From: sashiko-bot@kernel.org
To: "Mayuresh Chitale" <mayuresh.chitale@oss.qualcomm.com>
Cc: conor+dt@kernel.org, robh@kernel.org, devicetree@vger.kernel.org
Subject: Re: [PATCH v5 07/14] gtrace: Add function to copy into perf AUX buffer
Date: Mon, 10 Aug 2026 15:42:15 +0000 [thread overview]
Message-ID: <20260810154215.89AA01F0155D@smtp.kernel.org> (raw)
In-Reply-To: <20260810152223.3946743-8-mayuresh.chitale@oss.qualcomm.com>
Thank you for your contribution! Sashiko AI review found 2 potential issue(s) to consider:
- [High] The newly added `gtrace_path_copyto_auxbuf` function dereferences `gtdrv` without a NULL check, leading to a kernel panic if the component's driver is unbound.
- [High] Lack of module pinning or device locking in `gtrace_path_copyto_auxbuf` allows concurrent driver unbind or module unloading, leading to a Use-After-Free and kernel panic.
--
--- Patch [7]: [PATCH v5 07/14] gtrace: Add function to copy into perf AUX buffer ---
commit 175afd4c59c793de1c5fef3899d7379cf730bece
Author: Anup Patel <anup.patel@oss.qualcomm.com>
gtrace: Add function to copy into perf AUX buffer
This commit adds gtrace_path_copyto_auxbuf() and a new driver callback
copyto_auxbuf to allow the RISC-V trace ramsink to copy trace data into a
perf AUX buffer.
> diff --git a/drivers/hwtracing/gtrace/gtrace-core.c b/drivers/hwtracing/gtrace/gtrace-core.c
> index 6ff1b30879472..53a3679ba69fa 100644
> --- a/drivers/hwtracing/gtrace/gtrace-core.c
> +++ b/drivers/hwtracing/gtrace/gtrace-core.c
> @@ -626,6 +626,28 @@ int gtrace_path_stop(struct gtrace_path *path)
> }
> EXPORT_SYMBOL_GPL(gtrace_path_stop);
>
> +int gtrace_path_copyto_auxbuf(struct gtrace_path *path,
> + struct gtrace_perf_auxbuf *buf,
> + size_t *bytes_copied, u64 *format)
> +{
> + const struct gtrace_driver *gtdrv;
> + struct gtrace_component *comp;
> + struct gtrace_path_node *node;
> +
> + list_for_each_entry(node, &path->comp_list, head) {
> + comp = node->comp;
> + gtdrv = to_gtrace_driver(comp->dev.driver);
> + if (!gtdrv->copyto_auxbuf)
[Severity: High]
Does this sequence risk a null pointer dereference if a component's driver is
unbound?
If a driver is dynamically unbound via sysfs while the perf session is active,
comp->dev.driver becomes null. The to_gtrace_driver() macro will then return
null, causing the evaluation of gtdrv->copyto_auxbuf to panic.
> + continue;
> +
> + *bytes_copied = gtdrv->copyto_auxbuf(comp, buf, format);
[Severity: High]
Can this indirect function call race with a concurrent module unload?
If the component's module is unloaded immediately after the driver pointer is
checked but before the callback executes, jumping to gtdrv->copyto_auxbuf()
could execute freed memory.
Could this be prevented by holding a module reference (try_module_get()) or
taking the device lock (device_lock()) while reading the driver structure and
executing the callback?
> + return 0;
> + }
> +
> + return -EOPNOTSUPP;
> +}
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260810152223.3946743-1-mayuresh.chitale@oss.qualcomm.com?part=7
next prev parent reply other threads:[~2026-08-10 15:42 UTC|newest]
Thread overview: 27+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-10 15:22 [PATCH v5 00/14] Linux RISC-V trace framework and drivers Mayuresh Chitale
2026-08-10 15:22 ` [PATCH v5 01/14] dt-bindings: Add RISC-V trace component bindings Mayuresh Chitale
2026-08-10 15:33 ` sashiko-bot
2026-08-10 15:22 ` [PATCH v5 02/14] hwtracing: gtrace: Initial implementation of gtrace framework Mayuresh Chitale
2026-08-10 15:36 ` sashiko-bot
2026-08-10 15:22 ` [PATCH v5 03/14] gtrace: Add RISC-V platform driver for the " Mayuresh Chitale
2026-08-10 15:38 ` sashiko-bot
2026-08-10 15:22 ` [PATCH v5 04/14] gtrace: Add functions to create/destroy a trace component path Mayuresh Chitale
2026-08-10 15:34 ` sashiko-bot
2026-08-10 15:22 ` [PATCH v5 05/14] gtrace: Add functions to start/stop tracing on a " Mayuresh Chitale
2026-08-10 15:33 ` sashiko-bot
2026-08-10 15:22 ` [PATCH v5 06/14] gtrace: Add RISC-V Trace encoder driver Mayuresh Chitale
2026-08-10 15:40 ` sashiko-bot
2026-08-10 15:22 ` [PATCH v5 07/14] gtrace: Add function to copy into perf AUX buffer Mayuresh Chitale
2026-08-10 15:42 ` sashiko-bot [this message]
2026-08-10 15:22 ` [PATCH v5 08/14] perf: Add gtrace AUX buffer trace format type Mayuresh Chitale
2026-08-10 15:37 ` sashiko-bot
2026-08-10 15:22 ` [PATCH v5 09/14] gtrace: Add RISC-V Trace ramsink driver Mayuresh Chitale
2026-08-10 15:47 ` sashiko-bot
2026-08-10 15:22 ` [PATCH v5 10/14] riscv: Enable DMA_RESTRICTED_POOL in defconfig Mayuresh Chitale
2026-08-10 15:22 ` [PATCH v5 11/14] gtrace: Add perf driver for tracing using perf tool Mayuresh Chitale
2026-08-10 15:48 ` sashiko-bot
2026-08-10 15:22 ` [PATCH v5 12/14] perf tools: Add RISC-V trace PMU record capabilities Mayuresh Chitale
2026-08-10 15:55 ` sashiko-bot
2026-08-10 15:22 ` [PATCH v5 13/14] perf tools: Initial support for gtrace decoder Mayuresh Chitale
2026-08-10 15:51 ` sashiko-bot
2026-08-10 15:22 ` [PATCH v5 14/14] MAINTAINERS: Add entry for RISC-V trace framework Mayuresh Chitale
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260810154215.89AA01F0155D@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=conor+dt@kernel.org \
--cc=devicetree@vger.kernel.org \
--cc=mayuresh.chitale@oss.qualcomm.com \
--cc=robh@kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox