Linux Modules
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Jim Cromie" <jim.cromie@gmail.com>
Cc: dri-devel@lists.freedesktop.org, linux-modules@vger.kernel.org
Subject: Re: [PATCH v9 24/39] dyndbg-API: replace DECLARE_DYNDBG_CLASSMAP
Date: Wed, 09 Sep 2026 01:13:08 +0000	[thread overview]
Message-ID: <20260909011309.543B91F00A3A@smtp.kernel.org> (raw)
In-Reply-To: <20260908-dd-cmap-part2-clean-v9-24-3a3f621f4a10@gmail.com>

Thank you for your contribution! Sashiko AI review found 3 potential issue(s) to consider:
- [Medium] Newly loaded classmap user modules fail to sync disabled classes due to a hardcoded `0UL` state assumption.
- [Medium] TOCTOU race in `ddebug_apply_class_users` when a class parameter is modified via sysfs concurrently with module load.
- [Low] struct ddebug_class_user defines mod_name as non-const char*, which discards qualifiers from string literals.
--

commit ed72477b68f823658c20da0da2c5754d60e12c69
Author: Jim Cromie <jim.cromie@gmail.com>

dyndbg-API: replace DECLARE_DYNDBG_CLASSMAP
    
DECLARE_DYNDBG_CLASSMAP had a flaw: multiple invocations across both
core and driver modules broke the K&R "define once, refer afterwards"
principle, causing boot-time parameter propagation failures.

Replace it with an explicit client-server model:
[ ... ]

> diff --git a/include/linux/dynamic_debug.h b/include/linux/dynamic_debug.h
> index 144a2a947abcb..6517e0169a803 100644
> --- a/include/linux/dynamic_debug.h
> +++ b/include/linux/dynamic_debug.h
[ ... ]
> +struct ddebug_class_user {
> +	char *mod_name;

[Severity: Low]
Does this code discard qualifiers from string literals?

Using the DYNAMIC_DEBUG_CLASSMAP_USE_ macro assigns the string literal
DDEBUG_MODNAME to this field, which can trigger compiler warnings and
compromises type safety. Should this be declared as const char *mod_name
instead, similar to how it is defined in struct ddebug_class_map?

> +	struct ddebug_class_map *map;
> +	const int offset;	/* offset from map->base */
> +} __aligned(8);

[ ... ]
> diff --git a/lib/dynamic_debug.c b/lib/dynamic_debug.c
> index 2065bfd1687e0..0e25b4d53942b 100644
> --- a/lib/dynamic_debug.c
> +++ b/lib/dynamic_debug.c
[ ... ]
> +/* called for class-users only, parse_one does this for definer modules */
> +static void ddebug_sync_classbits(const struct kernel_param *kp, const char *modname)
> +{
> +	const struct ddebug_class_param *dcp = kp->arg;
> +	u32 val, new_bits;
> +
> +	if (!dcp || !dcp->map)
> +		return;
> +
> +	switch (dcp->map->map_type) {
> +	case DD_CLASS_TYPE_DISJOINT_BITS:
> +		val = READ_ONCE(*dcp->bits);
> +		ddebug_class_param_clamp_input(&val, kp);
> +		new_bits = val;
> +		v2pr_info("  %s: classbits: 0x%x\n", KP_NAME(kp), new_bits);
> +		ddebug_apply_class_bitmap(dcp, &new_bits, 0UL, modname);

[Severity: Medium]
Will this fail to sync disabled classes for newly loaded modules?

By hardcoding 0UL as the old_bits argument, ddebug_apply_class_bitmap()
assumes the module starts with all debug classes disabled. This means it
will skip generating disable commands for any cleared bits.

If a module is compiled with -DDEBUG, its callsites are enabled by default
and won't be correctly disabled to match the system-wide classmap parameter
state.

> +		break;
> +	case DD_CLASS_TYPE_LEVEL_NUM:
> +		val = READ_ONCE(*dcp->lvl);
> +		ddebug_class_param_clamp_input(&val, kp);
> +		new_bits = CLASSMAP_BITMASK(val);
> +		v2pr_info("  %s: lvl:%d bits:0x%x\n", KP_NAME(kp), val, new_bits);
> +		ddebug_apply_class_bitmap(dcp, &new_bits, 0UL, modname);
> +		break;
> +	default:
> +		pr_err("bad map type %d\n", dcp->map->map_type);
> +		return;
> +	}
> +}
[ ... ]
> @@ -1238,12 +1404,17 @@ static int ddebug_add_module(struct _ddebug_info *di)
>  	 */
>  	dt->info = *di;
>  	dd_set_module_subrange(i, cm, &dt->info, maps);
> +	dd_set_module_subrange(i, cli, &dt->info, users);
>  
>  	mutex_lock(&ddebug_lock);
>  	list_add_tail(&dt->link, &ddebug_tables);
>  	mutex_unlock(&ddebug_lock);
>  
> -	vpr_info("%3u debug prints in module %s\n", di->descs.len, di->mod_name);
> +	if (dt->info.users.len)
> +		ddebug_apply_class_users(&dt->info);

[Severity: Medium]
Can this introduce a TOCTOU race with concurrent sysfs updates?

Here, the new module is added to ddebug_tables and the ddebug_lock is
dropped before the module's initial settings are applied by
ddebug_apply_class_users().

If a concurrent sysfs write to the dyndbg class parameter occurs in this
lockless window, the sysfs thread will acquire ddebug_lock, apply its new
parameter value to all modules (including this newly added one), and update
the parameter value.

When this load thread then calls ddebug_apply_class_users(), it will read the
parameter unprotected. If it read the old parameter value before the sysfs
thread overwrote it, it will subsequently acquire the lock deep inside
ddebug_change() and apply the stale old value, overwriting the sysfs thread's
newer changes. This would leave the module permanently out of sync.

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260908-dd-cmap-part2-clean-v9-0-3a3f621f4a10@gmail.com?part=24

  reply	other threads:[~2026-09-09  1:13 UTC|newest]

Thread overview: 56+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-09  0:54 [PATCH v9 00/39] dyndbg: fix classmaps API for subsystems, query extensions, and selftests Jim Cromie via B4 Relay
2026-09-09  0:54 ` [PATCH v9 01/39] selftests/dyndbg: Add kselftest script to verify dynamic-debug Jim Cromie via B4 Relay
2026-09-09  0:54 ` [PATCH v9 02/39] vmlinux.lds.h: refactor BOUNDED_SECTION_* macros into bounded_sections.lds.h Jim Cromie via B4 Relay
2026-09-09  0:54 ` [PATCH v9 03/39] vmlinux.lds.h: drop unused HEADERED_SECTION* macros Jim Cromie via B4 Relay
2026-09-09  0:55 ` [PATCH v9 04/39] vmlinux.lds.h: Fix ALIGN(8) omission causing NULL ptr on i386 Jim Cromie via B4 Relay
2026-09-09  0:55 ` [PATCH v9 05/39] vmlinux.lds.h: remove redundant ALIGN(8) directives Jim Cromie via B4 Relay
2026-09-09  0:55 ` [PATCH v9 06/39] dyndbg.lds.S: fix lost dyndbg sections in modules Jim Cromie via B4 Relay
2026-09-09  0:55 ` [PATCH v9 07/39] dyndbg: factor ddebug_match_desc out from ddebug_change Jim Cromie via B4 Relay
2026-09-09  1:03   ` sashiko-bot
2026-09-09  0:55 ` [PATCH v9 08/39] dyndbg: add stub macro for DECLARE_DYNDBG_CLASSMAP Jim Cromie via B4 Relay
2026-09-09  1:10   ` sashiko-bot
2026-09-09  0:55 ` [PATCH v9 09/39] dyndbg: reword "class unknown," to "class:_UNKNOWN_" Jim Cromie via B4 Relay
2026-09-09  0:55 ` [PATCH v9 10/39] dyndbg-API: remove DD_CLASS_TYPE_(DISJOINT|LEVEL)_NAMES and code Jim Cromie via B4 Relay
2026-09-09  0:55 ` [PATCH v9 11/39] dyndbg: drop NUM_TYPE_ARGS Jim Cromie via B4 Relay
2026-09-09  0:55 ` [PATCH v9 12/39] dyndbg: bump num-tokens in a query-cmd from 9 to 15 Jim Cromie via B4 Relay
2026-09-09  0:55 ` [PATCH v9 13/39] dyndbg: reduce verbose/debug clutter Jim Cromie via B4 Relay
2026-09-09  0:55 ` [PATCH v9 14/39] lib/parser: add match_wildcard_hyphen() for agnostic matching Jim Cromie via B4 Relay
2026-09-09  0:55 ` [PATCH v9 15/39] kbuild, dyndbg: Clean up builtin module-name ambiguities Jim Cromie via B4 Relay
2026-09-09 15:50   ` Nicolas Schier
2026-09-11 18:20     ` jim.cromie
2026-09-09  0:55 ` [PATCH v9 16/39] dyndbg: refactor param_set_dyndbg_classes and below Jim Cromie via B4 Relay
2026-09-09  0:55 ` [PATCH v9 17/39] dyndbg: tighten fn-sig of ddebug_apply_class_bitmap Jim Cromie via B4 Relay
2026-09-09  0:55 ` [PATCH v9 18/39] dyndbg: replace classmap list with an array-slice Jim Cromie via B4 Relay
2026-09-09  0:55 ` [PATCH v9 19/39] dyndbg: macrofy a 2-index for-loop pattern Jim Cromie via B4 Relay
2026-09-09  0:55 ` [PATCH v9 20/39] dyndbg: reduce class param storage to u32 Jim Cromie via B4 Relay
2026-09-09  0:55 ` [PATCH v9 21/39] dyndbg,module: make proper substructs in _ddebug_info Jim Cromie via B4 Relay
2026-09-09  0:55 ` [PATCH v9 22/39] dyndbg: move mod_name down from struct ddebug_table to _ddebug_info Jim Cromie via B4 Relay
2026-09-09  0:55 ` [PATCH v9 23/39] dyndbg: hoist classmap-filter-by-modname up to ddebug_add_module Jim Cromie via B4 Relay
2026-09-09  0:55 ` [PATCH v9 24/39] dyndbg-API: replace DECLARE_DYNDBG_CLASSMAP Jim Cromie via B4 Relay
2026-09-09  1:13   ` sashiko-bot [this message]
2026-09-09 20:56     ` jim.cromie
2026-09-09  0:55 ` [PATCH v9 25/39] selftests/dyndbg: enable FT_classmap_inheritance Jim Cromie via B4 Relay
2026-09-09  0:55 ` [PATCH v9 26/39] dyndbg: detect class_id reservation conflicts Jim Cromie via B4 Relay
2026-09-09  0:55 ` [PATCH v9 27/39] dyndbg: check DYNAMIC_DEBUG_CLASSMAP_{DEFINE,USE_} args at compile-time Jim Cromie via B4 Relay
2026-09-09  1:07   ` sashiko-bot
2026-09-09  0:55 ` [PATCH v9 28/39] dyndbg-test: add do_bulk testpoint, rename do_prints to do_classes Jim Cromie via B4 Relay
2026-09-09  1:08   ` sashiko-bot
2026-09-09  0:55 ` [PATCH v9 29/39] dyndbg-API: promote DYNAMIC_DEBUG_CLASSMAP_PARAM to API Jim Cromie via B4 Relay
2026-09-09  1:08   ` sashiko-bot
2026-09-09  0:55 ` [PATCH v9 30/39] dyndbg: control-parser: treat comma as a token separator Jim Cromie via B4 Relay
2026-09-09  0:55 ` [PATCH v9 31/39] selftests: enable comma-terminator tests Jim Cromie via B4 Relay
2026-09-09  0:55 ` [PATCH v9 32/39] dyndbg: split multi-query strings with @ Jim Cromie via B4 Relay
2026-09-09  1:06   ` sashiko-bot
2026-09-09  0:55 ` [PATCH v9 33/39] dyndbg: resolve "protection" of class'd pr_debug Jim Cromie via B4 Relay
2026-09-09  1:17   ` sashiko-bot
2026-09-09  0:55 ` [PATCH v9 34/39] dyndbg: harden classmap and descriptor validation Jim Cromie via B4 Relay
2026-09-09  1:13   ` sashiko-bot
2026-09-09  0:55 ` [PATCH v9 35/39] docs/dyndbg: add classmap info to howto Jim Cromie via B4 Relay
2026-09-09  0:55 ` [PATCH v9 36/39] dyndbg: Ignore additional arguments from pr_fmt Jim Cromie via B4 Relay
2026-09-09  1:14   ` sashiko-bot
2026-09-09  0:55 ` [PATCH v9 37/39] dyndbg: add epilogue to dynamic_debug/control file Jim Cromie via B4 Relay
2026-09-09  1:09   ` sashiko-bot
2026-09-09  0:55 ` [PATCH v9 38/39] dyndbg: add +c flag to count advantage of classmaps for DRM Jim Cromie via B4 Relay
2026-09-09  1:11   ` sashiko-bot
2026-09-09  0:55 ` [PATCH v9 39/39] dyndbg: add DEBUG-biased fallback stubs for _dynamic_func_call_cls Jim Cromie via B4 Relay
2026-09-09  1:12   ` sashiko-bot

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260909011309.543B91F00A3A@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=dri-devel@lists.freedesktop.org \
    --cc=jim.cromie@gmail.com \
    --cc=linux-modules@vger.kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox