From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from foss.arm.com (foss.arm.com [217.140.110.172]) by smtp.subspace.kernel.org (Postfix) with ESMTP id A4A6834F48B for ; Mon, 23 Feb 2026 09:50:45 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=217.140.110.172 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1771840246; cv=none; b=WeElruGB6Hrie8Ok6h6Z8Nl2K/DcngP2B3hY0i9CcJn+k2d32RfxcwAhowP8/MnCRgVntiEh0I2Vfja96b5tnlHiMnOzjeIIfFihj3SK6DMpjPktX8dDZpDz9e0vSzGW2YcNI3ywV+hz1u3nO+EzlZv2fgkxc5IArT5CI+8fRgE= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1771840246; c=relaxed/simple; bh=NVxT24wBHj6PILyxA3JE/FqTOjc5SyA+KOuHyQV0qjI=; h=Message-ID:Date:MIME-Version:Subject:To:Cc:References:From: In-Reply-To:Content-Type; b=ItGhMA/jHzYaC6zrP1Zi/iF/CM7KdfsLsrfeQMNUtUz17hHAw0OIvuUF9t3/4rNHMxw7HbopxbNqOcxBOmJkNcB7gvaqXDGnVLSua4y7qO/EyVfArARdM4cR/nWVzxjxybAQQi+Zs43R0MhNKmZCsaUgsE4vLhNv6hfE5Krtmbk= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=arm.com; spf=pass smtp.mailfrom=arm.com; arc=none smtp.client-ip=217.140.110.172 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=arm.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=arm.com Received: from usa-sjc-imap-foss1.foss.arm.com (unknown [10.121.207.14]) by usa-sjc-mx-foss1.foss.arm.com (Postfix) with ESMTP id B5DA3339; Mon, 23 Feb 2026 01:50:38 -0800 (PST) Received: from [10.57.72.33] (unknown [10.57.72.33]) by usa-sjc-imap-foss1.foss.arm.com (Postfix) with ESMTPSA id 8FEAF3F62B; Mon, 23 Feb 2026 01:50:43 -0800 (PST) Message-ID: <666e2c55-a1aa-4960-a084-50921ec7f696@arm.com> Date: Mon, 23 Feb 2026 09:50:41 +0000 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 User-Agent: Mozilla Thunderbird Subject: Re: [PATCH] coresight: tmc: Fix overflow when calculating is bigger than 2GiB Content-Language: en-GB To: Leo Yan , Mike Leach , James Clark , Mathieu Poirier , Greg Kroah-Hartman , Junhao He Cc: coresight@lists.linaro.org, linux-arm-kernel@lists.infradead.org, linux-kernel@vger.kernel.org, Michiel van Tol References: <20260217-arm_coresight_fix_big_buffer_size-v1-1-774e893d8e3f@arm.com> From: Suzuki K Poulose In-Reply-To: <20260217-arm_coresight_fix_big_buffer_size-v1-1-774e893d8e3f@arm.com> Content-Type: text/plain; charset=UTF-8; format=flowed Content-Transfer-Encoding: 7bit Hi Leo On 17/02/2026 13:19, Leo Yan wrote: > When specifying a 2GB AUX buffer, the ETR driver ends up allocating only > a 1MB buffer instead: > > # echo 'file coresight-tmc-etr.c +p' > \ > /sys/kernel/debug/dynamic_debug/control > # perf record -e cs_etm/@tmc_etr0,timestamp=0/u -C 0 -m ,2G -- test > coresight tmc_etr0: allocated buffer of size 1024KB in mode 0 > > The page index is an 'int' type, and shifting it by PAGE_SHIFT overflows > when the resulting value exceeds 2GB. This produces a negative value, > causing the driver to fall back to the minimum buffer size (1MB). > > Cast the page index to a wider type to accommodate large buffer sizes. > Also fix a similar issue in the buffer offset calculation. > > Reported-by: Michiel van Tol > Fixes: 99443ea19e8b ("coresight: Add generic TMC sg table framework") > Fixes: eebe8dbd8630 ("coresight: tmc: Decouple the perf buffer allocation from sysfs mode") > Signed-off-by: Leo Yan > --- > drivers/hwtracing/coresight/coresight-tmc-etr.c | 4 ++-- > 1 file changed, 2 insertions(+), 2 deletions(-) > > diff --git a/drivers/hwtracing/coresight/coresight-tmc-etr.c b/drivers/hwtracing/coresight/coresight-tmc-etr.c > index cee82e52c4ea96b035f1db71b2d9a006bfc1c51e..990bbb721e1d712d7b93f1e36087fdaf9d3baa3b 100644 > --- a/drivers/hwtracing/coresight/coresight-tmc-etr.c > +++ b/drivers/hwtracing/coresight/coresight-tmc-etr.c > @@ -154,7 +154,7 @@ tmc_pages_get_offset(struct tmc_pages *tmc_pages, dma_addr_t addr) > for (i = 0; i < tmc_pages->nr_pages; i++) { > page_start = tmc_pages->daddrs[i]; > if (addr >= page_start && addr < (page_start + PAGE_SIZE)) > - return i * PAGE_SIZE + (addr - page_start); > + return (long)i * PAGE_SIZE + (addr - page_start); > } > > return -EINVAL; > @@ -1381,7 +1381,7 @@ alloc_etr_buf(struct tmc_drvdata *drvdata, struct perf_event *event, > node = (event->cpu == -1) ? NUMA_NO_NODE : cpu_to_node(event->cpu); > > /* Use the minimum limit if the required size is smaller */ > - size = nr_pages << PAGE_SHIFT; > + size = (ssize_t)nr_pages << PAGE_SHIFT; > size = max_t(ssize_t, size, TMC_ETR_PERF_MIN_BUF_SIZE); > > /* > Thanks for the fix. Could we not fix the declaration of the variables instead ? (Also add a comment to make sure people don't revert it back ) Cheers Suzuki > --- > base-commit: eebe8dbd8630f51cf70b1f68a440cd3d7f7a914d > change-id: 20260217-arm_coresight_fix_big_buffer_size-a8a41298369d > > Best regards,