Linux Trace Kernel
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Vincent Donnefort" <vdonnefort@google.com>
Cc: linux-trace-kernel@vger.kernel.org
Subject: Re: [PATCH v5 15/18] tracing/remotes: Add poll_ms tracefs file
Date: Wed, 12 Aug 2026 17:13:04 +0000	[thread overview]
Message-ID: <20260812171304.A47D41F000E9@smtp.kernel.org> (raw)
In-Reply-To: <20260812161340.2417322-16-vdonnefort@google.com>

Thank you for your contribution! Sashiko AI review found 2 potential issue(s) to consider:
- [Low] Data race on `remote->poll_ms` due to lockless reads.
- [Low] Improper mixing of goto-based error handling and scope-based cleanup (__free) in `trace_remote_iter`.
--

--- Patch [15]: [PATCH v5 15/18] tracing/remotes: Add poll_ms tracefs file ---
commit a661ee191c6d806ed0a716f67237aca890febe25
Author: Vincent Donnefort <vdonnefort@google.com>

tracing/remotes: Add poll_ms tracefs file

Add a tracefs file to configure the trace remote polling period. Keep
the default value to 100ms.

> diff --git a/kernel/trace/trace_remote.c b/kernel/trace/trace_remote.c
> index 5536e0df43795..b1c75666ab638 100644
> --- a/kernel/trace/trace_remote.c
> +++ b/kernel/trace/trace_remote.c
> @@ -1135,6 +1135,40 @@ static int dump_on_panic_show(struct seq_file *s, void *unused)
>  }
>  DEFINE_TRACE_REMOTE_ATTRIBUTE(dump_on_panic);
>  
> +static ssize_t poll_ms_write(struct file *filp, const char __user *ubuf, size_t cnt, loff_t *ppos)
> +{
> +	struct seq_file *seq = filp->private_data;
> +	struct trace_remote *remote = seq->private;
> +	unsigned int val;
> +	int ret;
> +
> +	ret = kstrtouint_from_user(ubuf, cnt, 10, &val);
> +	if (ret)
> +		return ret;
> +
> +	if (!val)
> +		return -EINVAL;
> +
> +	guard(mutex)(&remote->lock);
> +
> +	if (val < remote->poll_ms && remote->poll_cnt)
> +		mod_delayed_work(system_percpu_wq, &remote->poll_work, msecs_to_jiffies(val));
> +
> +	remote->poll_ms = val;
> +
> +	return cnt;
> +}
> +
> +static int poll_ms_show(struct seq_file *s, void *unused)
> +{
> +	struct trace_remote *remote = s->private;
> +
> +	seq_printf(s, "%u\n", remote->poll_ms);

[Severity: Low]
Does this code introduce a data race on remote->poll_ms?

In poll_ms_write(), remote->poll_ms is modified while holding remote->lock.
However, in poll_ms_show(), remote->poll_ms is read without holding
remote->lock.

It appears this could also cause a data race with lockless reads in
trace_remote_do_poll():

kernel/trace/trace_remote.c:trace_remote_do_poll() {
    ...
	schedule_delayed_work(&remote->poll_work, yield ? 0 : msecs_to_jiffies(remote->poll_ms));
}

Could this concurrent read and write cause a data race, potentially leading
to torn reads or violating kernel concurrency expectations?

[ ... ]

Also, looking at trace_remote_iter() in kernel/trace/trace_remote.c:

kernel/trace/trace_remote.c:trace_remote_iter() {
	struct trace_remote_iterator *iter __free(kfree) = kzalloc_obj(*iter);
    ...
		if (WARN_ON_ONCE(remote->dmesg)) {
			ret = -EBUSY;
			goto err;
		}
    ...
err:
	switch (type) {
	case TRI_PANIC:
		break;
	default:
		trace_remote_put(remote);
	}
	return ERR_PTR(ret);
}

[Severity: Low]
Does this code incorrectly mix goto-based error handling and scope-based
cleanup (__free)?

The cleanup subsystem guidelines prohibit mixing goto-based error paths
with __free() variable declarations in the same function. While it does not
appear to cause a concrete resource leak or double-free in this specific
instance, could this create confusing ownership semantics and risk future
bugs during refactoring?

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260812161340.2417322-1-vdonnefort@google.com?part=15

      parent reply	other threads:[~2026-08-12 17:13 UTC|newest]

Thread overview: 22+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-08-12 16:13 [PATCH v5 00/18] tracing/remotes: Add printk, dump_on_panic and boot parameters Vincent Donnefort
2026-08-12 16:13 ` [PATCH v5 01/18] tracing/remotes: Gate tracefs files opening on trace remote registration Vincent Donnefort
2026-08-12 16:31   ` sashiko-bot
2026-08-12 16:13 ` [PATCH v5 02/18] tracing/remotes: Release tracefs,eventfs on registration failure Vincent Donnefort
2026-08-12 16:25   ` sashiko-bot
2026-08-12 16:13 ` [PATCH v5 03/18] tracing/remotes: Use kstrtobool for boolean tracefs files Vincent Donnefort
2026-08-12 16:13 ` [PATCH v5 04/18] tracing/remotes: Use a single per-remote polling work Vincent Donnefort
2026-08-12 16:13 ` [PATCH v5 05/18] tracing/simple_ring_buffer: Add support for compressed length Vincent Donnefort
2026-08-12 16:42   ` sashiko-bot
2026-08-12 16:13 ` [PATCH v5 06/18] tracing/remotes: Add dmesg tracefs file Vincent Donnefort
2026-08-12 16:42   ` sashiko-bot
2026-08-12 16:13 ` [PATCH v5 07/18] tracing/remotes: selftests: Add a test for the " Vincent Donnefort
2026-08-12 16:40   ` sashiko-bot
2026-08-12 16:13 ` [PATCH v5 08/18] tracing/remotes: selftests: Prefix hypervisor folder Vincent Donnefort
2026-08-12 16:52   ` sashiko-bot
2026-08-12 16:13 ` [PATCH v5 09/18] ring-buffer: Use irqsave for the reader lock in ring_buffer_poll_remote Vincent Donnefort
2026-08-12 16:13 ` [PATCH v5 10/18] ring-buffer: Use panic-friendly locking in ring_buffer_iter interface Vincent Donnefort
2026-08-12 16:54   ` sashiko-bot
     [not found] ` <20260812161340.2417322-15-vdonnefort@google.com>
2026-08-12 17:02   ` [PATCH v5 14/18] tracing/remotes: selftests: Add a test for the dump_on_panic tracefs file sashiko-bot
     [not found] ` <20260812161340.2417322-14-vdonnefort@google.com>
2026-08-12 17:08   ` [PATCH v5 13/18] tracing/remotes: Add " sashiko-bot
     [not found] ` <20260812161340.2417322-17-vdonnefort@google.com>
2026-08-12 17:11   ` [PATCH v5 16/18] tracing/remotes: Add trace_remote cmdline options sashiko-bot
     [not found] ` <20260812161340.2417322-16-vdonnefort@google.com>
2026-08-12 17:13   ` sashiko-bot [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260812171304.A47D41F000E9@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=linux-trace-kernel@vger.kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    --cc=vdonnefort@google.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox