From: Cristian Marussi <cristian.marussi@arm.com>
To: Fayssal Benmlih <Fayssal.Benmlih@arm.com>
Cc: Cristian Marussi <Cristian.Marussi@arm.com>,
"arm-scmi@vger.kernel.org" <arm-scmi@vger.kernel.org>,
"d-gole@ti.com" <d-gole@ti.com>,
"david@kernel.org" <david@kernel.org>,
Elif Topuz <Elif.Topuz@arm.com>,
"etienne.carriere@st.com" <etienne.carriere@st.com>,
"f.fainelli@gmail.com" <f.fainelli@gmail.com>,
"james.quinlan@broadcom.com" <james.quinlan@broadcom.com>,
"jic23@kernel.org" <jic23@kernel.org>,
"kas@kernel.org" <kas@kernel.org>,
"kernel-team@meta.com" <kernel-team@meta.com>,
"leitao@kernel.org" <leitao@kernel.org>,
"linux-arm-kernel@lists.infradead.org"
<linux-arm-kernel@lists.infradead.org>,
"linux-doc@vger.kernel.org" <linux-doc@vger.kernel.org>,
"linux-kernel@vger.kernel.org" <linux-kernel@vger.kernel.org>,
Lukasz Luba <Lukasz.Luba@arm.com>,
"michal.simek@amd.com" <michal.simek@amd.com>,
"peng.fan@oss.nxp.com" <peng.fan@oss.nxp.com>,
Philip Radford <Philip.Radford@arm.com>,
"puranjay@kernel.org" <puranjay@kernel.org>,
Souvik Chakravarty <Souvik.Chakravarty@arm.com>,
"sudeep.holla@kernel.org" <sudeep.holla@kernel.org>,
"usama.arif@linux.dev" <usama.arif@linux.dev>,
"vincent.guittot@linaro.org" <vincent.guittot@linaro.org>
Subject: Re: [PATCH v7 06/23] firmware: arm_scmi: Add basic Telemetry support
Date: Mon, 10 Aug 2026 14:39:44 +0100 [thread overview]
Message-ID: <annUoAwdtF4unA7q@pluto> (raw)
In-Reply-To: <AFD5A4D3-916E-4989-9F38-F23E7A2BED0B@contoso.com>
On Mon, Aug 03, 2026 at 11:53:11PM +0100, Fayssal Benmlih wrote:
> Hi Cristian,
>
Hi,
> I found a few error-path consistency issues inline.
>
> > tde->de.tstamp_support = !!tde->ts_type;
> > /* Count timestamped DEs */
> > ti->num_des_tstamp += !!tde->de.tstamp_support;
> > tde->de.fc_support = IS_FC_SUPPORTED(desc);
> > tde->de.name_support = IS_NAME_SUPPORTED(desc);
> > [...]
> > if (rx_len < payld_sz)
> > return -ENOSPC;
>
> num_des_tstamp is incremented before all variable parts of the descriptor
> and the optional fast-channel mapping have been validated.
>
> If a later validation or ioremap operation fails, the descriptor is
> rejected but the timestamp count is not rolled back. GET_ALL state checks
> can then compare against an inflated timestamp count.
>
> Please update this counter only after the complete descriptor has been
> validated and successfully registered, or undo it on every later failure.
Fixed in V8.
>
> > err:
> > /* DE not enumerated at this point were created in this call */
> > if (discovered)
> > scmi_telemetry_free_tde_put(ti, tde);
> >
> > return ret;
>
> At this point descriptor parsing may already have changed fields in tde and
> its associated scmi_telemetry_de_info. The object is returned to the free
> list without resetting that partial state.
>
> Can the descriptor be fully reset before it is made available for reuse,
> or can parsing be done into temporary state that is committed only after
> all validation succeeds?
Fixed in V8 by clearing the tde descriptor on put.
>
> > for (int i = 0; i < ti->info.base.num_groups; i++) {
> > struct scmi_telemetry_group *grp = &rinfo->grps[i];
> > [...]
> > grp->des = no_free_ptr(des);
> > grp->des_str = no_free_ptr(des_str);
> > /* Reset group DE counter */
> > grp->info->num_des = 0;
> > }
> > [...]
> > rinfo->num_groups = ti->info.base.num_groups;
>
> The per-group allocations are transferred out of automatic cleanup during
> the loop, but rinfo->num_groups is only assigned after every group
> succeeds.
Fixed in v8.
>
> If allocation for a later group fails, resources_free() calls
> scmi_telemetry_groups_free(), which iterates rinfo->num_groups. Since that
> is still zero, allocations already installed in earlier groups are leaked.
>
> Please increment a cleanup-visible group count as each group is committed,
> or make cleanup iterate base.num_groups and safely free NULL members.
>
Added also a rollback logic in V8 (which needs a small further fix in V9
apparently listening to Sashiuko complains....)
Thanks,
Cristian
next prev parent reply other threads:[~2026-08-10 13:40 UTC|newest]
Thread overview: 37+ messages / expand[flat|nested] mbox.gz Atom feed top
[not found] <<20260802145618.1952804-7-cristian.marussi@arm.com>
2026-08-03 22:53 ` [PATCH v7 06/23] firmware: arm_scmi: Add basic Telemetry support Fayssal Benmlih
2026-08-10 13:39 ` Cristian Marussi [this message]
[not found] <<20260802145618.1952804-9-cristian.marussi@arm.com>
2026-08-03 22:54 ` [PATCH v7 08/23] firmware: arm_scmi: Add Telemetry configuration operations Fayssal Benmlih
2026-08-10 14:13 ` Cristian Marussi
[not found] <<20260802145618.1952804-8-cristian.marussi@arm.com>
2026-08-03 22:53 ` [PATCH v7 07/23] firmware: arm_scmi: Add support to parse SHMTIs areas Fayssal Benmlih
2026-08-10 14:06 ` Cristian Marussi
[not found] <<20260802145618.1952804-4-cristian.marussi@arm.com>
2026-08-03 22:52 ` [PATCH v7 03/23] firmware: arm_scmi: Introduce protocol instance notifiers Fayssal Benmlih
2026-08-10 13:35 ` Cristian Marussi
[not found] <<20260802145618.1952804-20-cristian.marussi@arm.com>
2026-08-03 22:25 ` [PATCH v7 19/23] uapi: Add ARM SCMI Telemetry definitions Fayssal Benmlih
2026-08-04 10:39 ` Cristian Marussi
2026-08-02 14:55 [PATCH v7 00/23] Introduce SCMI Telemetry support Cristian Marussi
2026-08-02 14:55 ` [PATCH v7 01/23] firmware: arm_scmi: Add new SCMIv4.0 error codes definitions Cristian Marussi
2026-08-02 14:55 ` [PATCH v7 02/23] firmware: arm_scmi: Allow registration of unknown-size events/reports Cristian Marussi
2026-08-02 14:55 ` [PATCH v7 03/23] firmware: arm_scmi: Introduce protocol instance notifiers Cristian Marussi
2026-08-02 14:55 ` [PATCH v7 04/23] dt-bindings: firmware: arm,scmi: Add support for telemetry protocol Cristian Marussi
2026-08-02 14:56 ` [PATCH v7 05/23] include: trace: Add Telemetry trace events Cristian Marussi
2026-08-02 14:56 ` [PATCH v7 06/23] firmware: arm_scmi: Add basic Telemetry support Cristian Marussi
2026-08-02 14:56 ` [PATCH v7 07/23] firmware: arm_scmi: Add support to parse SHMTIs areas Cristian Marussi
2026-08-02 14:56 ` [PATCH v7 08/23] firmware: arm_scmi: Add Telemetry configuration operations Cristian Marussi
2026-08-02 14:56 ` [PATCH v7 09/23] firmware: arm_scmi: Add Telemetry DataEvent read capabilities Cristian Marussi
2026-08-02 14:56 ` [PATCH v7 10/23] firmware: arm_scmi: Add support for Telemetry reset Cristian Marussi
2026-08-02 14:56 ` [PATCH v7 11/23] firmware: arm_scmi: Add Telemetry notification support Cristian Marussi
2026-08-02 14:56 ` [PATCH v7 12/23] firmware: arm_scmi: Add support for boot-on Telemetry Cristian Marussi
2026-08-02 14:56 ` [PATCH v7 13/23] firmware: arm-scmi: Add telemetry generic event support Cristian Marussi
2026-08-02 14:56 ` [PATCH v7 14/23] firmware: arm_scmi: Add Telemetry generation counter event Cristian Marussi
2026-08-02 14:56 ` [PATCH v7 15/23] firmware: arm_scmi: Add common per-protocol debugfs support Cristian Marussi
2026-08-02 14:56 ` [PATCH v7 16/23] firmware: arm_scmi: Add Telemetry debugfs SHMTI dump support Cristian Marussi
2026-08-02 14:56 ` [PATCH v7 17/23] firmware: arm_scmi: Add Telemetry debugfs ABI documentation Cristian Marussi
2026-08-02 14:56 ` [PATCH v7 18/23] firmware: arm_scmi: Expose per-instance identifier Cristian Marussi
2026-08-02 14:56 ` [PATCH v7 19/23] uapi: Add ARM SCMI Telemetry definitions Cristian Marussi
2026-08-02 14:56 ` [PATCH v7 20/23] firmware: arm_scmi: Add System Telemetry driver Cristian Marussi
2026-08-02 14:56 ` [PATCH v7 21/23] docs: ioctl-number: Add SCMI Ioctls Cristian Marussi
2026-08-02 14:56 ` [PATCH v7 22/23] [RFC] Documentation: Add SCMI System Telemetry documentation Cristian Marussi
2026-08-02 14:56 ` [PATCH v7 23/23] [RFC] tools/scmi: Add SCMI Telemetry testing tool Cristian Marussi
2026-08-05 5:21 ` [PATCH v7 00/23] Introduce SCMI Telemetry support Subrahmanya Lingappa
2026-08-05 6:14 ` David Hildenbrand (Arm)
2026-08-05 11:06 ` Subrahmanya Lingappa
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=annUoAwdtF4unA7q@pluto \
--to=cristian.marussi@arm.com \
--cc=Elif.Topuz@arm.com \
--cc=Fayssal.Benmlih@arm.com \
--cc=Lukasz.Luba@arm.com \
--cc=Philip.Radford@arm.com \
--cc=Souvik.Chakravarty@arm.com \
--cc=arm-scmi@vger.kernel.org \
--cc=d-gole@ti.com \
--cc=david@kernel.org \
--cc=etienne.carriere@st.com \
--cc=f.fainelli@gmail.com \
--cc=james.quinlan@broadcom.com \
--cc=jic23@kernel.org \
--cc=kas@kernel.org \
--cc=kernel-team@meta.com \
--cc=leitao@kernel.org \
--cc=linux-arm-kernel@lists.infradead.org \
--cc=linux-doc@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=michal.simek@amd.com \
--cc=peng.fan@oss.nxp.com \
--cc=puranjay@kernel.org \
--cc=sudeep.holla@kernel.org \
--cc=usama.arif@linux.dev \
--cc=vincent.guittot@linaro.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox