From: sashiko-bot@kernel.org
To: "Mayuresh Chitale" <mayuresh.chitale@oss.qualcomm.com>
Cc: devicetree@vger.kernel.org, robh@kernel.org, conor+dt@kernel.org
Subject: Re: [PATCH v6 05/14] gtrace: Add functions to start/stop tracing on a component path
Date: Thu, 01 Oct 2026 05:36:16 +0000 [thread overview]
Message-ID: <20261001053617.D21221F000FF@smtp.kernel.org> (raw)
In-Reply-To: <20261001052243.3042627-6-mayuresh.chitale@oss.qualcomm.com>
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [High] gtrace: UAF in comp_start/stop due to missing module/device locks
--
commit ed6a9060977521b7cc68908d59a7104ec2d2492f
Author: Mayuresh Chitale <mayuresh.chitale@oss.qualcomm.com>
gtrace: Add functions to start/stop tracing on a component path
The perf driver framework needs to be able to start / stop all components
in a trace component path during its operation. Add gtrace_path_start()
and gtrace_path_stop() functions for this purpose.
> diff --git a/drivers/hwtracing/gtrace/gtrace-core.c b/drivers/hwtracing/gtrace/gtrace-core.c
> index f750025104ec9..d7f1df90aa31d 100644
> --- a/drivers/hwtracing/gtrace/gtrace-core.c
> +++ b/drivers/hwtracing/gtrace/gtrace-core.c
[ ... ]
> @@ -611,6 +621,100 @@ static void gtrace_release_path_nodes(struct gtrace_path *path)
> }
> }
>
> +static int __gtrace_comp_start(struct gtrace_component *comp, pid_t owner)
> +{
> + struct gtrace_comp_priv *cpriv = to_gtrace_comp_priv(comp);
> + const struct gtrace_driver *gtdrv = to_gtrace_driver(comp->dev.driver);
> + unsigned long flags;
> + int ret = 0;
> +
> + if (!gtdrv)
> + return -ENODEV;
> +
> + raw_spin_lock_irqsave(&cpriv->lock, flags);
[Severity: High]
Does this lockless driver check create a race with device unbind?
If a privileged user writes to a component's sysfs unbind file or unloads
its module while perf tracing is active, the driver core calls gtrace_remove()
and sets comp->dev.driver to NULL.
If __gtrace_comp_start() is concurrently called from perf_event_start() in
IRQ context, it could fetch the driver pointer here locklessly just before
it is cleared.
> + if (cpriv->start_count) {
> + if (cpriv->owner != owner) {
> + ret = -EBUSY;
> + goto out;
> + }
> + } else {
> + if (gtdrv->start) {
> + ret = gtdrv->start(comp);
[Severity: High]
Could this result in a use-after-free or a panic?
If the race described above occurs, the cached gtdrv pointer might now
point to a freed structure or unmapped driver text, causing a panic when
this callback is invoked inside the lock.
> + if (ret)
> + goto out;
> + }
> + cpriv->owner = owner;
> + }
> +
> + cpriv->start_count++;
> +out:
> + raw_spin_unlock_irqrestore(&cpriv->lock, flags);
> + return ret;
> +}
> +
> +static int __gtrace_comp_stop(struct gtrace_component *comp)
> +{
> + struct gtrace_comp_priv *cpriv = to_gtrace_comp_priv(comp);
> + const struct gtrace_driver *gtdrv = to_gtrace_driver(comp->dev.driver);
> + unsigned long flags;
> + int ret = 0;
> +
> + raw_spin_lock_irqsave(&cpriv->lock, flags);
[Severity: High]
Does this have the same race as __gtrace_comp_start()?
The driver pointer is cached locklessly here as well, exposing the stop
callback to a race with driver removal.
> + if (!cpriv->start_count) {
> + ret = -EINVAL;
> + goto out;
> + }
> +
> + cpriv->start_count--;
> + if (!cpriv->start_count) {
> + if (!gtdrv) {
> + ret = -ENODEV;
> + goto out;
> + }
> +
> + if (gtdrv->stop)
> + ret = gtdrv->stop(comp);
[Severity: High]
Could this trigger a use-after-free during the stop path?
If the driver has been removed and the structure freed, calling this
potentially freed stop callback could crash the kernel.
> + }
> +out:
> + raw_spin_unlock_irqrestore(&cpriv->lock, flags);
> + return ret;
> +}
--
Sashiko AI review · https://sashiko.dev/#/patchset/20261001052243.3042627-1-mayuresh.chitale@oss.qualcomm.com?part=5
next prev parent reply other threads:[~2026-10-01 5:36 UTC|newest]
Thread overview: 25+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-10-01 5:22 [PATCH v6 00/14] Linux RISC-V trace framework and drivers Mayuresh Chitale
2026-10-01 5:22 ` [PATCH v6 01/14] dt-bindings: Add RISC-V trace component bindings Mayuresh Chitale
2026-10-01 5:33 ` sashiko-bot
2026-10-01 5:22 ` [PATCH v6 02/14] hwtracing: gtrace: Initial implementation of gtrace framework Mayuresh Chitale
2026-10-01 5:37 ` sashiko-bot
2026-10-01 5:22 ` [PATCH v6 03/14] gtrace: Add RISC-V platform driver for the " Mayuresh Chitale
2026-10-01 5:36 ` sashiko-bot
2026-10-01 5:22 ` [PATCH v6 04/14] gtrace: Add functions to create/destroy a trace component path Mayuresh Chitale
2026-10-01 5:36 ` sashiko-bot
2026-10-01 5:22 ` [PATCH v6 05/14] gtrace: Add functions to start/stop tracing on a " Mayuresh Chitale
2026-10-01 5:36 ` sashiko-bot [this message]
2026-10-01 5:22 ` [PATCH v6 06/14] gtrace: Add RISC-V Trace encoder driver Mayuresh Chitale
2026-10-01 5:34 ` sashiko-bot
2026-10-01 5:22 ` [PATCH v6 07/14] gtrace: Add function to copy into perf AUX buffer Mayuresh Chitale
2026-10-01 5:40 ` sashiko-bot
2026-10-01 5:22 ` [PATCH v6 08/14] perf: Add gtrace AUX buffer trace format type Mayuresh Chitale
2026-10-01 5:22 ` [PATCH v6 09/14] gtrace: Add RISC-V Trace ramsink driver Mayuresh Chitale
2026-10-01 5:42 ` sashiko-bot
2026-10-01 5:22 ` [PATCH v6 10/14] riscv: Enable DMA_RESTRICTED_POOL in defconfig Mayuresh Chitale
2026-10-01 5:22 ` [PATCH v6 11/14] gtrace: Add perf driver for tracing using perf tool Mayuresh Chitale
2026-10-01 5:44 ` sashiko-bot
2026-10-01 5:22 ` [PATCH v6 12/14] perf tools: Add RISC-V trace PMU record capabilities Mayuresh Chitale
2026-10-01 5:22 ` [PATCH v6 13/14] perf tools: Initial support for gtrace decoder Mayuresh Chitale
2026-10-01 5:35 ` sashiko-bot
2026-10-01 5:22 ` [PATCH v6 14/14] MAINTAINERS: Add entry for RISC-V trace framework Mayuresh Chitale
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20261001053617.D21221F000FF@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=conor+dt@kernel.org \
--cc=devicetree@vger.kernel.org \
--cc=mayuresh.chitale@oss.qualcomm.com \
--cc=robh@kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox