From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-wm1-f48.google.com (mail-wm1-f48.google.com [209.85.128.48]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id A717239D6E9 for ; Sat, 25 Jul 2026 10:00:16 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.128.48 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784973618; cv=none; b=N7Yu3eTo1iDv7iTKpcySmX4OZ8ASfxPm8S42+91kFsqOyItxKp/yWQS8KQ03Y+8TaGGKOMfhPhSOWQy+7GkIdBlFw5ZhoK2y/Ug8qLjPXncKnY1naX6qCRnwIpvNkitO7rwYO190p586FqU+ot5bqelPHTbABagO042qpQutKG4= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784973618; c=relaxed/simple; bh=R9+eHSSRaNSMn5gfAQa4T+nJmQ3AaUjOI/z3OxupB/w=; h=Date:From:To:Cc:Subject:Message-ID:In-Reply-To:References: MIME-Version:Content-Type; b=bMx4oQw7kPAlvr13a0FarnCn4PPBnhBtMvpSofLqMxwJRV/gcpBts7HOGryOGMxQgczJ66IexZQlGZrdl6G592ohzx/cXb4/WGTxEJYoNx68vrqaFw/s1+7FAeki78Ikc/ySTIA7mwmWoRc1JjkdFaq058NV492o6Ul9XR23i48= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=Kl7+eY5e; arc=none smtp.client-ip=209.85.128.48 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="Kl7+eY5e" Received: by mail-wm1-f48.google.com with SMTP id 5b1f17b1804b1-493f6de72faso9867865e9.0 for ; Sat, 25 Jul 2026 03:00:16 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1784973615; x=1785578415; darn=vger.kernel.org; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:subject:cc:to:from:date:from:to:cc:subject :date:message-id:reply-to:content-type; bh=Yd+jk16uLDBllgEthpdyLs2rszBLLyqW9n9CRNG4JS8=; b=Kl7+eY5edBMHTlZigB3Ji/wMlDubAM48Hx9ca4M2TpBET7wYE5/E9cFnpY1HsqFTsQ fUw4KV8+dmmgTCHq0WOqxdw3SBCPUfW+d1tux7wZLaLWLDTHYMAIg5X7ZxVuhK9bEdb4 I3uvCkdrGLKiD/GlBw/cmykhxBW1M8WdZql/rVe50P6YWI0AnaJONewRhlPlqmX4aFCe qtDaEx1UyG9lXjPPgmHKjVh4mkCRAS2gTaJ7bKCmRUXB86xYHMBUnbvlGgyfBwxi9LWa xVR+RNLizT7ye57b4CgBQAW71NfFPff/6+4vknK2vcF21BQI6et6sq+R44s9JJxbTvhB Wkxg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784973615; x=1785578415; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:subject:cc:to:from:date:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=Yd+jk16uLDBllgEthpdyLs2rszBLLyqW9n9CRNG4JS8=; b=diVhGnQmWPRaVdAUKw4pp/WxM4XzRU8caqnAqknhXSA4rB79l2f3GYvi7g69MuJr++ 2YitML12w6GBizJfxCYpQKVTfFQ9Y5HiJfsoTsqKjmARDSj+eObq19hqRxkNOWXc/OpN pr9pBUARU0AW0UuXz/M8OgF6YvYxYyUgf08CTVPZkZso+z4XBysulhX9kAmSqWoYFKh9 Vw6Yd+JKWxyfmWOCUmsh59gMdYDy+2p+a5JM7K2C9xE/qfVJtO+ZZzEhOjobXZKA7iCe HK/pFLhk7UQLDhnIHhDjZ+s5C/dZakw2tiUetjpjn2lmkMQ3tX9wCo1iY94AJdiGYTOE ZRjw== X-Gm-Message-State: AOJu0YzMqrESdBVlvfGqJ1Oeh/KKDlmHNfq1Jb3fPDaRxZCUD717FUzL nklm9BTFWnAZhR817K4DIffHZJXVJ6zAY5FRehvftA+gpPYokm3WPSAD X-Gm-Gg: AR+sD10rkU4ok4BZ9UJJEVyNjIiaI+V7xwWACnscEcCb+Dewz9TcvgG2FaM+p5K2ehc +wSzzR2+C8umCKALXuQRdl54YRI7ZKSGMusXAVvMzl7k0VLb4NXaJPs1z3cmxEDycmUyNye8rLN F+NshbwSDAsQIpipKYPSuD4hX2IFstKle6q6C7ihgQDUQeqS+HywR6+Ym4LEsQBRRSf/BnUyMXh JkZ0ZAnzp9c44num6b+QMzWubebQ9CJrM76s41V1N6gncwx6mY2EOs010wiZnw3ssk/Drw0RZ3v erzVLvbfP0/3I6H4jpMZ3PiFzz70UdvJRhLDmgbC8xSwkw4i8Y1lrWn9xb49Vx1l329AFDvpPe7 oD43BVhPZbu9sv3hS1sMQG9MkhsYwlVNjszEyBL99fgZpwbEyw6uOLkk5MbZlr9ml4fFCpeTFrT sszQ4k5rVikC+0iVLKzq2EUvNU/Ak7fv5LHMor0TubzDkp1VgrTg== X-Received: by 2002:a05:600c:4f89:b0:495:501a:fcf8 with SMTP id 5b1f17b1804b1-496b5c7181emr20673975e9.9.1784973614526; Sat, 25 Jul 2026 03:00:14 -0700 (PDT) Received: from pumpkin (82-69-66-36.dsl.in-addr.zen.co.uk. [82.69.66.36]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-496b4ed6b76sm57502545e9.2.2026.07.25.03.00.13 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sat, 25 Jul 2026 03:00:13 -0700 (PDT) Date: Sat, 25 Jul 2026 11:00:12 +0100 From: David Laight To: Steven Rostedt Cc: linux-kernel@vger.kernel.org, Masami Hiramatsu , Mark Rutland , Mathieu Desnoyers , Andrew Morton , stable@vger.kernel.org, Fuad Tabba , Vincent Donnefort Subject: Re: [for-linus][PATCH 1/9] tracing/remotes: Fix page_va[] access before counter update in trace_remote_alloc_buffer() Message-ID: <20260725110012.2962b76c@pumpkin> In-Reply-To: <20260724231855.591578614@kernel.org> References: <20260724231840.483353969@kernel.org> <20260724231855.591578614@kernel.org> X-Mailer: Claws Mail 4.1.1 (GTK 3.24.38; arm-unknown-linux-gnueabihf) Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset=US-ASCII Content-Transfer-Encoding: 7bit On Fri, 24 Jul 2026 19:18:41 -0400 Steven Rostedt wrote: > From: Fuad Tabba > > page_va[] is annotated __counted_by(nr_page_va), so nr_page_va must > cover an index before that element is accessed. The allocation loop > writes page_va[id] while nr_page_va is still id and increments it only > afterwards, so every write is one element past the declared count. > > The store is out of bounds with respect to the annotation: a build with > CONFIG_UBSAN_BOUNDS on a toolchain that honours __counted_by > (clang >= 20.1, gcc >= 15.1) flags it as an array-index overflow. > > Increment nr_page_va before writing the element it now covers. A failed > allocation then leaves the slot counted but NULL; the error path frees > it with free_page(0), which is a no-op. Uggg... Shouldn't the __counted_by() field be the size of the array itself, not the number of valid items? David > > Cc: stable@vger.kernel.org > Link: https://patch.msgid.link/20260713072823.2668323-1-fuad.tabba@linux.dev > Fixes: 96e43537af546 ("tracing: Introduce trace remotes") > Signed-off-by: Fuad Tabba > Reviewed-by: Vincent Donnefort > Tested-by: Vincent Donnefort > Signed-off-by: Steven Rostedt > --- > kernel/trace/trace_remote.c | 3 +-- > 1 file changed, 1 insertion(+), 2 deletions(-) > > diff --git a/kernel/trace/trace_remote.c b/kernel/trace/trace_remote.c > index 0f6ef5c36d84..ef42d9c38b37 100644 > --- a/kernel/trace/trace_remote.c > +++ b/kernel/trace/trace_remote.c > @@ -1004,11 +1004,10 @@ int trace_remote_alloc_buffer(struct trace_buffer_desc *desc, size_t desc_size, > desc->nr_cpus++; > > for (id = 0; id < nr_pages; id++) { > + rb_desc->nr_page_va++; > rb_desc->page_va[id] = (unsigned long)__get_free_page(GFP_KERNEL); > if (!rb_desc->page_va[id]) > goto err; > - > - rb_desc->nr_page_va++; > } > rb_desc = __next_ring_buffer_desc(rb_desc); > }