From: Lingyue <lingyue@xiaomi.com>
To: <catalin.marinas@arm.com>, <will@kernel.org>,
<mark.rutland@arm.com>, <dianders@chromium.org>,
<swboyd@chromium.org>, <frederic@kernel.org>,
<james.morse@arm.com>, <scott@os.amperecomputing.com>,
<linux-arm-kernel@lists.infradead.org>,
<linux-kernel@vger.kernel.org>
Cc: <huangshaobo3@xiaomi.com>, <huangjun7@xiaomi.com>,
Lingyue <lingyue@xiaomi.com>
Subject: [PATCH] arm64: smp: do not allocate CPU IDs to invalid CPU nodes
Date: Fri, 21 Jun 2024 15:50:45 +0800 [thread overview]
Message-ID: <20240621075045.249798-1-lingyue@xiaomi.com> (raw)
Many modules, such as arch topology, rely on num_possible_cpus() to
allocate memory and then access the allocated space using CPU IDs.
These modules assume that there are no gaps in cpu_possible_mask.
However, in of_parse_and_init_cpus(), CPU IDs are still allocated
for invalid CPU nodes, leading to gaps in cpu_possible_mask and
resulting in out-of-bounds memory access. So it is crucial to avoid
allocating CPU IDs to invalid CPU nodes.
This issue can be reproduced easily on QEMU with KASAN enabled, by
modifing reg property of a CPU node to 0xFFFFFFFF
[ 0.197756] BUG: KASAN: slab-out-of-bounds in topology_normalize_cpu_scale.part.0+0x2cc/0x34c
[ 0.199518] Read of size 4 at addr ffff000007ebe924 by task swapper/0/1
[ 0.200087]
[ 0.200739] CPU: 0 PID: 1 Comm: swapper/0 Not tainted 6.10.0-rc4 #3
[ 0.201647] Hardware name: linux,dummy-virt (DT)
[ 0.203067] Call trace:
[ 0.203404] dump_backtrace+0x90/0xe8
[ 0.203974] show_stack+0x18/0x24
[ 0.204424] dump_stack_lvl+0x78/0x90
[ 0.205090] print_report+0x114/0x5cc
[ 0.205908] kasan_report+0xa4/0xf0
[ 0.206488] __asan_report_load4_noabort+0x20/0x2c
[ 0.207427] topology_normalize_cpu_scale.part.0+0x2cc/0x34c
[ 0.208275] init_cpu_topology+0x254/0x430
[ 0.209518] smp_prepare_cpus+0x20/0x25c
[ 0.210824] kernel_init_freeable+0x1dc/0x4fc
[ 0.212047] kernel_init+0x24/0x1ec
[ 0.213143] ret_from_fork+0x10/0x20
Signed-off-by: Lingyue <lingyue@xiaomi.com>
---
arch/arm64/kernel/smp.c | 6 +++---
1 file changed, 3 insertions(+), 3 deletions(-)
diff --git a/arch/arm64/kernel/smp.c b/arch/arm64/kernel/smp.c
index 31c8b3094dd7..5b4178145920 100644
--- a/arch/arm64/kernel/smp.c
+++ b/arch/arm64/kernel/smp.c
@@ -638,12 +638,12 @@ static void __init of_parse_and_init_cpus(void)
u64 hwid = of_get_cpu_hwid(dn, 0);
if (hwid & ~MPIDR_HWID_BITMASK)
- goto next;
+ continue;
if (is_mpidr_duplicate(cpu_count, hwid)) {
pr_err("%pOF: duplicate cpu reg properties in the DT\n",
dn);
- goto next;
+ continue;
}
/*
@@ -656,7 +656,7 @@ static void __init of_parse_and_init_cpus(void)
if (bootcpu_valid) {
pr_err("%pOF: duplicate boot cpu reg property in DT\n",
dn);
- goto next;
+ continue;
}
bootcpu_valid = true;
--
2.34.1
next reply other threads:[~2024-06-21 7:52 UTC|newest]
Thread overview: 3+ messages / expand[flat|nested] mbox.gz Atom feed top
2024-06-21 7:50 Lingyue [this message]
2024-06-21 10:12 ` [PATCH] arm64: smp: do not allocate CPU IDs to invalid CPU nodes Mark Rutland
2024-06-22 8:31 ` Lingyue
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20240621075045.249798-1-lingyue@xiaomi.com \
--to=lingyue@xiaomi.com \
--cc=catalin.marinas@arm.com \
--cc=dianders@chromium.org \
--cc=frederic@kernel.org \
--cc=huangjun7@xiaomi.com \
--cc=huangshaobo3@xiaomi.com \
--cc=james.morse@arm.com \
--cc=linux-arm-kernel@lists.infradead.org \
--cc=linux-kernel@vger.kernel.org \
--cc=mark.rutland@arm.com \
--cc=scott@os.amperecomputing.com \
--cc=swboyd@chromium.org \
--cc=will@kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox