Linux Modules
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Jim Cromie" <jim.cromie@gmail.com>
Cc: dri-devel@lists.freedesktop.org, linux-modules@vger.kernel.org
Subject: Re: [PATCH v7 28/29] dyndbg-API: replace DECLARE_DYNDBG_CLASSMAP
Date: Tue, 21 Jul 2026 21:18:13 +0000	[thread overview]
Message-ID: <20260721211814.01EBE1F000E9@smtp.kernel.org> (raw)
In-Reply-To: <20260721-dd-maint-2-v7-28-010fbe73b311@gmail.com>

Thank you for your contribution! Sashiko AI review found 5 potential issue(s) to consider:
- [High] ddebug_sync_classbits unconditionally treats LEVEL_NUM parameters as bitmasks, corrupting stored verbosity levels and incorrectly configuring callsites.
- [High] Incorrect arithmetic for used classmaps with offsets completely breaks class control and leads to out-of-bounds array reads.
- [High] Module classmap initialization silently fails because configuration queries are executed before the module is published to the global tracking list.
- [Medium] ddebug_match_apply_kparam fails to verify that the kernel parameter's class map matches the target map, applying all loaded dyndbg parameters indiscriminately.
- [Medium] Unprotected read-modify-write on shared classmap bits causes a data race during concurrent module loads or sysfs writes.
--

--- Patch [28]: [PATCH v7 28/29] dyndbg-API: replace DECLARE_DYNDBG_CLASSMAP ---
commit bd4f2adcad3c31e1b42bccb83f503513dbc0eb2e
Author: Jim Cromie <jim.cromie@gmail.com>
Subject: dyndbg-API: replace DECLARE_DYNDBG_CLASSMAP

This patch replaces DECLARE_DYNDBG_CLASSMAP with two new macros:
DYNAMIC_DEBUG_CLASSMAP_DEFINE and DYNAMIC_DEBUG_CLASSMAP_USE. It splits the
classmap declarations into definitions (exported by core) and uses (from
drivers) to solve initialization ordering issues and avoid duplicate classmap
allocations.

> --- a/lib/dynamic_debug.c
> +++ b/lib/dynamic_debug.c
[ ... ]
> @@ -160,20 +163,39 @@ static void v3pr_info_dq(const struct ddebug_query *query, const char *msg)
[ ... ]
>  static struct ddebug_class_map *ddebug_find_valid_class(struct _ddebug_info const *di,
>  							 const char *query_class,
>  							 int *class_id)
>  {
[ ... ]
> +	for_subvec(i, cli, di, users) {
> +		idx = match_string(cli->map->class_names, cli->map->length, query_class);
> +		if (idx >= 0) {
> +			v2pr_di_info(di, "class-ref: %s -> %s.%s ",
> +				    cli->mod_name, cli->map->mod_name, query_class);
> +			*class_id = idx + cli->map->base - cli->offset;

[Severity: High]
Should this subtract the offset? When a module uses a classmap with a non-zero
offset, subtracting it here instead of adding it appears to yield the wrong
class ID, breaking sysfs control ID mapping.

> +			return cli->map;
> +		}
> +	}
> +	*class_id = -ENOENT;
> +	return NULL;
>  }
[ ... ]
> @@ -1090,12 +1113,17 @@ static bool ddebug_class_in_range(const int class_id, const struct ddebug_class_
>  static const char *ddebug_class_name(struct _ddebug_info *di, struct _ddebug *dp)
>  {
>  	struct ddebug_class_map *map;
> +	struct ddebug_class_user *cli;
>  	int i;
>  
>  	for_subvec(i, map, di, maps)
>  		if (ddebug_class_in_range(dp->class_id, map))
>  			return map->class_names[dp->class_id - map->base];
>  
> +	for_subvec(i, cli, di, users)
> +		if (ddebug_class_in_range(dp->class_id, cli->map))
> +			return cli->map->class_names[dp->class_id - cli->map->base - cli->offset];

[Severity: High]
Does this compute a negative array index? If an unrelated callsite falls in
the unadjusted range checked by ddebug_class_in_range(), subtracting both
base and offset from dp->class_id could result in a negative index. This
could lead to an out-of-bounds read on cli->map->class_names.

> +
>  	return NULL;
>  }
[ ... ]
> @@ -1176,6 +1204,87 @@ static const struct proc_ops proc_fops = {
[ ... ]
> +static void ddebug_sync_classbits(const struct kernel_param *kp, const char *modname)
> +{
> +	const struct ddebug_class_param *dcp = kp->arg;
> +
> +	/* clamp initial bitvec, mask off hi-bits */
> +	if (*dcp->bits & ~CLASSMAP_BITMASK(dcp->map->length)) {
> +		*dcp->bits &= CLASSMAP_BITMASK(dcp->map->length);

[Severity: High]
Does this logic corrupt LEVEL_NUM classmaps? By unconditionally treating the
union field *dcp->bits as a bitmask, this overwrites the integer level stored
in *dcp->lvl for DD_CLASS_TYPE_LEVEL_NUM. Treating an integer level as a
bitmask seems to incorrectly enable disjoint classes and corrupt the stored
verbosity level.

[Severity: Medium]
Could this unprotected read-modify-write on *dcp->bits cause a data race?
Since this can execute during concurrent module loads or sysfs writes without
ddebug_lock, it looks like concurrent updates to the shared parent classmap
bitmask could be lost.

> +		v2pr_info("preset classbits: %x\n", *dcp->bits);
> +	}
> +	/* force class'd prdbgs (in USEr module) to match (DEFINEr module) class-param */
> +	ddebug_apply_class_bitmap(dcp, dcp->bits, ~0, modname);
> +	ddebug_apply_class_bitmap(dcp, dcp->bits, 0, modname);
> +}
> +
> +static void ddebug_match_apply_kparam(const struct kernel_param *kp,
> +				      const struct ddebug_class_map *map,
> +				      const char *mod_name)
> +{
> +	struct ddebug_class_param *dcp;
> +
> +	if (kp->ops != &param_ops_dyndbg_classes)
> +		return;
> +
> +	dcp = (struct ddebug_class_param *)kp->arg;
> +
> +	if (dcp) {
> +		v2pr_info(" kp:%s.%s =0x%x", mod_name, kp->name, *dcp->bits);
> +		vpr_cm_info(map, " %s maps ", mod_name);
> +		ddebug_sync_classbits(kp, mod_name);

[Severity: Medium]
Is a check comparing dcp->map to map missing here? Because this verifies
kp->ops but omits verifying that the kernel parameter's class map matches the
target map, it seems all dyndbg parameters of the defining module will be
applied to every classmap indiscriminately.

> +	}
> +}
[ ... ]
> @@ -1213,6 +1322,7 @@ static int ddebug_add_module(struct _ddebug_info *di)
[ ... ]
> +	if (dt->info.maps.len)
> +		ddebug_apply_class_maps(&dt->info);
> +	if (dt->info.users.len)
> +		ddebug_apply_class_users(&dt->info);
>  
>  	mutex_lock(&ddebug_lock);
>  	list_add_tail(&dt->link, &ddebug_tables);
>  	mutex_unlock(&ddebug_lock);

[Severity: High]
Will module classmap initialization fail here? The initialization functions
ddebug_apply_class_maps() and ddebug_apply_class_users() execute queries
against the global ddebug_tables list. Since list_add_tail() is called
after these functions return, it appears ddebug_change() will fail to find
the newly loaded module, silently dropping the initial configuration.

>  
> -	vpr_info("%3u debug prints in module %s\n", di->descs.len, di->mod_name);
> +	vpr_info("%3u debug prints in module %s\n",
> +		 dt->info.descs.len, dt->info.mod_name);
>  	return 0;
>  }

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260721-dd-maint-2-v7-0-010fbe73b311@gmail.com?part=28

  reply	other threads:[~2026-07-21 21:18 UTC|newest]

Thread overview: 38+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-07-21 20:56 [PATCH v7 00/29] fix dynamic-debug classmaps API for DRM Jim Cromie
2026-07-21 20:56 ` [PATCH v7 01/29] params: fix a pr_debug(" %p ") use - already in MM-* Jim Cromie
2026-07-21 20:56 ` [PATCH v7 02/29] selftests/dyndbg: Add kselftest script to verify dynamic-debug Jim Cromie
2026-07-21 21:06   ` sashiko-bot
2026-07-21 20:56 ` [PATCH v7 03/29] drm: Fix incorrect ccflags-y spelling inside Makefile Jim Cromie
2026-07-21 20:56 ` [PATCH v7 04/29] drm: fix config dependent unused variable warning Jim Cromie
2026-07-21 20:56 ` [PATCH v7 05/29] drm: Mark CONFIG_DRM_USE_DYNAMIC_DEBUG as unBROKEN Jim Cromie
2026-07-21 20:56 ` [PATCH v7 06/29] vmlinux.lds.h: refactor BOUNDED_SECTION_* macros into bounded_sections.lds.h Jim Cromie
2026-07-21 20:56 ` [PATCH v7 07/29] vmlinux.lds.h: drop unused HEADERED_SECTION* macros Jim Cromie
2026-07-21 20:56 ` [PATCH v7 08/29] vmlinux.lds.h: Fix ALIGN(8) omission causing NULL ptr on i386 Jim Cromie
2026-07-21 20:56 ` [PATCH v7 09/29] vmlinux.lds.h: remove redundant ALIGN(8) directives Jim Cromie
2026-07-21 20:56 ` [PATCH v7 10/29] dyndbg.lds.S: fix lost dyndbg sections in modules Jim Cromie
2026-07-21 20:57 ` [PATCH v7 11/29] dyndbg: factor ddebug_match_desc out from ddebug_change Jim Cromie
2026-07-21 21:05   ` sashiko-bot
2026-07-21 20:57 ` [PATCH v7 12/29] dyndbg: add stub macro for DECLARE_DYNDBG_CLASSMAP Jim Cromie
2026-07-21 20:57 ` [PATCH v7 13/29] dyndbg: reword "class unknown," to "class:_UNKNOWN_" Jim Cromie
2026-07-21 20:57 ` [PATCH v7 14/29] dyndbg-API: remove DD_CLASS_TYPE_(DISJOINT|LEVEL)_NAMES and code Jim Cromie
2026-07-21 20:57 ` [PATCH v7 15/29] dyndbg: drop NUM_TYPE_ARGS Jim Cromie
2026-07-21 20:57 ` [PATCH v7 16/29] dyndbg: bump num-tokens in a query-cmd from 9 to 15 Jim Cromie
2026-07-21 20:57 ` [PATCH v7 17/29] dyndbg: reduce verbose/debug clutter Jim Cromie
2026-07-21 20:57 ` [PATCH v7 18/29] lib/parser: add match_wildcard_hyphen() for agnostic matching Jim Cromie
2026-07-21 20:57 ` [PATCH v7 19/29] dyndbg: use KBUILD_MODFILE for unique builtin module names Jim Cromie
2026-07-21 20:57 ` [PATCH v7 20/29] dyndbg: refactor param_set_dyndbg_classes and below Jim Cromie
2026-07-21 21:11   ` sashiko-bot
2026-07-21 20:57 ` [PATCH v7 21/29] dyndbg: tighten fn-sig of ddebug_apply_class_bitmap Jim Cromie
2026-07-21 20:57 ` [PATCH v7 22/29] dyndbg: replace classmap list with an array-slice Jim Cromie
2026-07-21 20:57 ` [PATCH v7 23/29] dyndbg: macrofy a 2-index for-loop pattern Jim Cromie
2026-07-21 20:57 ` [PATCH v7 24/29] dyndbg: pin class param storage to u32 Jim Cromie
2026-07-21 21:10   ` sashiko-bot
2026-07-21 20:57 ` [PATCH v7 25/29] dyndbg,module: make proper substructs in _ddebug_info Jim Cromie
2026-07-21 21:09   ` sashiko-bot
2026-07-21 20:57 ` [PATCH v7 26/29] dyndbg: move mod_name down from struct ddebug_table to _ddebug_info Jim Cromie
2026-07-21 21:13   ` sashiko-bot
2026-07-21 20:57 ` [PATCH v7 27/29] dyndbg: hoist classmap-filter-by-modname up to ddebug_add_module Jim Cromie
2026-07-21 20:57 ` [PATCH v7 28/29] dyndbg-API: replace DECLARE_DYNDBG_CLASSMAP Jim Cromie
2026-07-21 21:18   ` sashiko-bot [this message]
2026-07-21 20:57 ` [PATCH v7 29/29] selftests/dyndbg: enable FT_classmap_inheritance Jim Cromie
2026-07-21 21:11   ` sashiko-bot

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260721211814.01EBE1F000E9@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=dri-devel@lists.freedesktop.org \
    --cc=jim.cromie@gmail.com \
    --cc=linux-modules@vger.kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox