Linux Trace Kernel
 help / color / mirror / Atom feed
From: Vincent Donnefort <vdonnefort@google.com>
To: sashiko-reviews@lists.linux.dev
Cc: linux-trace-kernel@vger.kernel.org
Subject: Re: [PATCH v5 01/18] tracing/remotes: Gate tracefs files opening on trace remote registration
Date: Thu, 13 Aug 2026 14:16:18 +0100	[thread overview]
Message-ID: <an3DosTQoNFcOHs4@google.com> (raw)
In-Reply-To: <20260812163111.587781F000E9@smtp.kernel.org>

On Wed, Aug 12, 2026 at 04:31:10PM +0000, sashiko-bot@kernel.org wrote:
> Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
> - [High] Incomplete tracefs gating: Caller-created tracefs files bypass the newly introduced `trace_remote_tracefs_open` gating, leaving them fully accessible if registration fails.
> --
> 
> --- Patch [1]: [PATCH v5 01/18] tracing/remotes: Gate tracefs files opening on trace remote registration ---
> commit 63ef30c302e1341f240b4f5b82d4e65d421da4cf
> Author: Vincent Donnefort <vdonnefort@google.com>
> tracing/remotes: Gate tracefs files opening on trace remote registration
> 
> This commit adds a global list of registered trace remotes and a gating
> function to prevent access to tracefs files for remotes that are being
> destroyed or failed to register. Standard trace remote file operations
> are wrapped to check this list before allowing open().
> 
> > --- a/kernel/trace/trace_remote.c
> > +++ b/kernel/trace/trace_remote.c
> 
> [ ... ]
> 
> > @@ -932,8 +999,12 @@ int trace_remote_register(const char *name, struct trace_remote_callbacks *cbs,
> >  	}
> >  
> >  	ret = cbs->init ? cbs->init(remote->dentry, priv) : 0;
> > -	if (ret)
> > +	if (ret) {
> >  		pr_err("Init failed for trace remote '%s' (%d)\n", name, ret);
> > +	} else {
> > +		guard(mutex)(&trace_remotes_lock);
> > +		list_add(&remote->node, &trace_remotes);
> > +	}
> >  
> >  	return ret;
> >  }
> 
> [Severity: High]
> Does this leave caller-created tracefs files exposed if cbs->init() fails?
> 
> If a remote's initialization fails halfway through, any custom tracefs files
> already created by cbs->init() will leak and remain accessible. Because
> trace_remote_tracefs_open() is static to trace_remote.c, the caller cannot
> wrap their custom files' open() callbacks with this new gating mechanism.
> 
> For example, if KVM's hyp_trace_init_tracefs() successfully creates
> a 'write_event' file but fails later, trace_remote_register() returns an
> error and the remote is not added to the trace_remotes list. 
> 
> Userspace could then open the leaked 'write_event' file, bypassing the
> gating entirely, and trigger kvm_call_hyp_nvhe() against the uninitialized
> hypervisor stub.
> 
> Should trace_remote_tracefs_open() be exported so that subsystems can gate
> their custom files, or should the leaked files be cleaned up when
> trace_remote_register() returns an error?
> 
> -- 
> Sashiko AI review · https://sashiko.dev/#/patchset/20260812161340.2417322-1-vdonnefort@google.com?part=1

In the following patch, the tracefs folder is entirely removed on init failure.

-- 
Vincent

  reply	other threads:[~2026-08-13 13:16 UTC|newest]

Thread overview: 29+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-08-12 16:13 [PATCH v5 00/18] tracing/remotes: Add printk, dump_on_panic and boot parameters Vincent Donnefort
2026-08-12 16:13 ` [PATCH v5 01/18] tracing/remotes: Gate tracefs files opening on trace remote registration Vincent Donnefort
2026-08-12 16:31   ` sashiko-bot
2026-08-13 13:16     ` Vincent Donnefort [this message]
2026-08-12 16:13 ` [PATCH v5 02/18] tracing/remotes: Release tracefs,eventfs on registration failure Vincent Donnefort
2026-08-12 16:25   ` sashiko-bot
2026-08-13 13:25     ` Vincent Donnefort
2026-08-12 16:13 ` [PATCH v5 03/18] tracing/remotes: Use kstrtobool for boolean tracefs files Vincent Donnefort
2026-08-12 16:13 ` [PATCH v5 04/18] tracing/remotes: Use a single per-remote polling work Vincent Donnefort
2026-08-12 16:13 ` [PATCH v5 05/18] tracing/simple_ring_buffer: Add support for compressed length Vincent Donnefort
2026-08-12 16:42   ` sashiko-bot
2026-08-13 14:00     ` Vincent Donnefort
2026-08-12 16:13 ` [PATCH v5 06/18] tracing/remotes: Add dmesg tracefs file Vincent Donnefort
2026-08-12 16:42   ` sashiko-bot
2026-08-13 14:02     ` Vincent Donnefort
2026-08-12 16:13 ` [PATCH v5 07/18] tracing/remotes: selftests: Add a test for the " Vincent Donnefort
2026-08-12 16:40   ` sashiko-bot
2026-08-13 14:06     ` Vincent Donnefort
2026-08-12 16:13 ` [PATCH v5 08/18] tracing/remotes: selftests: Prefix hypervisor folder Vincent Donnefort
2026-08-12 16:52   ` sashiko-bot
2026-08-12 16:13 ` [PATCH v5 09/18] ring-buffer: Use irqsave for the reader lock in ring_buffer_poll_remote Vincent Donnefort
2026-08-12 16:13 ` [PATCH v5 10/18] ring-buffer: Use panic-friendly locking in ring_buffer_iter interface Vincent Donnefort
2026-08-12 16:54   ` sashiko-bot
     [not found] ` <20260812161340.2417322-15-vdonnefort@google.com>
2026-08-12 17:02   ` [PATCH v5 14/18] tracing/remotes: selftests: Add a test for the dump_on_panic tracefs file sashiko-bot
     [not found] ` <20260812161340.2417322-14-vdonnefort@google.com>
2026-08-12 17:08   ` [PATCH v5 13/18] tracing/remotes: Add " sashiko-bot
     [not found] ` <20260812161340.2417322-17-vdonnefort@google.com>
2026-08-12 17:11   ` [PATCH v5 16/18] tracing/remotes: Add trace_remote cmdline options sashiko-bot
2026-08-13 14:21     ` Vincent Donnefort
     [not found] ` <20260812161340.2417322-16-vdonnefort@google.com>
2026-08-12 17:13   ` [PATCH v5 15/18] tracing/remotes: Add poll_ms tracefs file sashiko-bot
2026-08-13 14:20     ` Vincent Donnefort

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=an3DosTQoNFcOHs4@google.com \
    --to=vdonnefort@google.com \
    --cc=linux-trace-kernel@vger.kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox