From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-pg1-f202.google.com (mail-pg1-f202.google.com [209.85.215.202]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id BD0522F549C for ; Thu, 9 Apr 2026 18:29:45 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.215.202 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1775759386; cv=none; b=ntnJ19PAueV08u/b0q/uYNXbrLsc+HgOyTEvGldSjhk9n/NJDoffCAJkhya0T/4j4gOPXOEWYwTfayRL1OSzyrGxItGIlI8OAFBQvQK8M2xN59fc4zqjJ0O0tm2bid/NgjsBaFRp5fpm2/9y2yGzaRHWSterwCdeNSk+PXRYITY= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1775759386; c=relaxed/simple; bh=bH0poclTHVIIo1emHkK1x2hq8XVz66E3qtLSSP9rpW0=; h=Date:Mime-Version:Message-ID:Subject:From:To:Cc:Content-Type; b=TmFHrd0iZorcQv77GxX9o7zpu8Z7aTP4OXnu4C3X363fAO58cIh/HNq5lmNfSZ+FxbP7ffRrLzyfiNDz+oHI77Z7JiG8vEBaP1UdMhre6u+8UwUQo7LUXe1xHo7fstWDDsRMFg9ifDjnUQ4P2htlUNsUNS/CjAWDAvu7zd40EiU= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com; spf=pass smtp.mailfrom=flex--seanjc.bounces.google.com; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b=DCV0IU4h; arc=none smtp.client-ip=209.85.215.202 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=flex--seanjc.bounces.google.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b="DCV0IU4h" Received: by mail-pg1-f202.google.com with SMTP id 41be03b00d2f7-c76b6db8bb2so1050779a12.3 for ; Thu, 09 Apr 2026 11:29:45 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20251104; t=1775759385; x=1776364185; darn=vger.kernel.org; h=cc:to:from:subject:message-id:mime-version:date:reply-to:from:to:cc :subject:date:message-id:reply-to; bh=mq38IKP064dX+fVfM5O2xnmPvNbtiH2Ru9kG9Z0ukv8=; b=DCV0IU4hyRq3xxu/E0Rm6vfg8wBdEOpflsz8ERseZO36JIiIu9bxsQqwq3fH58jHim OcZcnuxk6d+c/9I4DSY+PczlqSM/ynw6K+/V9Euzxl49A8tahWnQEz79PY5BAzjc3014 FCosqvyfnKcDDwIeUTEbqneF1mY7e1WkBYjeVDqoFm1qrJy2eA3rw5IoKb3mRIOoF0Nb GM8sqErGDfYZWpuip0LOCb9hBZJcxm4ij5Cqv36mBLR79Wp0HJD7bf4/kGu1O+x2/ENe a6QbEvaAHV7F2fodW+Z+8UOphaGCtkKaMdcMHauju9/QusRmaSYYdBd3AU2EgsNAWzRZ qPqA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1775759385; x=1776364185; h=cc:to:from:subject:message-id:mime-version:date:reply-to :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to; bh=mq38IKP064dX+fVfM5O2xnmPvNbtiH2Ru9kG9Z0ukv8=; b=lvWzVhOdAX86uHcxL631yvdOsk/yN4iT9tg1vluG1O7w0qNlcht0h8wkdeHKLKICqT lYw+9yXzyAUZIN05CsjUSfqVtz+hkjrbUe6P5mGU6tkdXZbCPIOYdlu6Bs8qVpVlfRPD wkUOzpc7ZrxPpzm+4kbPW2rsDwfdM9YhKR+EWBveTz4HnyLC4qedrdP5pvCPmDPF/VTu WvZuXsQyJr3e1Sf8dN64f11BxAe6H6uOhNIwd6JZafQfp4JKFWGT/WGmSaRWT66NDJYo PDGGrXr8S0zYK2UVYE9kY+F+172nZm5Zcf41f67aRG9uu6j2DFrpW2ehuCpeIY57YP3B mZig== X-Gm-Message-State: AOJu0YwlfRuVyIe0unKKM4T8QrLkW6gMjhei8REx6+5cs4leFj4gfEh8 /HmoA5+zvuLKyJdrdmFLZveiHAzOdEOvDG36NaoUnTCjVaS5MnaOL3wtHJ9SNOFozy0dyGZLbhI m0QlGCw== X-Received: from pfqy15.prod.google.com ([2002:aa7:9e0f:0:b0:824:9ab3:ebe8]) (user=seanjc job=prod-delivery.src-stubby-dispatcher) by 2002:a05:6a00:4601:b0:82c:212a:8023 with SMTP id d2e1a72fcca58-82f0c12fe20mr319867b3a.11.1775759384933; Thu, 09 Apr 2026 11:29:44 -0700 (PDT) Reply-To: Sean Christopherson Date: Thu, 9 Apr 2026 11:29:41 -0700 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 X-Mailer: git-send-email 2.53.0.1213.gd9a14994de-goog Message-ID: <20260409182941.1912856-1-seanjc@google.com> Subject: [PATCH] x86/bug: Add printf() validation to HAVE_ARCH_BUG_FORMAT_ARGS WARNs From: Sean Christopherson To: Thomas Gleixner , Ingo Molnar , Borislav Petkov , Dave Hansen , x86@kernel.org Cc: linux-kernel@vger.kernel.org, Yan Zhao , Peter Zijlstra , Sean Christopherson Content-Type: text/plain; charset="UTF-8" Add explicit printf() validation for x86-64's newfangled WARN implementation, as most (all?) compilers fail to detect basic formatting issues without the annotation. Lack of validation is especially problematic for code that is 64-bit-only, as blatant goofs can easily go unnoticed. Cc: Yan Zhao Cc: Peter Zijlstra (Intel) Link: https://lore.kernel.org/all/adc1IrD8uqWdaOKv@yzhao56-desk.sh.intel.com Fixes: 5b472b6e5bd9 ("x86_64/bug: Implement __WARN_printf()") Fixes: 11bb4944f014 ("x86/bug: Implement WARN_ONCE()") Signed-off-by: Sean Christopherson --- This is *very* lightly tested. Yan reported a bug against a commit in the kvm-x86 tree (see the link) where I botched the formatting of a WARN_ONCE() argument, but none of my builds (with W=1 and -Werror) detected the issue, nor did any of the build bots (AFAIK). I'm not entirely sure how Yan managed to trigger the diagnostic, but it's easy to observe the lack of validation by creating a malformed WARN/WARN_ONCE, and then toggling HAVE_ARCH_BUG_FORMAT_ARGS. Thankfully, it looks like my goof is the only one that has snuck in (and I need to rebase that commit anyways). arch/x86/include/asm/bug.h | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/arch/x86/include/asm/bug.h b/arch/x86/include/asm/bug.h index 80c1696d8d59..29b7dad4d5ef 100644 --- a/arch/x86/include/asm/bug.h +++ b/arch/x86/include/asm/bug.h @@ -153,6 +153,9 @@ struct arch_va_list { struct sysv_va_list args; }; extern void *__warn_args(struct arch_va_list *args, struct pt_regs *regs); +static __always_inline __printf(1, 2) void __WARN_validate_printf(const char *fmt, ...) { } +#else +#define __WARN_validate_printf(fmt, ...) #endif /* __ASSEMBLER__ */ #define __WARN_bug_entry(flags, format) ({ \ @@ -172,6 +175,7 @@ extern void *__warn_args(struct arch_va_list *args, struct pt_regs *regs); #define __WARN_print_arg(flags, format, arg...) \ do { \ int __flags = (flags) | BUGFLAG_WARNING | BUGFLAG_ARGS ; \ + __WARN_validate_printf(format, ## arg); \ static_call_mod(WARN_trap)(__WARN_bug_entry(__flags, format), ## arg); \ asm (""); /* inhibit tail-call optimization */ \ } while (0) base-commit: c9904c53ca958b5ebf5165dd1705c52f6afc2b2f -- 2.53.0.1213.gd9a14994de-goog