From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id F067236E466 for ; Thu, 1 Oct 2026 05:42:17 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790833339; cv=none; b=EyXfPL2AUpDIYkV2tw9qLx8yP2oxx18h/ht1EhC8fLxYEAGM1MVSi7FAEFiJsLhSzMw3D/PJVfmFpC6AQ/iHFXlxSmyAuvrUZgTysb83fU6I5HPsIxD9GL5w+zZHWPQEj1utSgxFIBbmX65eH6zFLJ1l/2O6h0snHzrM3yqh9wA= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790833339; c=relaxed/simple; bh=/ep0j2ArAOb7+WDonbUmcpEfI8QYtUd7j4OCqVQW8gI=; h=From:Subject:To:Cc:In-Reply-To:References:Content-Type:Date: Message-Id; b=TJ+LzoKmNDGZEAyuyOtn8B5ehpZHWKxiLWhvIRLcLAVc/dwJmyABD/F88ADMwnK6UxXNGR5+9HE8ejv4m0syGYUFnIA/T0zig2Wf5I3p8uv6jTyHbBbrMnw+E2PdhmZraPrL+mt3CxHRkEDnYTpf9QcCzgag/PZ3ZHxrpJXwkgk= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=ow7YJZj/; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="ow7YJZj/" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 6250F1F000FF; Thu, 1 Oct 2026 05:42:17 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=kernel.org; s=k20260515; t=1790833337; bh=gCCW1EAUFDunloTrPpmWw1dHTloIhv0+UpCaTLiI/Zc=; h=From:Subject:Reply-To:To:Cc:In-Reply-To:References:Date; b=ow7YJZj/FINL+24495G317/vNhEcdJ6tQl6Drkgr2cgh0yib/dDl0VF2H2WLAlRxE 1FlFl5GHUBENXjx8EpOqh+IcTpKcgobWyjrenEzn3gVCXYwjtsDHolEeZVX2Q1G/7E kbd1GgCwKN+Q/Yr4uIH0IK+D+RJyKpu5qLFf4rI1WvZmzzcdEg48gvahhqlj3GtL5e vIv0A5lpnC8gFk/xmzqJBajrA7v4s9EHKxcJrMIzlRStgsqrBbC2g19CS2WDuF4FfD 6GGt3by6dUCJjvJ5dlq/zbZz+iwfh0UtVs8e8hVeTg23kbA1zxnh4qNRu/HySkp9Au wH7BTyXkCNdDg== From: sashiko-bot@kernel.org Subject: Re: [PATCH v6 09/14] gtrace: Add RISC-V Trace ramsink driver Reply-To: sashiko-reviews@lists.linux.dev To: "Mayuresh Chitale" Cc: robh@kernel.org, conor+dt@kernel.org, devicetree@vger.kernel.org In-Reply-To: <20261001052243.3042627-10-mayuresh.chitale@oss.qualcomm.com> References: <20261001052243.3042627-1-mayuresh.chitale@oss.qualcomm.com> <20261001052243.3042627-10-mayuresh.chitale@oss.qualcomm.com> Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: quoted-printable Date: Thu, 01 Oct 2026 05:42:16 +0000 Message-Id: <20261001054217.6250F1F000FF@smtp.kernel.org> Precedence: bulk X-Mailing-List: devicetree@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Thank you for your contribution! Sashiko AI review found 2 potential issue(= s) to consider: - [High] gtrace: DMA use-after-free on driver unbind while tracing - [Medium] gtrace: out-of-bounds read if hardware write pointer exceeds lim= it -- commit 727d829afd136c7c3871f88297ecd560269b3dbd Author: Mayuresh Chitale gtrace: Add RISC-V Trace ramsink driver This commit adds the initial implementation of the RISC-V E-Trace ramsink driver. The ramsink stores trace data generated by upstream components into a system memory buffer. > diff --git a/drivers/hwtracing/gtrace/rvtrace-ramsink.c b/drivers/hwtraci= ng/gtrace/rvtrace-ramsink.c > new file mode 100644 > index 0000000000000..67b6779aaceec > --- /dev/null > +++ b/drivers/hwtracing/gtrace/rvtrace-ramsink.c [ ... ] > +static size_t rvtrace_ramsink_copyto_auxbuf(struct gtrace_component *com= p, > + struct gtrace_perf_auxbuf *buf, > + u64 *format) > +{ > + struct rvtrace_ramsink_priv *priv =3D dev_get_drvdata(&comp->dev); > + struct trace_buf src, dst; > + size_t bytes =3D 0; > + bool wrap; > + u64 wp; > + > + dst.base =3D buf->base; > + dst.len =3D buf->length; > + dst.cur =3D buf->pos; > + src.base =3D priv->va; > + src.len =3D priv->size; > + *format =3D PERF_AUX_FLAG_GTRACE_FORMAT_ETRACE; > + wp =3D rvtrace_ramsink_read_pair(comp->pdata, RVTRACE_RAMSINK_WPLOW_OFF= ); > + wrap =3D wp & RVTRACE_RAMSINK_WPLOW_WRAP; > + wp &=3D ~RVTRACE_RAMSINK_WPLOW_WRAP; > + > + if (wrap) { > + rvtrace_ramsink_write_pair(comp->pdata, priv->start, RVTRACE_RAMSINK_W= PLOW_OFF); > + src.cur =3D wp - priv->start; > + priv->prev_wp =3D priv->start; > + /* > + * There is no way to tell if trRamWp wrapped around more than once. A= s a > + * result priv->prev_wp can't be used and the entire buffer must be co= pied > + * even though some data might be duplicated. > + */ > + bytes =3D priv->size; > + } else { > + src.cur =3D priv->prev_wp - priv->start; > + bytes =3D wp - priv->prev_wp; > + priv->prev_wp =3D wp; > + } [Severity: Medium] Does this code safely handle anomalous hardware behavior? If the hardware write pointer (wp) read directly from RVTRACE_RAMSINK_WPLOW_OFF exceeds the configured priv->end limit, it seems src.cur could underflow or exceed the buffer length (priv->size). Without bounds checking on the offset returned by hardware, could this cause the subsequent memcpy in tbuf_to_pbuf_copy to read out-of-bounds kernel memory and leak it into the userspace perf ring buffer? > + > + tbuf_to_pbuf_copy(&src, &dst, bytes); > + dev_dbg(&comp->dev, "Copied %zu bytes\n", bytes); > + return bytes; > +} [ ... ] > +static void rvtrace_ramsink_cleanup(struct gtrace_component *comp) > +{ > + struct rvtrace_ramsink_priv *priv =3D dev_get_drvdata(&comp->dev); > + > + dma_free_coherent(comp->pdata->dev, priv->alloc_size, priv->alloc_va, p= riv->alloc_start); > +} [ ... ] > +static void rvtrace_ramsink_remove(struct gtrace_component *comp) > +{ > + rvtrace_ramsink_cleanup(comp); > +} [Severity: High] Can unbinding this driver while tracing is active lead to a DMA use-after-free? rvtrace_ramsink_remove calls rvtrace_ramsink_cleanup which immediately frees the DMA memory via dma_free_coherent. If the hardware isn't explicitly halted via gtrace_disable_component first, the hardware might continue writing trace data to the freed memory pages. --=20 Sashiko AI review =C2=B7 https://sashiko.dev/#/patchset/20261001052243.3042= 627-1-mayuresh.chitale@oss.qualcomm.com?part=3D9