mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Yeoreum Yun" <yeoreum.yun@arm.com>
Cc: linux-kernel@vger.kernel.org, linux-rt-devel@lists.linux.dev
Subject: Re: [PATCH RESEND v13 03/14] coresight: etm3x: prohibit modifying cntr_val and reset while session is enabled
Date: Sat, 03 Oct 2026 03:06:38 +0000	[thread overview]
Message-ID: <20261003030639.07A511F000FF@smtp.kernel.org> (raw)
In-Reply-To: <20261003-separate_etm_cfg_v2-v13-3-5d8a29aead95@arm.com>

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [High] coresight: etm3x: TOCTOU race in reset_store() allows trace ID release during active session
--

commit e2e191629dd66da8998d4646f82c1d5c193cb283
Author: Yeoreum Yun <yeoreum.yun@arm.com>

coresight: etm3x: prohibit modifying cntr_val and reset while session is enabled
    
This commit adds checks to prohibit modifying cntr_val and calling reset while
a trace session is enabled by returning -EBUSY.

> diff --git a/drivers/hwtracing/coresight/coresight-etm3x-sysfs.c b/drivers/hwtracing/coresight/coresight-etm3x-sysfs.c
> index b3c67e96a82a4..cdb70a4382eb8 100644
> --- a/drivers/hwtracing/coresight/coresight-etm3x-sysfs.c
> +++ b/drivers/hwtracing/coresight/coresight-etm3x-sysfs.c
> @@ -75,6 +75,10 @@ static ssize_t reset_store(struct device *dev,
>  	if (ret)
>  		return ret;
>  
> +	if (IS_ERR_OR_NULL(drvdata->csdev) ||
> +	    coresight_get_mode(drvdata->csdev))
> +		return -EBUSY;
> +
>  	if (val) {
>  		spin_lock(&drvdata->spinlock);

[Severity: High]
Does this code introduce a Time-of-Check to Time-of-Use (TOCTOU) race?

Since coresight_get_mode() is checked outside drvdata->spinlock, a concurrent
sysfs write to enable_source could start a trace session (allocating a trace
ID and starting the hardware tracer) immediately after the mode check passes.

Once reset_store() acquires the spinlock, it will unconditionally zero the
sysfs configuration and call etm_release_trace_id().

Releasing the trace ID while the hardware tracer is actively emitting packets
returns the ID to the global pool. Another source might subsequently allocate
the same trace ID, leading to collisions at the CoreSight sink and
unrecoverable trace data corruption. This structural race condition appears
to remain unfixed through the end of the patch series.

>  		memset(config, 0, sizeof(struct etm_config));

[ ... ]

> @@ -744,6 +748,9 @@ static ssize_t cntr_val_store(struct device *dev,
>  	ret = kstrtoul(buf, 16, &val);
>  	if (ret)
>  		return ret;
> +	if (IS_ERR_OR_NULL(drvdata->csdev) ||
> +	    coresight_get_mode(drvdata->csdev))
> +		return -EBUSY;
>  
>  	spin_lock(&drvdata->spinlock);

[Severity: High]
Could the same TOCTOU race pattern apply here as well?

If a trace session is concurrently enabled right after the mode check, the
counter value could be modified while the session is active, resulting in a
lost sysfs write.

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20261003-separate_etm_cfg_v2-v13-0-5d8a29aead95@arm.com?part=3

  reply	other threads:[~2026-10-03  3:06 UTC|newest]

Thread overview: 27+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-10-03  2:52 [PATCH RESEND v13 00/14] fix several inconsistencies with sysfs configuration in etmX Yeoreum Yun
2026-10-03  2:52 ` [PATCH RESEND v13 01/14] coresight: etm4x: read-back TRCSEQSTR at disabling and prohibit modifying seq_state while enabling Yeoreum Yun
2026-10-03  3:08   ` sashiko-bot
2026-10-03  3:44     ` Yeoreum Yun
2026-10-03  6:07   ` Suzuki K Poulose
2026-10-03  2:52 ` [PATCH RESEND v13 02/14] coresight: etm4x: prohibit modifying cntr_val while session is enabled Yeoreum Yun
2026-10-03  3:06   ` sashiko-bot
2026-10-03  4:29     ` Yeoreum Yun
2026-10-03  2:52 ` [PATCH RESEND v13 03/14] coresight: etm3x: prohibit modifying cntr_val and reset " Yeoreum Yun
2026-10-03  3:06   ` sashiko-bot [this message]
2026-10-03  4:34     ` Yeoreum Yun
2026-10-03  6:10   ` Suzuki K Poulose
2026-10-03  2:52 ` [PATCH RESEND v13 04/14] coresight: etm4x: fix inconsistencies with sysfs configuration Yeoreum Yun
2026-10-03  3:06   ` sashiko-bot
2026-10-03  4:40     ` Yeoreum Yun
2026-10-03  2:52 ` [PATCH RESEND v13 05/14] coresight: etm3x: " Yeoreum Yun
2026-10-03  2:52 ` [PATCH RESEND v13 06/14] coresight: etm3x: remove redundant cpu online check on etm_enable_sysfs() Yeoreum Yun
2026-10-03  2:52 ` [PATCH RESEND v13 07/14] coresight: etm4x: introduce struct etm4_caps Yeoreum Yun
2026-10-03  2:52 ` [PATCH RESEND v13 08/14] coresight: etm4x: exclude ss_status from drvdata->config Yeoreum Yun
2026-10-03  2:52 ` [PATCH RESEND v13 09/14] coresight: etm4x: remove s_ex_level from config Yeoreum Yun
2026-10-03  6:14   ` Suzuki K Poulose
2026-10-03  2:52 ` [PATCH RESEND v13 10/14] coresight: etm4x: rename local config as curr_config referring drvdata->curr_config Yeoreum Yun
2026-10-03  2:52 ` [PATCH RESEND v13 11/14] coresight: etm4x: rename drvdata->config to sysfs_config Yeoreum Yun
2026-10-03  2:52 ` [PATCH RESEND v13 12/14] coresight: etm3x: introduce struct etm_caps Yeoreum Yun
2026-10-03  2:52 ` [PATCH RESEND v13 13/14] coresight: etm3x: rename local config as curr_config referring drvdata->curr_config Yeoreum Yun
2026-10-03  2:52 ` [PATCH RESEND v13 14/14] coresight: etm3x: rename drvdata->config to sysfs_config Yeoreum Yun
2026-10-03  6:56 ` [PATCH RESEND v13 00/14] fix several inconsistencies with sysfs configuration in etmX Suzuki K Poulose

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20261003030639.07A511F000FF@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=linux-rt-devel@lists.linux.dev \
    --cc=sashiko-reviews@lists.linux.dev \
    --cc=yeoreum.yun@arm.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®