From: "Ahmed S. Darwish" <darwi@linutronix.de>
To: kernel test robot <oliver.sang@intel.com>
Cc: oe-lkp@lists.linux.dev, lkp@intel.com,
linux-kernel@vger.kernel.org, Ingo Molnar <mingo@redhat.com>,
Borislav Petkov <bp@alien8.de>,
Dave Hansen <dave.hansen@linux.intel.com>,
Thomas Gleixner <tglx@linutronix.de>,
Andrew Cooper <andrew.cooper3@citrix.com>,
"H. Peter Anvin" <hpa@zytor.com>,
John Ogness <john.ogness@linutronix.de>,
x86@kernel.org, x86-cpuid@lists.linux.dev
Subject: Re: [PATCH v3 22/29] x86/cpu: Use consolidated leaf 0x2 descriptor table
Date: Mon, 24 Mar 2025 12:15:09 +0100 [thread overview]
Message-ID: <Z-E-vXHVl3dLFYx0@lx-t490> (raw)
In-Reply-To: <202503241523.6b53646b-lkp@intel.com>
Hi,
On Mon, 24 Mar 2025, kernel test robot wrote:
>
> [ 5.001760][ T0] BUG: KASAN: stack-out-of-bounds in intel_detect_tlb (arch/x86/kernel/cpu/intel.c:698 arch/x86/kernel/cpu/intel.c:688)
> [ 5.001760][ T0] Read of size 1 at addr ffffffff8a607e80 by task swapper/0/0
> [ 5.001760][ T0]
> [ 5.001760][ T0] CPU: 0 UID: 0 PID: 0 Comm: swapper/0 Not tainted 6.14.0-rc5-00152-ge114ca069e27 #1
> [ 5.001760][ T0] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.16.2-debian-1.16.2-1 04/01/2014
> [ 5.001760][ T0] Call Trace:
> [ 5.001760][ T0] <TASK>
> [ 5.001760][ T0] dump_stack_lvl (lib/dump_stack.c:124)
> [ 5.001760][ T0] print_address_description+0x2c/0x3f0
> [ 5.001760][ T0] ? intel_detect_tlb (arch/x86/kernel/cpu/intel.c:698 arch/x86/kernel/cpu/intel.c:688)
>
I've reproduced the KASAN report and below hunk fixes it:
| --- a/arch/x86/include/asm/cpuid/leaf_0x2_api.h
| +++ b/arch/x86/include/asm/cpuid/leaf_0x2_api.h
| @@ -88,9 +88,9 @@ static inline void cpuid_get_leaf_0x2_regs(union leaf_0x2_regs *regs)
| * }
| * }
| */
| -#define for_each_leaf_0x2_entry(regs, __ptr, entry) \
| - for (__ptr = &(regs).desc[1], entry = &cpuid_0x2_table[*__ptr]; \
| - __ptr < &(regs).desc[16]; \
| - __ptr++, entry = &cpuid_0x2_table[*__ptr])
| +#define for_each_leaf_0x2_entry(regs, __ptr, entry) \
| + for (__ptr = &(regs).desc[1]; \
| + __ptr < &(regs).desc[16] && (entry = &cpuid_0x2_table[*__ptr]); \
| + __ptr++)
I'll include the fix in v4.
(It also makes sense that this was triggered at x86/cpu intel.c and not
x86/cacheinfo, since in cacheinfo.c, CPUID(4) when available is always
preferred to CPUID(2).)
Thanks!
--
Ahmed S. Darwish
Linutronix GmbH
next prev parent reply other threads:[~2025-03-24 11:15 UTC|newest]
Thread overview: 32+ messages / expand[flat|nested] mbox.gz Atom feed top
2025-03-19 12:21 [PATCH v3 00/29] x86: Leaf 0x2 and leaf 0x4 refactorings Ahmed S. Darwish
2025-03-19 12:21 ` [PATCH v3 01/29] x86/cpu: Remove leaf 0x2 parsing loop Ahmed S. Darwish
2025-03-19 12:21 ` [PATCH v3 02/29] x86/cacheinfo: " Ahmed S. Darwish
2025-03-19 12:21 ` [PATCH v3 03/29] x86/cpu: Introduce and use leaf 0x2 parsing helpers Ahmed S. Darwish
2025-03-19 12:21 ` [PATCH v3 04/29] x86/cacheinfo: Use " Ahmed S. Darwish
2025-03-19 12:21 ` [PATCH v3 05/29] x86/cacheinfo: Refactor leaf 0x2 cache descriptor lookup Ahmed S. Darwish
2025-03-19 12:21 ` [PATCH v3 06/29] x86/cacheinfo: Properly name amd_cpuid4()'s first parameter Ahmed S. Darwish
2025-03-19 12:21 ` [PATCH v3 07/29] x86/cacheinfo: Use proper name for cacheinfo instances Ahmed S. Darwish
2025-03-19 12:21 ` [PATCH v3 08/29] x86/cacheinfo: Constify _cpuid4_info_regs instances Ahmed S. Darwish
2025-03-19 12:21 ` [PATCH v3 09/29] x86/cacheinfo: Align ci_info_init() assignment expressions Ahmed S. Darwish
2025-03-19 12:21 ` [PATCH v3 10/29] x86/cacheinfo: Standardize _cpuid4_info_regs instance naming Ahmed S. Darwish
2025-03-19 12:21 ` [PATCH v3 11/29] x86/cacheinfo: Consolidate AMD/Hygon leaf 0x8000001d calls Ahmed S. Darwish
2025-03-19 12:21 ` [PATCH v3 12/29] x86/cacheinfo: Separate amd_northbridge from _cpuid4_info_regs Ahmed S. Darwish
2025-03-19 12:21 ` [PATCH v3 13/29] x86/cacheinfo: Move AMD cache_disable_0/1 handling to separate file Ahmed S. Darwish
2025-03-19 12:21 ` [PATCH v3 14/29] x86/cacheinfo: Use sysfs_emit() for sysfs attributes show() Ahmed S. Darwish
2025-03-19 12:21 ` [PATCH v3 15/29] x86/cacheinfo: Separate Intel and AMD leaf 0x4 code paths Ahmed S. Darwish
2025-03-19 12:21 ` [PATCH v3 16/29] x86/cacheinfo: Rename _cpuid4_info_regs to _cpuid4_info Ahmed S. Darwish
2025-03-19 12:21 ` [PATCH v3 17/29] x86/cacheinfo: Clarify type markers for leaf 0x2 cache descriptors Ahmed S. Darwish
2025-03-19 12:21 ` [PATCH v3 18/29] x86/cacheinfo: Use enums for cache descriptor types Ahmed S. Darwish
2025-03-19 12:21 ` [PATCH v3 19/29] x86/cpu: Use enums for TLB " Ahmed S. Darwish
2025-03-19 12:21 ` [PATCH v3 20/29] x86/cpu: Consolidate CPUID leaf 0x2 tables Ahmed S. Darwish
2025-03-19 12:21 ` [PATCH v3 21/29] x86/cacheinfo: Use consolidated leaf 0x2 descriptor table Ahmed S. Darwish
2025-03-19 12:21 ` [PATCH v3 22/29] x86/cpu: " Ahmed S. Darwish
2025-03-24 7:37 ` kernel test robot
2025-03-24 11:15 ` Ahmed S. Darwish [this message]
2025-03-19 12:21 ` [PATCH v3 23/29] x86/cacheinfo: Separate leaf 0x2 handling and post-processing logic Ahmed S. Darwish
2025-03-19 12:21 ` [PATCH v3 24/29] x86/cacheinfo: Separate Intel leaf 0x4 handling Ahmed S. Darwish
2025-03-19 12:21 ` [PATCH v3 25/29] x86/cacheinfo: Extract out cache level topology ID calculation Ahmed S. Darwish
2025-03-19 12:21 ` [PATCH v3 26/29] x86/cacheinfo: Extract out cache self-snoop checks Ahmed S. Darwish
2025-03-19 12:21 ` [PATCH v3 27/29] x86/cacheinfo: Relocate leaf 0x4 cache_type mapping Ahmed S. Darwish
2025-03-19 12:21 ` [PATCH v3 28/29] x86/cacheinfo: Introduce cpuid_amd_hygon_has_l3_cache() Ahmed S. Darwish
2025-03-19 12:21 ` [PATCH v3 29/29] x86/cacheinfo: Apply maintainer-tip coding style fixes Ahmed S. Darwish
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=Z-E-vXHVl3dLFYx0@lx-t490 \
--to=darwi@linutronix.de \
--cc=andrew.cooper3@citrix.com \
--cc=bp@alien8.de \
--cc=dave.hansen@linux.intel.com \
--cc=hpa@zytor.com \
--cc=john.ogness@linutronix.de \
--cc=linux-kernel@vger.kernel.org \
--cc=lkp@intel.com \
--cc=mingo@redhat.com \
--cc=oe-lkp@lists.linux.dev \
--cc=oliver.sang@intel.com \
--cc=tglx@linutronix.de \
--cc=x86-cpuid@lists.linux.dev \
--cc=x86@kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®