From: David Laight <david.laight.linux@gmail.com>
To: Gui-Dong Han <hanguidong02@gmail.com>
Cc: linux@roeck-us.net, linux-hwmon@vger.kernel.org,
linux-kernel@vger.kernel.org, baijiaju1990@gmail.com
Subject: Re: [PATCH] hwmon: submitting-patches: Explain race conditions caused by calculations in macros
Date: Tue, 2 Dec 2025 19:43:17 +0000 [thread overview]
Message-ID: <20251202194317.555d0911@pumpkin> (raw)
In-Reply-To: <20251202175536.12774-1-hanguidong02@gmail.com>
On Wed, 3 Dec 2025 01:55:36 +0800
Gui-Dong Han <hanguidong02@gmail.com> wrote:
> The current documentation advises against calculations in macros
> primarily to avoid code obfuscation. It misses the risk of concurrency
> issues.
>
> Add a note explaining that macros evaluating arguments multiple times
> can lead to race conditions when accessing shared data.
>
> Link: https://lore.kernel.org/all/CALbr=LYJ_ehtp53HXEVkSpYoub+XYSTU8Rg=o1xxMJ8=5z8B-g@mail.gmail.com/
> Signed-off-by: Gui-Dong Han <hanguidong02@gmail.com>
> ---
> Documentation/hwmon/submitting-patches.rst | 5 ++++-
> 1 file changed, 4 insertions(+), 1 deletion(-)
>
> diff --git a/Documentation/hwmon/submitting-patches.rst b/Documentation/hwmon/submitting-patches.rst
> index 6482c4f137dc..7f7095951750 100644
> --- a/Documentation/hwmon/submitting-patches.rst
> +++ b/Documentation/hwmon/submitting-patches.rst
> @@ -82,7 +82,10 @@ increase the chances of your change being accepted.
> * Avoid calculations in macros and macro-generated functions. While such macros
> may save a line or so in the source, it obfuscates the code and makes code
> review more difficult. It may also result in code which is more complicated
> - than necessary. Use inline functions or just regular functions instead.
> + than necessary. Such macros may also evaluate their arguments multiple times.
> + This leads to Time-of-Check to Time-of-Use (TOCTOU) race conditions when
> + accessing shared data without locking, for example when calculating values in
> + sysfs show functions. Use inline functions or just regular functions instead.
That is only half the story.
#defines are fine - provided they are written properly.
The main issue isn't TOCTOU, but just calls like foo(*arg++).
It is important that side effects of arguments only happen once.
So it is important that #defines don't evaluate their arguments more than once.
That is the real issue.
If you are reading shared data without locks there are much bigger problems
if it really matters that you get a valid value (see READ_ONCE()).
David
>
> * Limit the number of kernel log messages. In general, your driver should not
> generate an error message just because a runtime operation failed. Report
next prev parent reply other threads:[~2025-12-02 19:43 UTC|newest]
Thread overview: 3+ messages / expand[flat|nested] mbox.gz Atom feed top
2025-12-02 17:55 Gui-Dong Han
2025-12-02 19:43 ` David Laight [this message]
2025-12-05 4:05 ` Guenter Roeck
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20251202194317.555d0911@pumpkin \
--to=david.laight.linux@gmail.com \
--cc=baijiaju1990@gmail.com \
--cc=hanguidong02@gmail.com \
--cc=linux-hwmon@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux@roeck-us.net \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®