Linux Trace Kernel
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Vincent Donnefort" <vdonnefort@google.com>
Cc: linux-trace-kernel@vger.kernel.org
Subject: Re: [PATCH v5 01/18] tracing/remotes: Gate tracefs files opening on trace remote registration
Date: Wed, 12 Aug 2026 16:31:10 +0000	[thread overview]
Message-ID: <20260812163111.587781F000E9@smtp.kernel.org> (raw)
In-Reply-To: <20260812161340.2417322-2-vdonnefort@google.com>

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [High] Incomplete tracefs gating: Caller-created tracefs files bypass the newly introduced `trace_remote_tracefs_open` gating, leaving them fully accessible if registration fails.
--

--- Patch [1]: [PATCH v5 01/18] tracing/remotes: Gate tracefs files opening on trace remote registration ---
commit 63ef30c302e1341f240b4f5b82d4e65d421da4cf
Author: Vincent Donnefort <vdonnefort@google.com>
tracing/remotes: Gate tracefs files opening on trace remote registration

This commit adds a global list of registered trace remotes and a gating
function to prevent access to tracefs files for remotes that are being
destroyed or failed to register. Standard trace remote file operations
are wrapped to check this list before allowing open().

> --- a/kernel/trace/trace_remote.c
> +++ b/kernel/trace/trace_remote.c

[ ... ]

> @@ -932,8 +999,12 @@ int trace_remote_register(const char *name, struct trace_remote_callbacks *cbs,
>  	}
>  
>  	ret = cbs->init ? cbs->init(remote->dentry, priv) : 0;
> -	if (ret)
> +	if (ret) {
>  		pr_err("Init failed for trace remote '%s' (%d)\n", name, ret);
> +	} else {
> +		guard(mutex)(&trace_remotes_lock);
> +		list_add(&remote->node, &trace_remotes);
> +	}
>  
>  	return ret;
>  }

[Severity: High]
Does this leave caller-created tracefs files exposed if cbs->init() fails?

If a remote's initialization fails halfway through, any custom tracefs files
already created by cbs->init() will leak and remain accessible. Because
trace_remote_tracefs_open() is static to trace_remote.c, the caller cannot
wrap their custom files' open() callbacks with this new gating mechanism.

For example, if KVM's hyp_trace_init_tracefs() successfully creates
a 'write_event' file but fails later, trace_remote_register() returns an
error and the remote is not added to the trace_remotes list. 

Userspace could then open the leaked 'write_event' file, bypassing the
gating entirely, and trigger kvm_call_hyp_nvhe() against the uninitialized
hypervisor stub.

Should trace_remote_tracefs_open() be exported so that subsystems can gate
their custom files, or should the leaked files be cleaned up when
trace_remote_register() returns an error?

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260812161340.2417322-1-vdonnefort@google.com?part=1

  reply	other threads:[~2026-08-12 16:31 UTC|newest]

Thread overview: 22+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-08-12 16:13 [PATCH v5 00/18] tracing/remotes: Add printk, dump_on_panic and boot parameters Vincent Donnefort
2026-08-12 16:13 ` [PATCH v5 01/18] tracing/remotes: Gate tracefs files opening on trace remote registration Vincent Donnefort
2026-08-12 16:31   ` sashiko-bot [this message]
2026-08-12 16:13 ` [PATCH v5 02/18] tracing/remotes: Release tracefs,eventfs on registration failure Vincent Donnefort
2026-08-12 16:25   ` sashiko-bot
2026-08-12 16:13 ` [PATCH v5 03/18] tracing/remotes: Use kstrtobool for boolean tracefs files Vincent Donnefort
2026-08-12 16:13 ` [PATCH v5 04/18] tracing/remotes: Use a single per-remote polling work Vincent Donnefort
2026-08-12 16:13 ` [PATCH v5 05/18] tracing/simple_ring_buffer: Add support for compressed length Vincent Donnefort
2026-08-12 16:42   ` sashiko-bot
2026-08-12 16:13 ` [PATCH v5 06/18] tracing/remotes: Add dmesg tracefs file Vincent Donnefort
2026-08-12 16:42   ` sashiko-bot
2026-08-12 16:13 ` [PATCH v5 07/18] tracing/remotes: selftests: Add a test for the " Vincent Donnefort
2026-08-12 16:40   ` sashiko-bot
2026-08-12 16:13 ` [PATCH v5 08/18] tracing/remotes: selftests: Prefix hypervisor folder Vincent Donnefort
2026-08-12 16:52   ` sashiko-bot
2026-08-12 16:13 ` [PATCH v5 09/18] ring-buffer: Use irqsave for the reader lock in ring_buffer_poll_remote Vincent Donnefort
2026-08-12 16:13 ` [PATCH v5 10/18] ring-buffer: Use panic-friendly locking in ring_buffer_iter interface Vincent Donnefort
2026-08-12 16:54   ` sashiko-bot
     [not found] ` <20260812161340.2417322-15-vdonnefort@google.com>
2026-08-12 17:02   ` [PATCH v5 14/18] tracing/remotes: selftests: Add a test for the dump_on_panic tracefs file sashiko-bot
     [not found] ` <20260812161340.2417322-14-vdonnefort@google.com>
2026-08-12 17:08   ` [PATCH v5 13/18] tracing/remotes: Add " sashiko-bot
     [not found] ` <20260812161340.2417322-17-vdonnefort@google.com>
2026-08-12 17:11   ` [PATCH v5 16/18] tracing/remotes: Add trace_remote cmdline options sashiko-bot
     [not found] ` <20260812161340.2417322-16-vdonnefort@google.com>
2026-08-12 17:13   ` [PATCH v5 15/18] tracing/remotes: Add poll_ms tracefs file sashiko-bot

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260812163111.587781F000E9@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=linux-trace-kernel@vger.kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    --cc=vdonnefort@google.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox