* [PATCH v2 0/2] Fix and add warning of misuse of type##_replace_bits() @ 2025-07-09 9:38 Ben Horgan 2025-07-09 9:38 ` [PATCH v2 1/2] KVM: arm64: Fix enforcement of upper bound on MDCR_EL2.HPMN Ben Horgan 2025-07-09 9:38 ` [PATCH v2 2/2] bitfield: Ensure the return values of helper functions are checked Ben Horgan 0 siblings, 2 replies; 5+ messages in thread From: Ben Horgan @ 2025-07-09 9:38 UTC (permalink / raw) To: catalin.marinas, will, maz, oliver.upton, joey.gouly, suzuki.poulose, yuzenghui, linux-arm-kernel, kvmarm, yury.norov, linux, linux-kernel Cc: james.morse, Ben Horgan By inspection there is one mistake in the use of u64_replace_bits(). Fix this and while I'm here add a __must_check annotation to help avoid the same mistake happening again. Changes since v1: Patch 1: Add Rb tag from Zenghui Yu - thanks! Patch 2: Extend to add __must_check on _get_bits() and _encode_bits() Ben Horgan (2): KVM: arm64: Fix enforcement of upper bound on MDCR_EL2.HPMN bitfield: Ensure the return values of helper functions are checked arch/arm64/kvm/sys_regs.c | 2 +- include/linux/bitfield.h | 8 ++++---- 2 files changed, 5 insertions(+), 5 deletions(-) -- 2.43.0 ^ permalink raw reply [flat|nested] 5+ messages in thread
* [PATCH v2 1/2] KVM: arm64: Fix enforcement of upper bound on MDCR_EL2.HPMN 2025-07-09 9:38 [PATCH v2 0/2] Fix and add warning of misuse of type##_replace_bits() Ben Horgan @ 2025-07-09 9:38 ` Ben Horgan 2025-07-09 12:22 ` (subset) " Marc Zyngier 2025-07-09 9:38 ` [PATCH v2 2/2] bitfield: Ensure the return values of helper functions are checked Ben Horgan 1 sibling, 1 reply; 5+ messages in thread From: Ben Horgan @ 2025-07-09 9:38 UTC (permalink / raw) To: catalin.marinas, will, maz, oliver.upton, joey.gouly, suzuki.poulose, yuzenghui, linux-arm-kernel, kvmarm, yury.norov, linux, linux-kernel Cc: james.morse, Ben Horgan, stable Previously, u64_replace_bits() was used to no effect as the return value was ignored. Convert to u64p_replace_bits() so the value is updated in place. Reviewed-by: Zenghui Yu <yuzenghui@huawei.com> Signed-off-by: Ben Horgan <ben.horgan@arm.com> Fixes: efff9dd2fee7 ("KVM: arm64: Handle out-of-bound write to MDCR_EL2.HPMN") Cc: Marc Zyngier <maz@kernel.org> Cc: stable@vger.kernel.org --- arch/arm64/kvm/sys_regs.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/arch/arm64/kvm/sys_regs.c b/arch/arm64/kvm/sys_regs.c index 76c2f0da821f..c20bd6f21e60 100644 --- a/arch/arm64/kvm/sys_regs.c +++ b/arch/arm64/kvm/sys_regs.c @@ -2624,7 +2624,7 @@ static bool access_mdcr(struct kvm_vcpu *vcpu, */ if (hpmn > vcpu->kvm->arch.nr_pmu_counters) { hpmn = vcpu->kvm->arch.nr_pmu_counters; - u64_replace_bits(val, hpmn, MDCR_EL2_HPMN); + u64p_replace_bits(&val, hpmn, MDCR_EL2_HPMN); } __vcpu_assign_sys_reg(vcpu, MDCR_EL2, val); -- 2.43.0 ^ permalink raw reply [flat|nested] 5+ messages in thread
* Re: (subset) [PATCH v2 1/2] KVM: arm64: Fix enforcement of upper bound on MDCR_EL2.HPMN 2025-07-09 9:38 ` [PATCH v2 1/2] KVM: arm64: Fix enforcement of upper bound on MDCR_EL2.HPMN Ben Horgan @ 2025-07-09 12:22 ` Marc Zyngier 0 siblings, 0 replies; 5+ messages in thread From: Marc Zyngier @ 2025-07-09 12:22 UTC (permalink / raw) To: catalin.marinas, will, oliver.upton, joey.gouly, suzuki.poulose, yuzenghui, linux-arm-kernel, kvmarm, yury.norov, linux, linux-kernel, Ben Horgan Cc: james.morse, stable On Wed, 09 Jul 2025 10:38:07 +0100, Ben Horgan wrote: > Previously, u64_replace_bits() was used to no effect as the return value > was ignored. Convert to u64p_replace_bits() so the value is updated in > place. > > Applied to fixes, thanks! I have dropped the Cc: stable, as ths bug only exists in 6.16, and we are not backporting anything related to NV to previous kernel versions. [1/2] KVM: arm64: Fix enforcement of upper bound on MDCR_EL2.HPMN commit: 2265c08ec393ef1f5ef5019add0ab1e3a7ee0b79 Cheers, M. -- Without deviation from the norm, progress is not possible. ^ permalink raw reply [flat|nested] 5+ messages in thread
* [PATCH v2 2/2] bitfield: Ensure the return values of helper functions are checked 2025-07-09 9:38 [PATCH v2 0/2] Fix and add warning of misuse of type##_replace_bits() Ben Horgan 2025-07-09 9:38 ` [PATCH v2 1/2] KVM: arm64: Fix enforcement of upper bound on MDCR_EL2.HPMN Ben Horgan @ 2025-07-09 9:38 ` Ben Horgan 2025-07-09 15:33 ` Yury Norov 1 sibling, 1 reply; 5+ messages in thread From: Ben Horgan @ 2025-07-09 9:38 UTC (permalink / raw) To: catalin.marinas, will, maz, oliver.upton, joey.gouly, suzuki.poulose, yuzenghui, linux-arm-kernel, kvmarm, yury.norov, linux, linux-kernel Cc: james.morse, Ben Horgan As type##_replace_bits() has no side effects it is only useful if its return value is checked. Add __must_check to enforce this usage. To have the bits replaced in-place typep##_replace_bits() can be used instead. Although, type_##_get_bits() and type_##_encode_bits() are harder to misuse they are still only useful if the return value is checked. For consistency, also add __must_check to these. Signed-off-by: Ben Horgan <ben.horgan@arm.com> --- include/linux/bitfield.h | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/include/linux/bitfield.h b/include/linux/bitfield.h index 6d9a53db54b6..5355f8f806a9 100644 --- a/include/linux/bitfield.h +++ b/include/linux/bitfield.h @@ -189,14 +189,14 @@ static __always_inline u64 field_mask(u64 field) } #define field_max(field) ((typeof(field))field_mask(field)) #define ____MAKE_OP(type,base,to,from) \ -static __always_inline __##type type##_encode_bits(base v, base field) \ +static __always_inline __##type __must_check type##_encode_bits(base v, base field) \ { \ if (__builtin_constant_p(v) && (v & ~field_mask(field))) \ __field_overflow(); \ return to((v & field_mask(field)) * field_multiplier(field)); \ } \ -static __always_inline __##type type##_replace_bits(__##type old, \ - base val, base field) \ +static __always_inline __##type __must_check type##_replace_bits(__##type old, \ + base val, base field) \ { \ return (old & ~to(field)) | type##_encode_bits(val, field); \ } \ @@ -205,7 +205,7 @@ static __always_inline void type##p_replace_bits(__##type *p, \ { \ *p = (*p & ~to(field)) | type##_encode_bits(val, field); \ } \ -static __always_inline base type##_get_bits(__##type v, base field) \ +static __always_inline base __must_check type##_get_bits(__##type v, base field) \ { \ return (from(v) & field)/field_multiplier(field); \ } -- 2.43.0 ^ permalink raw reply [flat|nested] 5+ messages in thread
* Re: [PATCH v2 2/2] bitfield: Ensure the return values of helper functions are checked 2025-07-09 9:38 ` [PATCH v2 2/2] bitfield: Ensure the return values of helper functions are checked Ben Horgan @ 2025-07-09 15:33 ` Yury Norov 0 siblings, 0 replies; 5+ messages in thread From: Yury Norov @ 2025-07-09 15:33 UTC (permalink / raw) To: Ben Horgan Cc: catalin.marinas, will, maz, oliver.upton, joey.gouly, suzuki.poulose, yuzenghui, linux-arm-kernel, kvmarm, linux, linux-kernel, james.morse On Wed, Jul 09, 2025 at 10:38:08AM +0100, Ben Horgan wrote: > As type##_replace_bits() has no side effects it is only useful if its > return value is checked. Add __must_check to enforce this usage. To have > the bits replaced in-place typep##_replace_bits() can be used instead. > > Although, type_##_get_bits() and type_##_encode_bits() are harder to misuse > they are still only useful if the return value is checked. For > consistency, also add __must_check to these. > > Signed-off-by: Ben Horgan <ben.horgan@arm.com> Applied. Thanks, Yury ^ permalink raw reply [flat|nested] 5+ messages in thread
end of thread, other threads:[~2025-07-09 15:33 UTC | newest] Thread overview: 5+ messages (download: mbox.gz / follow: Atom feed) -- links below jump to the message on this page -- 2025-07-09 9:38 [PATCH v2 0/2] Fix and add warning of misuse of type##_replace_bits() Ben Horgan 2025-07-09 9:38 ` [PATCH v2 1/2] KVM: arm64: Fix enforcement of upper bound on MDCR_EL2.HPMN Ben Horgan 2025-07-09 12:22 ` (subset) " Marc Zyngier 2025-07-09 9:38 ` [PATCH v2 2/2] bitfield: Ensure the return values of helper functions are checked Ben Horgan 2025-07-09 15:33 ` Yury Norov
This is a public inbox, see mirroring instructions for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®