Linux s390 Architecture development
 help / color / mirror / Atom feed
From: Heiko Carstens <hca@linux.ibm.com>
To: sashiko-reviews@lists.linux.dev
Cc: Alexander Gordeev <agordeev@linux.ibm.com>,
	linux-s390@vger.kernel.org, Vasily Gorbik <gor@linux.ibm.com>,
	Christian Borntraeger <borntraeger@linux.ibm.com>
Subject: Re: [PATCH 08/32] s390/dis: Improve show_code() output
Date: Thu, 1 Oct 2026 14:50:38 +0200	[thread overview]
Message-ID: <20261001125038.23106B29-hca@linux.ibm.com> (raw)
In-Reply-To: <20261001104832.A2F561F000FF@smtp.kernel.org>

On Thu, Oct 01, 2026 at 10:48:32AM +0000, sashiko-bot@kernel.org wrote:
> Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
> - [Medium] s390/dis: NULL pointer dereference in get_trap_ip() during early boot crashes
> > +	pgm_check = test_pt_regs_flag(regs, PIF_PGM_CHECK);
> > +	if (pgm_check)
> > +		trapaddr = get_trap_ip(regs);
> 
> [Severity: Medium]
> Could this call to get_trap_ip() cause a NULL pointer dereference during an
> early boot crash?
> 
> If an early boot exception occurs with the transaction abort bit set
> (regs->int_code & 0x200), __do_early_pgm_check() will handle the exception,
> set PIF_PGM_CHECK, and eventually call show_regs() which calls show_code().
> 
> In get_trap_ip(), there is a check for the transaction abort bit:
> 
> arch/s390/kernel/traps.c:get_trap_ip() {
>     ...
>     if (regs->int_code & 0x200)
>         psw.addr = current->thread.trap_tdb.data[3];

This is not possible, since 0x200 is the mask for TX abort evented. Since the
kernel doesn't make use of TX itself, this bit cannot be set for the early
program check handler.

  reply	other threads:[~2026-10-01 12:50 UTC|newest]

Thread overview: 69+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-10-01 10:32 [PATCH 00/32] s390: Improve exception table handling and disassembler Heiko Carstens
2026-10-01 10:32 ` [PATCH 01/32] s390/kprobes: Prevent kprobes on instructions with exception table entry Heiko Carstens
2026-10-01 10:44   ` sashiko-bot
2026-10-01 10:32 ` [PATCH 02/32] s390/early: Fix early warning handling Heiko Carstens
2026-10-01 10:42   ` sashiko-bot
2026-10-01 10:32 ` [PATCH 03/32] s390: Clear pt_regs flags field Heiko Carstens
2026-10-01 10:44   ` sashiko-bot
2026-10-01 10:32 ` [PATCH 04/32] s390/bug: Indicate modified PSW in disassembly Heiko Carstens
2026-10-01 10:43   ` sashiko-bot
2026-10-01 10:32 ` [PATCH 05/32] s390/tools: Rename gen_facilities to gen_bitmaps Heiko Carstens
2026-10-01 10:37   ` sashiko-bot
2026-10-01 10:32 ` [PATCH 06/32] s390/tools: Generate bitmap of nullified program checks Heiko Carstens
2026-10-01 10:37   ` sashiko-bot
2026-10-01 10:32 ` [PATCH 07/32] s390/traps: Handle nullifying program checks in get_trap_ip() Heiko Carstens
2026-10-01 10:42   ` sashiko-bot
2026-10-01 10:32 ` [PATCH 08/32] s390/dis: Improve show_code() output Heiko Carstens
2026-10-01 10:48   ` sashiko-bot
2026-10-01 12:50     ` Heiko Carstens [this message]
2026-10-01 10:32 ` [PATCH 09/32] s390/extable: Rework exception handling logic Heiko Carstens
2026-10-01 10:41   ` sashiko-bot
2026-10-01 10:32 ` [PATCH 10/32] s390/diag: Convert amode31 exception tables to EX_TABLE_INSN Heiko Carstens
2026-10-01 10:40   ` sashiko-bot
2026-10-01 10:32 ` [PATCH 11/32] s390/uaccess: Convert inline assembly " Heiko Carstens
2026-10-01 10:40   ` sashiko-bot
2026-10-01 10:32 ` [PATCH 12/32] s390/lib/uaccess: " Heiko Carstens
2026-10-01 10:40   ` sashiko-bot
2026-10-01 10:32 ` [PATCH 13/32] s390/futex: " Heiko Carstens
2026-10-01 10:40   ` sashiko-bot
2026-10-01 10:32 ` [PATCH 14/32] s390/diag: " Heiko Carstens
2026-10-01 10:43   ` sashiko-bot
2026-10-01 10:32 ` [PATCH 15/32] s390/mm/pfault: " Heiko Carstens
2026-10-01 10:39   ` sashiko-bot
2026-10-01 10:32 ` [PATCH 16/32] s390/cpu_mf: " Heiko Carstens
2026-10-01 10:40   ` sashiko-bot
2026-10-01 10:32 ` [PATCH 17/32] s390/cert_store: " Heiko Carstens
2026-10-01 10:39   ` sashiko-bot
2026-10-01 10:32 ` [PATCH 18/32] s390/ipl: " Heiko Carstens
2026-10-01 10:40   ` sashiko-bot
2026-10-01 10:32 ` [PATCH 19/32] s390/hypfs: " Heiko Carstens
2026-10-01 10:39   ` sashiko-bot
2026-10-01 10:32 ` [PATCH 20/32] s390/ap: " Heiko Carstens
2026-10-01 10:40   ` sashiko-bot
2026-10-02  7:54   ` Harald Freudenberger
2026-10-01 10:32 ` [PATCH 21/32] s390/fpu: " Heiko Carstens
2026-10-01 10:42   ` sashiko-bot
2026-10-01 10:32 ` [PATCH 22/32] s390/traps: " Heiko Carstens
2026-10-01 10:41   ` sashiko-bot
2026-10-01 10:32 ` [PATCH 23/32] s390/word-at-a-time: " Heiko Carstens
2026-10-01 10:42   ` sashiko-bot
2026-10-01 10:32 ` [PATCH 24/32] s390/kvm: " Heiko Carstens
2026-10-01 10:42   ` sashiko-bot
2026-10-02  8:24   ` Claudio Imbrenda
2026-10-01 10:32 ` [PATCH 25/32] s390/pci: " Heiko Carstens
2026-10-01 10:46   ` sashiko-bot
2026-10-02  9:12   ` Niklas Schnelle
2026-10-01 10:32 ` [PATCH 26/32] s390/boot: " Heiko Carstens
2026-10-01 10:44   ` sashiko-bot
2026-10-01 10:32 ` [PATCH 27/32] s390/cio: " Heiko Carstens
2026-10-01 10:46   ` sashiko-bot
2026-10-01 10:32 ` [PATCH 28/32] s390/dasd: " Heiko Carstens
2026-10-01 10:44   ` sashiko-bot
2026-10-01 10:32 ` [PATCH 29/32] s390/diag_ftp: " Heiko Carstens
2026-10-01 10:43   ` sashiko-bot
2026-10-01 10:32 ` [PATCH 30/32] s390/sclp: " Heiko Carstens
2026-10-01 10:45   ` sashiko-bot
2026-10-01 10:32 ` [PATCH 31/32] s390/bpf: Simplify exception table entry handling Heiko Carstens
2026-10-01 10:46   ` sashiko-bot
2026-10-01 10:32 ` [PATCH 32/32] s390/extable: Remove EX_TABLE macros and fallback extable search Heiko Carstens
2026-10-01 10:44   ` sashiko-bot

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20261001125038.23106B29-hca@linux.ibm.com \
    --to=hca@linux.ibm.com \
    --cc=agordeev@linux.ibm.com \
    --cc=borntraeger@linux.ibm.com \
    --cc=gor@linux.ibm.com \
    --cc=linux-s390@vger.kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox