mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Yeoreum Yun" <yeoreum.yun@arm.com>
Cc: linux-kernel@vger.kernel.org, linux-rt-devel@lists.linux.dev
Subject: Re: [PATCH v13 01/14] coresight: etm4x: read-back TRCSEQSTR at disabling and prohibit modifying seq_state while enabling.
Date: Sat, 03 Oct 2026 01:33:45 +0000	[thread overview]
Message-ID: <20261003013345.9CAB71F000FF@smtp.kernel.org> (raw)
In-Reply-To: <20261002-separate_etm_cfg_v2-v13-1-fe429d8d96fb@arm.com>

Thank you for your contribution! Sashiko AI review found 2 potential issue(s) to consider:
- [High] null-deref: NULL pointer dereference in seq_state_store() during probe
- [Medium] race: TOCTOU race in seq_state_store() due to missing spinlock
--

commit be18b7cdd3b23e4d67d68cc4591ca50a52fb8ee1
Author: Yeoreum Yun <yeoreum.yun@arm.com>

coresight: etm4x: read-back TRCSEQSTR at disabling and prohibit modifying seq_state while enabling.

This commit copies the TRCSEQSTR value when disabling a sysfs session. It also
prohibits modifying seq_state while the sysfs session is active to prevent
those changes from being lost when the session is disabled.

> diff --git a/drivers/hwtracing/coresight/coresight-etm4x-sysfs.c b/drivers/hwtracing/coresight/coresight-etm4x-sysfs.c
> index cc6cdd3ae29d5..2c72ea831fe65 100644
> --- a/drivers/hwtracing/coresight/coresight-etm4x-sysfs.c
> +++ b/drivers/hwtracing/coresight/coresight-etm4x-sysfs.c
> @@ -1435,6 +1435,8 @@ static ssize_t seq_state_store(struct device *dev,
>  
>  	if (kstrtoul(buf, 16, &val))
>  		return -EINVAL;
> +	if (IS_ERR_OR_NULL(drvdata) || coresight_get_mode(drvdata->csdev))

[Severity: High]
Is there a risk of a NULL pointer dereference on drvdata->csdev during device
probe?

coresight_register() exposes sysfs files via device_register() before
returning the csdev pointer to etm4_probe(). If a user process accesses
the seq_state sysfs file during this window, drvdata->csdev will still
be NULL.

Because IS_ERR_OR_NULL(drvdata) does not check drvdata->csdev, calling
coresight_get_mode(drvdata->csdev) may dereference a NULL pointer.

> +		return -EBUSY;
>  	if (val >= drvdata->nrseqstate)
>  		return -EINVAL;
>  
>  	config->seq_state = val;

[Severity: Medium]
Could this assignment result in a TOCTOU race condition?

The mode check and assignment are performed without taking drvdata->spinlock.
If a user writes to the seq_state sysfs file while another thread
simultaneously enables the trace session, the lockless assignment could
overwrite the state even if the session becomes active.

Other store functions in this driver correctly use
raw_spin_lock(&drvdata->spinlock) when modifying configuration state.

>  	return size;
>  }

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20261002-separate_etm_cfg_v2-v13-0-fe429d8d96fb@arm.com?part=1

  reply	other threads:[~2026-10-03  1:33 UTC|newest]

Thread overview: 28+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-10-02 19:03 [PATCH v13 00/14] fix several inconsistencies with sysfs configuration in etmX Yeoreum Yun
2026-10-02 19:03 ` [PATCH v13 01/14] coresight: etm4x: read-back TRCSEQSTR at disabling and prohibit modifying seq_state while enabling Yeoreum Yun
2026-10-03  1:33   ` sashiko-bot [this message]
2026-10-03  1:47     ` Yeoreum Yun
2026-10-02 19:03 ` [PATCH v13 02/14] coresight: etm4x: prohibit modifying cntr_val while session is enabled Yeoreum Yun
2026-10-03  1:33   ` sashiko-bot
2026-10-03  1:50     ` Yeoreum Yun
2026-10-02 19:03 ` [PATCH v13 03/14] coresight: etm3x: prohibit modifying cntr_val and reset " Yeoreum Yun
2026-10-03  1:33   ` sashiko-bot
2026-10-03  2:02     ` Yeoreum Yun
2026-10-02 19:03 ` [PATCH v13 04/14] coresight: etm4x: fix inconsistencies with sysfs configuration Yeoreum Yun
2026-10-03  1:33   ` sashiko-bot
2026-10-03  2:30     ` Yeoreum Yun
2026-10-02 19:03 ` [PATCH v13 05/14] coresight: etm3x: " Yeoreum Yun
2026-10-03  1:33   ` sashiko-bot
2026-10-03  2:47     ` Yeoreum Yun
2026-10-02 19:03 ` [PATCH v13 06/14] coresight: etm3x: remove redundant cpu online check on etm_enable_sysfs() Yeoreum Yun
2026-10-02 19:03 ` [PATCH v13 07/14] coresight: etm4x: introduce struct etm4_caps Yeoreum Yun
2026-10-02 19:03 ` [PATCH v13 08/14] coresight: etm4x: exclude ss_status from drvdata->config Yeoreum Yun
2026-10-03  1:33   ` sashiko-bot
2026-10-03  2:38     ` Yeoreum Yun
2026-10-02 19:03 ` [PATCH v13 09/14] coresight: etm4x: remove s_ex_level from config Yeoreum Yun
2026-10-02 19:03 ` [PATCH v13 10/14] coresight: etm4x: rename local config as curr_config referring drvdata->curr_config Yeoreum Yun
2026-10-02 19:03 ` [PATCH v13 11/14] coresight: etm4x: rename drvdata->config to sysfs_config Yeoreum Yun
2026-10-02 19:03 ` [PATCH v13 12/14] coresight: etm3x: introduce struct etm_caps Yeoreum Yun
2026-10-02 19:03 ` [PATCH v13 13/14] coresight: etm3x: rename local config as curr_config referring drvdata->curr_config Yeoreum Yun
2026-10-02 19:03 ` [PATCH v13 14/14] coresight: etm3x: rename drvdata->config to sysfs_config Yeoreum Yun
2026-10-03  2:49 ` [PATCH v13 00/14] fix several inconsistencies with sysfs configuration in etmX Yeoreum Yun

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20261003013345.9CAB71F000FF@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=linux-rt-devel@lists.linux.dev \
    --cc=sashiko-reviews@lists.linux.dev \
    --cc=yeoreum.yun@arm.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®