From: sashiko-bot@kernel.org
To: "Mayuresh Chitale" <mayuresh.chitale@oss.qualcomm.com>
Cc: robh@kernel.org, conor+dt@kernel.org, devicetree@vger.kernel.org
Subject: Re: [PATCH v6 09/14] gtrace: Add RISC-V Trace ramsink driver
Date: Thu, 01 Oct 2026 05:42:16 +0000 [thread overview]
Message-ID: <20261001054217.6250F1F000FF@smtp.kernel.org> (raw)
In-Reply-To: <20261001052243.3042627-10-mayuresh.chitale@oss.qualcomm.com>
Thank you for your contribution! Sashiko AI review found 2 potential issue(s) to consider:
- [High] gtrace: DMA use-after-free on driver unbind while tracing
- [Medium] gtrace: out-of-bounds read if hardware write pointer exceeds limit
--
commit 727d829afd136c7c3871f88297ecd560269b3dbd
Author: Mayuresh Chitale <mayuresh.chitale@oss.qualcomm.com>
gtrace: Add RISC-V Trace ramsink driver
This commit adds the initial implementation of the RISC-V E-Trace ramsink
driver. The ramsink stores trace data generated by upstream components into
a system memory buffer.
> diff --git a/drivers/hwtracing/gtrace/rvtrace-ramsink.c b/drivers/hwtracing/gtrace/rvtrace-ramsink.c
> new file mode 100644
> index 0000000000000..67b6779aaceec
> --- /dev/null
> +++ b/drivers/hwtracing/gtrace/rvtrace-ramsink.c
[ ... ]
> +static size_t rvtrace_ramsink_copyto_auxbuf(struct gtrace_component *comp,
> + struct gtrace_perf_auxbuf *buf,
> + u64 *format)
> +{
> + struct rvtrace_ramsink_priv *priv = dev_get_drvdata(&comp->dev);
> + struct trace_buf src, dst;
> + size_t bytes = 0;
> + bool wrap;
> + u64 wp;
> +
> + dst.base = buf->base;
> + dst.len = buf->length;
> + dst.cur = buf->pos;
> + src.base = priv->va;
> + src.len = priv->size;
> + *format = PERF_AUX_FLAG_GTRACE_FORMAT_ETRACE;
> + wp = rvtrace_ramsink_read_pair(comp->pdata, RVTRACE_RAMSINK_WPLOW_OFF);
> + wrap = wp & RVTRACE_RAMSINK_WPLOW_WRAP;
> + wp &= ~RVTRACE_RAMSINK_WPLOW_WRAP;
> +
> + if (wrap) {
> + rvtrace_ramsink_write_pair(comp->pdata, priv->start, RVTRACE_RAMSINK_WPLOW_OFF);
> + src.cur = wp - priv->start;
> + priv->prev_wp = priv->start;
> + /*
> + * There is no way to tell if trRamWp wrapped around more than once. As a
> + * result priv->prev_wp can't be used and the entire buffer must be copied
> + * even though some data might be duplicated.
> + */
> + bytes = priv->size;
> + } else {
> + src.cur = priv->prev_wp - priv->start;
> + bytes = wp - priv->prev_wp;
> + priv->prev_wp = wp;
> + }
[Severity: Medium]
Does this code safely handle anomalous hardware behavior? If the hardware
write pointer (wp) read directly from RVTRACE_RAMSINK_WPLOW_OFF exceeds the
configured priv->end limit, it seems src.cur could underflow or exceed the
buffer length (priv->size).
Without bounds checking on the offset returned by hardware, could this
cause the subsequent memcpy in tbuf_to_pbuf_copy to read out-of-bounds
kernel memory and leak it into the userspace perf ring buffer?
> +
> + tbuf_to_pbuf_copy(&src, &dst, bytes);
> + dev_dbg(&comp->dev, "Copied %zu bytes\n", bytes);
> + return bytes;
> +}
[ ... ]
> +static void rvtrace_ramsink_cleanup(struct gtrace_component *comp)
> +{
> + struct rvtrace_ramsink_priv *priv = dev_get_drvdata(&comp->dev);
> +
> + dma_free_coherent(comp->pdata->dev, priv->alloc_size, priv->alloc_va, priv->alloc_start);
> +}
[ ... ]
> +static void rvtrace_ramsink_remove(struct gtrace_component *comp)
> +{
> + rvtrace_ramsink_cleanup(comp);
> +}
[Severity: High]
Can unbinding this driver while tracing is active lead to a DMA
use-after-free?
rvtrace_ramsink_remove calls rvtrace_ramsink_cleanup which immediately
frees the DMA memory via dma_free_coherent. If the hardware isn't
explicitly halted via gtrace_disable_component first, the hardware might
continue writing trace data to the freed memory pages.
--
Sashiko AI review · https://sashiko.dev/#/patchset/20261001052243.3042627-1-mayuresh.chitale@oss.qualcomm.com?part=9
next prev parent reply other threads:[~2026-10-01 5:42 UTC|newest]
Thread overview: 25+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-10-01 5:22 [PATCH v6 00/14] Linux RISC-V trace framework and drivers Mayuresh Chitale
2026-10-01 5:22 ` [PATCH v6 01/14] dt-bindings: Add RISC-V trace component bindings Mayuresh Chitale
2026-10-01 5:33 ` sashiko-bot
2026-10-01 5:22 ` [PATCH v6 02/14] hwtracing: gtrace: Initial implementation of gtrace framework Mayuresh Chitale
2026-10-01 5:37 ` sashiko-bot
2026-10-01 5:22 ` [PATCH v6 03/14] gtrace: Add RISC-V platform driver for the " Mayuresh Chitale
2026-10-01 5:36 ` sashiko-bot
2026-10-01 5:22 ` [PATCH v6 04/14] gtrace: Add functions to create/destroy a trace component path Mayuresh Chitale
2026-10-01 5:36 ` sashiko-bot
2026-10-01 5:22 ` [PATCH v6 05/14] gtrace: Add functions to start/stop tracing on a " Mayuresh Chitale
2026-10-01 5:36 ` sashiko-bot
2026-10-01 5:22 ` [PATCH v6 06/14] gtrace: Add RISC-V Trace encoder driver Mayuresh Chitale
2026-10-01 5:34 ` sashiko-bot
2026-10-01 5:22 ` [PATCH v6 07/14] gtrace: Add function to copy into perf AUX buffer Mayuresh Chitale
2026-10-01 5:40 ` sashiko-bot
2026-10-01 5:22 ` [PATCH v6 08/14] perf: Add gtrace AUX buffer trace format type Mayuresh Chitale
2026-10-01 5:22 ` [PATCH v6 09/14] gtrace: Add RISC-V Trace ramsink driver Mayuresh Chitale
2026-10-01 5:42 ` sashiko-bot [this message]
2026-10-01 5:22 ` [PATCH v6 10/14] riscv: Enable DMA_RESTRICTED_POOL in defconfig Mayuresh Chitale
2026-10-01 5:22 ` [PATCH v6 11/14] gtrace: Add perf driver for tracing using perf tool Mayuresh Chitale
2026-10-01 5:44 ` sashiko-bot
2026-10-01 5:22 ` [PATCH v6 12/14] perf tools: Add RISC-V trace PMU record capabilities Mayuresh Chitale
2026-10-01 5:22 ` [PATCH v6 13/14] perf tools: Initial support for gtrace decoder Mayuresh Chitale
2026-10-01 5:35 ` sashiko-bot
2026-10-01 5:22 ` [PATCH v6 14/14] MAINTAINERS: Add entry for RISC-V trace framework Mayuresh Chitale
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20261001054217.6250F1F000FF@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=conor+dt@kernel.org \
--cc=devicetree@vger.kernel.org \
--cc=mayuresh.chitale@oss.qualcomm.com \
--cc=robh@kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox