From: Andrew Jones <ajones@ventanamicro.com>
To: Borislav Petkov <bp@alien8.de>
Cc: Jonas Bonn <jonas@southpole.se>,
linux-s390@vger.kernel.org,
Alexander Gordeev <agordeev@linux.ibm.com>,
Dave Hansen <dave.hansen@linux.intel.com>,
Vasily Gorbik <gor@linux.ibm.com>,
Yury Norov <yury.norov@gmail.com>,
Heiko Carstens <hca@linux.ibm.com>,
x86@kernel.org,
Linux Kernel Mailing List <linux-kernel@vger.kernel.org>,
Stefan Kristiansson <stefan.kristiansson@saunalahti.fi>,
openrisc@lists.librecores.org, Ingo Molnar <mingo@redhat.com>,
Palmer Dabbelt <palmer@dabbelt.com>,
Paul Walmsley <paul.walmsley@sifive.com>,
Stafford Horne <shorne@gmail.com>,
linux-riscv <linux-riscv@lists.infradead.org>,
"open list:LINUX FOR POWERPC PA SEMI PWRFICIENT"
<linuxppc-dev@lists.ozlabs.org>,
Thomas Gleixner <tglx@linutronix.de>,
Albert Ou <aou@eecs.berkeley.edu>
Subject: Re: [PATCH v3 2/2] x86: Fix /proc/cpuinfo cpumask warning
Date: Mon, 31 Oct 2022 11:03:27 +0100 [thread overview]
Message-ID: <20221031100327.r7tswmpszvs5ot5n@kamzik> (raw)
In-Reply-To: <Y1+OUawGJDjh4DOJ@zn.tnic>
On Mon, Oct 31, 2022 at 09:58:57AM +0100, Borislav Petkov wrote:
> On Mon, Oct 31, 2022 at 09:06:04AM +0100, Andrew Jones wrote:
> > The valid cpumask range is [0, nr_cpu_ids) and cpumask_next() always
> > returns a CPU ID greater than its input, which results in its input
> > range being [-1, nr_cpu_ids - 1). Ensure showing CPU info avoids
> > triggering error conditions in cpumask_next() by stopping its loop
>
> What error conditions?
>
> What would happen if @n is outside of the valid range?
Currently (after the revert of 78e5a3399421) with DEBUG_PER_CPU_MAPS we'll
get a warning splat when the cpu is outside the range [-1, nr_cpu_ids) and
cpumask_next() will call find_next_bit() with the input plus one anyway.
find_next_bit() doesn't explicity document what happens when an input is
outside the range, but it currently returns the bitmap size without any
side effects, which means cpumask_next() will return nr_cpu_ids.
show_cpuinfo() doesn't try to show anything in that case and stops its
loop, or, IOW, things work fine now with an input of nr_cpu_ids - 1. But,
show_cpuinfo() is just getting away with a violated cpumask_next()
contract, which 78e5a3399421 exposed. How about a new commit message like
this
seq_read_iter() and cpuinfo's start and next seq operations implement a
pattern like
n = cpumask_next(n - 1, mask);
show(n);
while (1) {
++n;
n = cpumask_next(n - 1, mask);
if (n >= nr_cpu_ids)
break;
show(n);
}
which loops until cpumask_next() identifies its CPU ID input is out of
its valid range, [-1, nr_cpu_ids - 1). seq_read_iter() assumes the
result of an invalid input is to return nr_cpu_ids or larger without any
side effects, however the cpumask API does not document that and it
reserves the right to change how it responds to invalid inputs. Ensure
inputs from seq_read_iter() are valid.
Thanks,
drew
next prev parent reply other threads:[~2022-10-31 10:04 UTC|newest]
Thread overview: 23+ messages / expand[flat|nested] mbox.gz Atom feed top
2022-10-14 15:58 [PATCH v3 0/2] Fix /proc/cpuinfo cpumask warning Andrew Jones
2022-10-14 15:58 ` [PATCH v3 1/2] RISC-V: " Andrew Jones
2022-10-14 15:58 ` [PATCH v3 2/2] x86: " Andrew Jones
2022-10-28 7:48 ` Andrew Jones
2022-10-28 14:46 ` Yury Norov
2022-10-28 15:03 ` Borislav Petkov
2022-10-28 15:13 ` Yury Norov
2022-10-28 16:06 ` Borislav Petkov
2022-10-31 8:06 ` Andrew Jones
2022-10-31 8:58 ` Borislav Petkov
2022-10-31 10:03 ` Andrew Jones [this message]
2022-11-02 18:44 ` Borislav Petkov
2022-11-03 12:59 ` Andrew Jones
2022-11-03 15:02 ` Borislav Petkov
2022-11-03 15:34 ` Andrew Jones
2022-11-03 15:54 ` Borislav Petkov
2022-11-03 16:30 ` yury.norov
2022-11-03 16:49 ` Borislav Petkov
2022-11-03 17:31 ` Yury Norov
2022-11-03 23:22 ` Borislav Petkov
2022-10-15 18:08 ` [PATCH v3 0/2] " Yury Norov
2022-10-27 23:07 ` Palmer Dabbelt
2022-10-28 7:40 ` Andrew Jones
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20221031100327.r7tswmpszvs5ot5n@kamzik \
--to=ajones@ventanamicro.com \
--cc=agordeev@linux.ibm.com \
--cc=aou@eecs.berkeley.edu \
--cc=bp@alien8.de \
--cc=dave.hansen@linux.intel.com \
--cc=gor@linux.ibm.com \
--cc=hca@linux.ibm.com \
--cc=jonas@southpole.se \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-riscv@lists.infradead.org \
--cc=linux-s390@vger.kernel.org \
--cc=linuxppc-dev@lists.ozlabs.org \
--cc=mingo@redhat.com \
--cc=openrisc@lists.librecores.org \
--cc=palmer@dabbelt.com \
--cc=paul.walmsley@sifive.com \
--cc=shorne@gmail.com \
--cc=stefan.kristiansson@saunalahti.fi \
--cc=tglx@linutronix.de \
--cc=x86@kernel.org \
--cc=yury.norov@gmail.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox