mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* [PATCH] scripts/gdb: Fix radix tree lookup pointer handling
@ 2026-10-07  9:31 Ting-Han Hou
  2026-10-09 18:10 ` Ting-Han Hou
  2026-10-10 21:17 ` Andrew Morton
  0 siblings, 2 replies; 7+ messages in thread
From: Ting-Han Hou @ 2026-10-07  9:31 UTC (permalink / raw)
  To: Jan Kiszka, Kieran Bingham; +Cc: linux-kernel

From: Ting-Han Hou <ue081723@gmail.com>

lookup() casts each slot to a pointer to a node pointer and then
dereferences it. Since the slot already contains an entry pointer,
this reads the entry's contents as another pointer instead of
returning the entry itself.

Internal entries also need their tag bits removed before descending
to the next node.

Return non-internal entries directly and use entry_to_node() when
descending through internal entries. Remove the explicit shift
counter, as traversal now follows the entry type.

Fixes: b7235d6bb516 ("scripts/gdb: add a Radix Tree Parser")
Assisted-by: LLM
Signed-off-by: Ting-Han Hou <ue081723@gmail.com>
---
Tested with GDB 15.1 against standalone GCC-built C fixtures using the
xarray/xa_node field layout, with XA_CHUNK_SHIFT=4 and 6. These are
synthetic debugger fixtures, not a booted kernel or a kernel core dump.

Before the fix, a one-level lookup returned the payload 0x12345678
instead of its address; a two-level lookup missed a populated slot.
After the fix, all 33 checks passed for each slot configuration (66
total), including empty/direct roots, one- to three-level trees,
zero-filled payloads, value entries, absent/out-of-range indices,
struct/pointer roots, and the GDB convenience function.

This does not test multi-index entries or concurrent updates/retry
entries. The change is limited to the debugger lookup helper.

 scripts/gdb/linux/radixtree.py |   15 +++------------
 1 file changed, 3 insertions(+), 12 deletions(-)

diff --git a/scripts/gdb/linux/radixtree.py b/scripts/gdb/linux/radixtree.py
--- a/scripts/gdb/linux/radixtree.py
+++ b/scripts/gdb/linux/radixtree.py
@@ -55,24 +55,15 @@
     if (index > maxindex):
         return None

-    shift = node['shift'] + constants.LX_RADIX_TREE_MAP_SHIFT
-
     while True:
         offset = (index >> node['shift']) & constants.LX_RADIX_TREE_MAP_MASK
         slot = node['slots'][offset]

         if slot == 0:
             return None
-
-        node = slot.cast(node.type.pointer()).dereference()
-        if node == 0:
-            return None
-
-        shift -= constants.LX_RADIX_TREE_MAP_SHIFT
-        if (shift <= 0):
-            break
-
-    return node
+        if not is_internal_node(slot):
+            return slot
+        node = entry_to_node(slot)

 def descend(parent, index):
     offset = (index >> int(parent["shift"])) & constants.LX_RADIX_TREE_MAP_MASK

^ permalink raw reply	[flat|nested] 7+ messages in thread

end of thread, other threads:[~2026-10-11  3:59 UTC | newest]

Thread overview: 7+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-10-07  9:31 [PATCH] scripts/gdb: Fix radix tree lookup pointer handling Ting-Han Hou
2026-10-09 18:10 ` Ting-Han Hou
2026-10-10 21:17 ` Andrew Morton
2026-10-11  2:30   ` [PATCH v2 0/2] scripts/gdb: fix radix tree lookup and stack depot diagnostic Ting-Han Hou
2026-10-11  2:30     ` [PATCH v2 1/2] scripts/gdb: Fix radix tree lookup pointer handling Ting-Han Hou
2026-10-11  2:30     ` [PATCH v2 2/2] scripts/gdb: Fix stack depot out-of-bounds diagnostic Ting-Han Hou
2026-10-11  3:58     ` [PATCH v2 0/2] scripts/gdb: fix radix tree lookup and stack depot diagnostic Andrew Morton

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®