKiB %02x %02x %s%s%s",
> > + seq_printf(m, "%p: %c%c%c %8zdKiB %02x %02x %s%s%s",
> Please, correct me if I'm wrong, but i915_debugfs_describe_obj()
> prints into a debugfs file read by userspace exactly the case where
> Documentation/core-api/printk-formats.rst recommends %pK over %p.
I should probably get rid of this, too.
So we do have %p and %pK by now and both return hashed pointer unless
overridden. K can have a security policy which can only work in a user
context. There is a different override switch which does not make things
easier. The vast majority of users are gone.
> >If (and only if) you are printing addresses as a content of a virtual file in
> >e.g. procfs or sysfs (using e.g. seq_printf(), not printk()) read by a
> >userspace process, use the %pK modifier described below instead of %p or %px.
>
> And it was addedby 2563a4524feb, which explicitly wants to
> guard it with kptr_restrict(i mean that it's intentionally stronger).
Please look at the timeline:
pre v3.9-rc4, %p prints the bare pointer
v3.9-rc4 2563a4524febe ("drm/i915: restrict kernel address leak in debugfs")
(%p -> %pK the leak in i915/debugfs is closed, %p still prints the bare
pointer).
v4.15-rc2 ad67b74d2469d ("printk: hash addresses printed with %p")
now %p does not leak the pointer, too.
Sebastian
next prev parent reply other threads:[~2026-09-18 12:36 UTC|newest]
Thread overview: 9+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-18 10:37 [PATCH] drm/i915: Use %p for pointer formatting Sebastian Andrzej Siewior
2026-09-18 12:00 ` Sebastian Brzezinka
2026-09-18 12:36 ` Sebastian Andrzej Siewior [this message]
2026-09-18 12:18 ` ✗ i915.CI.BAT: failure for " Patchwork
2026-09-18 12:44 ` Sebastian Andrzej Siewior
2026-09-29 23:40 ` Andi Shyti
2026-09-30 0:22 ` ✓ i915.CI.BAT: success for drm/i915: Use %p for pointer formatting (rev2) Patchwork
2026-09-30 12:33 ` ✗ i915.CI.Full: failure " Patchwork
2026-09-30 16:18 ` [PATCH] drm/i915: Use %p for pointer formatting Andi Shyti
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260918123635.aEFLyRcK@linutronix.de \
--to=bigeasy@linutronix.de \
--cc=intel-gfx@lists.freedesktop.org \
--cc=jani.nikula@linux.intel.com \
--cc=joonas.lahtinen@linux.intel.com \
--cc=rodrigo.vivi@intel.com \
--cc=sebastian.brzezinka@intel.com \
--cc=tursulin@ursulin.net \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox