Linux s390 Architecture development
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "K Prateek Nayak" <kprateek.nayak@amd.com>
Cc: "Alexander Gordeev" <agordeev@linux.ibm.com>,
	linux-s390@vger.kernel.org,
	"Christian Borntraeger" <borntraeger@linux.ibm.com>,
	"Heiko Carstens" <hca@linux.ibm.com>,
	"Vasily Gorbik" <gor@linux.ibm.com>
Subject: Re: [RFC PATCH v3 07/13] s390/topology: Initialize sbm topology during topology_init_early()
Date: Fri, 02 Oct 2026 09:13:25 +0000	[thread overview]
Message-ID: <20261002091326.56FC01F00893@smtp.kernel.org> (raw)
In-Reply-To: <20261001192849.74788-8-kprateek.nayak@amd.com>

Thank you for your contribution! Sashiko AI review found 3 potential issue(s) to consider:
- [High] s390/topology: OOB write in SBM due to underestimating max_threads_per_instance
- [High] s390/topology: arch_sbm_cpu_instance_id() fails to map secondary CPUs
- [Low] s390/topology: __configure_sbm_topology() counts dummy head node
--

commit 7e4b5901a7b8d62cc7a0551c478b49d8ad5ae92b
Author: K Prateek Nayak <kprateek.nayak@amd.com>

s390/topology: Initialize sbm topology during topology_init_early()

This commit configures sparsebitmask (sbm) properties for the system using
socket_info when the topology mode is TOPOLOGY_MODE_HW. It also adds
arch_sbm_cpu_instance_id() to map CPUs to socket instance IDs during
CPU hotplug events.

> diff --git a/arch/s390/kernel/topology.c b/arch/s390/kernel/topology.c
> index 1377c6f3f6709..80dc51f5ce6f5 100644
> --- a/arch/s390/kernel/topology.c
> +++ b/arch/s390/kernel/topology.c

[ ... ]

> @@ -561,6 +562,55 @@ static int __init detect_polarization(union topology_entry *tle)
>  	return tl_core->pp != POLARIZATION_HRZ;
>  }
>  
> +int arch_sbm_cpu_instance_id(int cpu)
> +{
> +	struct mask_info *info = &socket_info;
> +
> +	/*
> +	 * sbm core should not call this if sbm_set_topology() was
> +	 * skipped below due to lack of topology information.
> +	 */
> +	if (WARN_ON_ONCE(topology_mode != TOPOLOGY_MODE_HW))
> +		return -1;
> +
> +	while (info) {
> +		if (cpumask_test_cpu(cpu, &info->mask))
> +			return info->id;

[Severity: High]
Can this fail to map newly hotplugged CPUs?

Since hardware topology masks on s390 are updated asynchronously via a
workqueue, the mask might not be populated before the CPU online callback
executes during CPU hotplug.

> +		info = info->next;
> +	}
> +
> +	pr_warn_once("socket mapping for CPU%d not found! Mapping to ID 0", cpu);
> +	return 0;

[Severity: High]
If the mask check above fails due to the asynchronous update race, does
falling back to instance 0 break SBM topology isolation by grouping all
secondary CPUs into a single instance?

> +}
> +
> +static void __configure_sbm_topology(void)
> +{
> +	int num_sbm_instances = 0, max_threads_per_instance = -1;
> +	struct mask_info *info = &socket_info;

[Severity: Low]
Should this traversal start at info->next instead of the dummy head node?

socket_info serves as a static dummy head, and alloc_masks() attaches newly
allocated instances starting at socket_info.next.

> +
> +	/*
> +	 * Consider single package if topology
> +	 * information is unavailable.
> +	 *
> +	 * sbm core will handle the initialization.
> +	 */
> +	if (topology_mode != TOPOLOGY_MODE_HW)
> +		return;
> +
> +	while (info) {
> +		num_sbm_instances += 1;

[Severity: Low]
Counting the dummy head node as a valid instance appears to pass an inflated
count to sbm_set_topology(), which would overallocate the SBM instance
metadata arrays by exactly one element.

> +		max_threads_per_instance = max_t(int,
> +						 cpumask_weight(&info->mask),
> +						 max_threads_per_instance);

[Severity: High]
Does calculating the max threads per instance here underestimate the
capacity?

Because this is called during topology_init_early() when only the boot CPU
is marked as present, info->mask will only contain the boot CPU's threads.
This results in a drastically undersized max_threads_per_instance.

When secondary CPUs come online later, alloc_sbm_index() assigns them
local indices. Will returning an index that exceeds this undersized limit
trigger an out-of-bounds write in the SBM core when accessing its internal
arrays?

> +		info = info->next;
> +	}
> +
> +	if (WARN_ON_ONCE(!num_sbm_instances || max_threads_per_instance < 1))
> +		return;
> +
> +	sbm_set_topology(num_sbm_instances, max_threads_per_instance);
> +}

[ ... ]

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20261001192849.74788-1-kprateek.nayak@amd.com?part=7

  reply	other threads:[~2026-10-02  9:13 UTC|newest]

Thread overview: 36+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-10-01 19:28 [RFC PATCH v3 00/13] lib, sched: Introduce sparsebitmap (sbm) K Prateek Nayak
2026-10-01 19:28 ` [RFC PATCH v3 01/13] lib/sbm: Introduce helpers for architectures to configure LLC properties K Prateek Nayak
2026-10-02  9:13   ` sashiko-bot
2026-10-07  5:43   ` Shrikanth Hegde
2026-10-01 19:28 ` [RFC PATCH v3 02/13] drivers/base/arch_topology: Add support for initializing sbm topology K Prateek Nayak
2026-10-02  9:13   ` sashiko-bot
2026-10-01 19:28 ` [RFC PATCH v3 03/13] LoongArch: Initialize CPU _PXM relation for disabled CPUs from SRAT K Prateek Nayak
2026-10-02  9:13   ` sashiko-bot
2026-10-01 19:28 ` [RFC PATCH v3 04/13] LoongArch: Configure sbm topology during SMP preparation K Prateek Nayak
2026-10-02  9:13   ` sashiko-bot
2026-10-07  3:51   ` [RFC PATCH v3.1 " K Prateek Nayak
2026-10-01 19:28 ` [RFC PATCH v3 05/13] MIPS: Initialize sbm topology on multi-node systems K Prateek Nayak
2026-10-02  9:13   ` sashiko-bot
2026-10-01 19:28 ` [RFC PATCH v3 06/13] powerpc/setup: Initialize sbm topology based on coregroup / NUMA topology K Prateek Nayak
2026-10-02  9:13   ` sashiko-bot
2026-10-07 14:43   ` Shrikanth Hegde
2026-10-01 19:28 ` [RFC PATCH v3 07/13] s390/topology: Initialize sbm topology during topology_init_early() K Prateek Nayak
2026-10-02  9:13   ` sashiko-bot [this message]
2026-10-07 10:19   ` Mete Durlu
2026-10-01 19:28 ` [RFC PATCH v3 08/13] sparc64: Initialize sbm topology on multi-LLC system K Prateek Nayak
2026-10-02  9:13   ` sashiko-bot
2026-10-01 19:28 ` [RFC PATCH v3 09/13] x86/cpu/topology: Initialize sbm topology after topology parsing K Prateek Nayak
2026-10-02  9:13   ` sashiko-bot
2026-10-03  8:27   ` Chen Yu
2026-10-04  6:17     ` K Prateek Nayak
2026-10-07  3:52   ` [RFC PATCH v3.1 " K Prateek Nayak
2026-10-01 19:28 ` [RFC PATCH v3 10/13] lib/sbm: Dynamically allocate sbm index when CPU is activated K Prateek Nayak
2026-10-02  9:13   ` sashiko-bot
2026-10-01 19:28 ` [RFC PATCH v3 11/13] lib/sbm: Add helpers to allocate, set, clear, and traverse the bits on sbm K Prateek Nayak
2026-10-02  9:13   ` sashiko-bot
2026-10-01 19:28 ` [RFC PATCH v3 12/13] sched/fair: Allocate nohz.idle_cpus_mask during sched_init_smp() K Prateek Nayak
2026-10-02  9:13   ` sashiko-bot
2026-10-01 19:28 ` [RFC PATCH v3 13/13] sched/fair: Switch nohz.idle_cpus to use sbm K Prateek Nayak
2026-10-02  9:13   ` sashiko-bot
2026-10-03  9:10 ` [RFC PATCH v3 00/13] lib, sched: Introduce sparsebitmap (sbm) Chen Yu
2026-10-04  6:13   ` K Prateek Nayak

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20261002091326.56FC01F00893@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=agordeev@linux.ibm.com \
    --cc=borntraeger@linux.ibm.com \
    --cc=gor@linux.ibm.com \
    --cc=hca@linux.ibm.com \
    --cc=kprateek.nayak@amd.com \
    --cc=linux-s390@vger.kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox