From: sashiko-bot@kernel.org
To: "K Prateek Nayak" <kprateek.nayak@amd.com>
Cc: "Alexander Gordeev" <agordeev@linux.ibm.com>,
linux-s390@vger.kernel.org,
"Christian Borntraeger" <borntraeger@linux.ibm.com>,
"Heiko Carstens" <hca@linux.ibm.com>,
"Vasily Gorbik" <gor@linux.ibm.com>
Subject: Re: [RFC PATCH v3 07/13] s390/topology: Initialize sbm topology during topology_init_early()
Date: Fri, 02 Oct 2026 09:13:25 +0000 [thread overview]
Message-ID: <20261002091326.56FC01F00893@smtp.kernel.org> (raw)
In-Reply-To: <20261001192849.74788-8-kprateek.nayak@amd.com>
Thank you for your contribution! Sashiko AI review found 3 potential issue(s) to consider:
- [High] s390/topology: OOB write in SBM due to underestimating max_threads_per_instance
- [High] s390/topology: arch_sbm_cpu_instance_id() fails to map secondary CPUs
- [Low] s390/topology: __configure_sbm_topology() counts dummy head node
--
commit 7e4b5901a7b8d62cc7a0551c478b49d8ad5ae92b
Author: K Prateek Nayak <kprateek.nayak@amd.com>
s390/topology: Initialize sbm topology during topology_init_early()
This commit configures sparsebitmask (sbm) properties for the system using
socket_info when the topology mode is TOPOLOGY_MODE_HW. It also adds
arch_sbm_cpu_instance_id() to map CPUs to socket instance IDs during
CPU hotplug events.
> diff --git a/arch/s390/kernel/topology.c b/arch/s390/kernel/topology.c
> index 1377c6f3f6709..80dc51f5ce6f5 100644
> --- a/arch/s390/kernel/topology.c
> +++ b/arch/s390/kernel/topology.c
[ ... ]
> @@ -561,6 +562,55 @@ static int __init detect_polarization(union topology_entry *tle)
> return tl_core->pp != POLARIZATION_HRZ;
> }
>
> +int arch_sbm_cpu_instance_id(int cpu)
> +{
> + struct mask_info *info = &socket_info;
> +
> + /*
> + * sbm core should not call this if sbm_set_topology() was
> + * skipped below due to lack of topology information.
> + */
> + if (WARN_ON_ONCE(topology_mode != TOPOLOGY_MODE_HW))
> + return -1;
> +
> + while (info) {
> + if (cpumask_test_cpu(cpu, &info->mask))
> + return info->id;
[Severity: High]
Can this fail to map newly hotplugged CPUs?
Since hardware topology masks on s390 are updated asynchronously via a
workqueue, the mask might not be populated before the CPU online callback
executes during CPU hotplug.
> + info = info->next;
> + }
> +
> + pr_warn_once("socket mapping for CPU%d not found! Mapping to ID 0", cpu);
> + return 0;
[Severity: High]
If the mask check above fails due to the asynchronous update race, does
falling back to instance 0 break SBM topology isolation by grouping all
secondary CPUs into a single instance?
> +}
> +
> +static void __configure_sbm_topology(void)
> +{
> + int num_sbm_instances = 0, max_threads_per_instance = -1;
> + struct mask_info *info = &socket_info;
[Severity: Low]
Should this traversal start at info->next instead of the dummy head node?
socket_info serves as a static dummy head, and alloc_masks() attaches newly
allocated instances starting at socket_info.next.
> +
> + /*
> + * Consider single package if topology
> + * information is unavailable.
> + *
> + * sbm core will handle the initialization.
> + */
> + if (topology_mode != TOPOLOGY_MODE_HW)
> + return;
> +
> + while (info) {
> + num_sbm_instances += 1;
[Severity: Low]
Counting the dummy head node as a valid instance appears to pass an inflated
count to sbm_set_topology(), which would overallocate the SBM instance
metadata arrays by exactly one element.
> + max_threads_per_instance = max_t(int,
> + cpumask_weight(&info->mask),
> + max_threads_per_instance);
[Severity: High]
Does calculating the max threads per instance here underestimate the
capacity?
Because this is called during topology_init_early() when only the boot CPU
is marked as present, info->mask will only contain the boot CPU's threads.
This results in a drastically undersized max_threads_per_instance.
When secondary CPUs come online later, alloc_sbm_index() assigns them
local indices. Will returning an index that exceeds this undersized limit
trigger an out-of-bounds write in the SBM core when accessing its internal
arrays?
> + info = info->next;
> + }
> +
> + if (WARN_ON_ONCE(!num_sbm_instances || max_threads_per_instance < 1))
> + return;
> +
> + sbm_set_topology(num_sbm_instances, max_threads_per_instance);
> +}
[ ... ]
--
Sashiko AI review · https://sashiko.dev/#/patchset/20261001192849.74788-1-kprateek.nayak@amd.com?part=7
next prev parent reply other threads:[~2026-10-02 9:13 UTC|newest]
Thread overview: 36+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-10-01 19:28 [RFC PATCH v3 00/13] lib, sched: Introduce sparsebitmap (sbm) K Prateek Nayak
2026-10-01 19:28 ` [RFC PATCH v3 01/13] lib/sbm: Introduce helpers for architectures to configure LLC properties K Prateek Nayak
2026-10-02 9:13 ` sashiko-bot
2026-10-07 5:43 ` Shrikanth Hegde
2026-10-01 19:28 ` [RFC PATCH v3 02/13] drivers/base/arch_topology: Add support for initializing sbm topology K Prateek Nayak
2026-10-02 9:13 ` sashiko-bot
2026-10-01 19:28 ` [RFC PATCH v3 03/13] LoongArch: Initialize CPU _PXM relation for disabled CPUs from SRAT K Prateek Nayak
2026-10-02 9:13 ` sashiko-bot
2026-10-01 19:28 ` [RFC PATCH v3 04/13] LoongArch: Configure sbm topology during SMP preparation K Prateek Nayak
2026-10-02 9:13 ` sashiko-bot
2026-10-07 3:51 ` [RFC PATCH v3.1 " K Prateek Nayak
2026-10-01 19:28 ` [RFC PATCH v3 05/13] MIPS: Initialize sbm topology on multi-node systems K Prateek Nayak
2026-10-02 9:13 ` sashiko-bot
2026-10-01 19:28 ` [RFC PATCH v3 06/13] powerpc/setup: Initialize sbm topology based on coregroup / NUMA topology K Prateek Nayak
2026-10-02 9:13 ` sashiko-bot
2026-10-07 14:43 ` Shrikanth Hegde
2026-10-01 19:28 ` [RFC PATCH v3 07/13] s390/topology: Initialize sbm topology during topology_init_early() K Prateek Nayak
2026-10-02 9:13 ` sashiko-bot [this message]
2026-10-07 10:19 ` Mete Durlu
2026-10-01 19:28 ` [RFC PATCH v3 08/13] sparc64: Initialize sbm topology on multi-LLC system K Prateek Nayak
2026-10-02 9:13 ` sashiko-bot
2026-10-01 19:28 ` [RFC PATCH v3 09/13] x86/cpu/topology: Initialize sbm topology after topology parsing K Prateek Nayak
2026-10-02 9:13 ` sashiko-bot
2026-10-03 8:27 ` Chen Yu
2026-10-04 6:17 ` K Prateek Nayak
2026-10-07 3:52 ` [RFC PATCH v3.1 " K Prateek Nayak
2026-10-01 19:28 ` [RFC PATCH v3 10/13] lib/sbm: Dynamically allocate sbm index when CPU is activated K Prateek Nayak
2026-10-02 9:13 ` sashiko-bot
2026-10-01 19:28 ` [RFC PATCH v3 11/13] lib/sbm: Add helpers to allocate, set, clear, and traverse the bits on sbm K Prateek Nayak
2026-10-02 9:13 ` sashiko-bot
2026-10-01 19:28 ` [RFC PATCH v3 12/13] sched/fair: Allocate nohz.idle_cpus_mask during sched_init_smp() K Prateek Nayak
2026-10-02 9:13 ` sashiko-bot
2026-10-01 19:28 ` [RFC PATCH v3 13/13] sched/fair: Switch nohz.idle_cpus to use sbm K Prateek Nayak
2026-10-02 9:13 ` sashiko-bot
2026-10-03 9:10 ` [RFC PATCH v3 00/13] lib, sched: Introduce sparsebitmap (sbm) Chen Yu
2026-10-04 6:13 ` K Prateek Nayak
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20261002091326.56FC01F00893@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=agordeev@linux.ibm.com \
--cc=borntraeger@linux.ibm.com \
--cc=gor@linux.ibm.com \
--cc=hca@linux.ibm.com \
--cc=kprateek.nayak@amd.com \
--cc=linux-s390@vger.kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox