From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mx0a-0031df01.pphosted.com (mx0a-0031df01.pphosted.com [205.220.168.131]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 1867444C4FD for ; Wed, 12 Aug 2026 13:59:18 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=205.220.168.131 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786543160; cv=none; b=H526FOoasOdbeLoIF+KRPGIVUce75Z80di82paO/W4B8PlSoVRxruCye945ygd4s88ccdmFOLALiccCcyfnEWUfX5TrzxAhqy4alsSe8R0ZxLeP8gmZzX9qb80IwMTa7E1amGMCvCmsfkYxEQK2EWcwp5ojVPZOL7nYKUIbS5oI= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786543160; c=relaxed/simple; bh=gIAaw7usTtpVY8l8jWXkfYlYYV8k+zoiz8TnUUqZLo0=; h=Message-ID:Date:MIME-Version:Subject:To:References:From:Cc: In-Reply-To:Content-Type; b=mHsXA7RQboOLtkG8ZEEfQQ4kHHM5L5tligohmJYMMOvd9bQM0tExulqN3Ea954lKM7gOXHUDzYPbZ0iTudh85ApJ+pDuoBYrVkHzMsjIjdn58WEZAiql/CX6w24mtmglTkJJSrLAPHmCD3QSiI11jU1h5qsFvlkQme7VvfYhryA= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=oss.qualcomm.com; spf=pass smtp.mailfrom=oss.qualcomm.com; dkim=pass (2048-bit key) header.d=qualcomm.com header.i=@qualcomm.com header.b=Mll+P9or; dkim=pass (2048-bit key) header.d=oss.qualcomm.com header.i=@oss.qualcomm.com header.b=MJUTJGBd; arc=none smtp.client-ip=205.220.168.131 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=oss.qualcomm.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=oss.qualcomm.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=qualcomm.com header.i=@qualcomm.com header.b="Mll+P9or"; dkim=pass (2048-bit key) header.d=oss.qualcomm.com header.i=@oss.qualcomm.com header.b="MJUTJGBd" Received: from pps.filterd (m0279866.ppops.net [127.0.0.1]) by mx0a-0031df01.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 67CDbX3l3597605 for ; Wed, 12 Aug 2026 13:59:18 GMT DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=qualcomm.com; h= cc:content-transfer-encoding:content-type:date:from:in-reply-to :message-id:mime-version:references:subject:to; s=qcppdkim1; bh= 5yGE3vDlilzN6eWX5sTduRrhbOKoDy5+ytcaqrJmAAM=; b=Mll+P9ortUz3Ol61 Y+ajbBh4z14GMfTFwnKCvWF8IST16ImgtI6ftnMGgeMmmXQUuS/1y0PrVnKCBIS8 11p0XAt9o3yo2noJxo+WGts/W5IummEaFQJqNd7pmqe4aYg9KaDzVj5kodKcu3DF xTOgmWps80UIdCDARchDx6/EXAr7WovbAXSDMB6Q0ee525sC42fhWKe0d8rmiOFc crNWU5yIZo4RRexT9bW8FZAbfwEVao0JMMY28aFqcjpr7Vg4ZcakcBMkCuAdIFqS 4Z+tjPk8RLBsWjvGBJhHZYJxfdSzFyfHHKHAl2oI5Hum96C+BapTqEdiU6UMNIs2 yKtjbQ== Received: from mail-pl1-f199.google.com (mail-pl1-f199.google.com [209.85.214.199]) by mx0a-0031df01.pphosted.com (PPS) with ESMTPS id 4g08jrm5rs-1 (version=TLSv1.3 cipher=TLS_AES_128_GCM_SHA256 bits=128 verify=NOT) for ; Wed, 12 Aug 2026 13:59:18 +0000 (GMT) Received: by mail-pl1-f199.google.com with SMTP id d9443c01a7336-2cc88e22f92so24142185ad.1 for ; Wed, 12 Aug 2026 06:59:18 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=oss.qualcomm.com; s=google; t=1786543157; x=1787147957; darn=vger.kernel.org; h=content-transfer-encoding:content-type:in-reply-to:cc:from :content-language:references:to:subject:user-agent:mime-version:date :message-id:from:to:cc:subject:date:message-id:reply-to:content-type; bh=5yGE3vDlilzN6eWX5sTduRrhbOKoDy5+ytcaqrJmAAM=; b=MJUTJGBd0d6AzEinTLhkldFgQqdEz/C7lxrI5PhjmTG+iE69mLLj9m3Pz7zfz4oEcP OJSvYtGpLeQ6rZ2nKy6UnxRc8ycSGvjo6hFY7JpEQHMfIpMSgFCbhKmAfTxqJBEpZ4MI Orr8NcN/QxScQ+9H9fod9aWzn5WoBD93WOtV0jzTHHHthhZjToDpVnqf2ka1qsx26zan TjAKxSKqLlvrebFDsp+BhA7tH+mdbd4kdhKVxhZmUxafmNGt8maMHZjujKeUOggUIIq6 dJA6xHmfnNaljplR6pJ1hV9uqfr4kmRcmTs5fNeq3K7184psSXKI/exzwwfd0BsS0XLi Ifdg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1786543157; x=1787147957; h=content-transfer-encoding:content-type:in-reply-to:cc:from :content-language:references:to:subject:user-agent:mime-version:date :message-id:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=5yGE3vDlilzN6eWX5sTduRrhbOKoDy5+ytcaqrJmAAM=; b=kUc6VVKZnwn85SO0WMWmNy1hnYO4pReI8QxmiGXClce+5leo0aFZXMFFL8NivRS8Ad U47fhyoDshOc9PaLojKHS5FAWGc9qjBy8onBiC9DdjgWsrRD1hRx9A3i4nzfMFb3T8Fd z/DNRF4Yqyxkpfl5//JKkjD07KMRgLti66h3eWcwlzT+Scpx9+/ZzMJq2AZ8/2EHQhRW gn9UFNTO5QpTmuW66b1Cw/OCh9y6S/Wqcci1w/3aDlwKf6oR96+Wnv2yaRQsdkbXtFKa Ma7Jmta6WyrrTowNO5VnKtDLfUN2ZdEvd4yt//sb5UVLbSvJ0Ow+0lUp7tKa/+5Fr9cC B3bg== X-Forwarded-Encrypted: i=1; AHgh+RorZnBPVEJqlXJ1QdGFE64iWUo1eyOeOOiCR1lJ5CMH+HNCYEKJN5KFzsben2ylJlZbDkqA8ykO0gHlLF0=@vger.kernel.org X-Gm-Message-State: AOJu0Yxi/UGH01rZHsHFML23W8tqruDpGBzTzuljp4L19Oam0oFGYpjw dmZB5oepzfKN66A0a5+gTgLMsUJvqevLXkZvkGAO30j57n3EtNX2CUJM97nbfYmzLlXLSnmEQLr aVA6Lbe8r4OHKWEAVUbWTXrlQLu3P1ti07yitaPR10LQrMfjTeUAtcWcDSbj7czEa08Y= X-Gm-Gg: AR+sD11uWoHlNwJ9VQLUWAhH5CLqhVXj5FJLBQ+gvCUyMn6/NO9DDFTviJLM1yDuxJu ZS4sdEYGeY6BuZZ2YydVxmqmuIW3HsZZ9b4kiwySZy2HpnVPuj1b6sdwf0NggiYYSZJ0610IOWn /0svP+9+l0oZdnUCA6/JPhhoT9yENb1QDnrsibWB2hfAdPByuWlYQMylg8DNP7o7IJ/ZyCjCXA4 XvjAYhH6qJtr6ukmpSCpNnn9pIx3hpOGL3S49j4r5bC7iZWl79a3LBBNhly+eNHTjff81219xaH 4FDp1R35GpJOZ7fU0smqCaOR+GQp7CCjDM9Tg+I643Qxa3HOBFei6R4exvJk44Z+QCcLAy+oW3Z nK8miXVN1QiEFFGsLAQd1daS7R5+H8iYKRjlg4iVrpfIET7T0Sqlhdd5pTF1eCOWpMNAaRA== X-Received: by 2002:a17:902:d582:b0:2d3:2b8a:5007 with SMTP id d9443c01a7336-2d34569a059mr64153155ad.15.1786543157547; Wed, 12 Aug 2026 06:59:17 -0700 (PDT) X-Received: by 2002:a17:902:d582:b0:2d3:2b8a:5007 with SMTP id d9443c01a7336-2d34569a059mr64152315ad.15.1786543156904; Wed, 12 Aug 2026 06:59:16 -0700 (PDT) Received: from [10.133.33.48] (tpe-colo-wan-fw-bordernet.qualcomm.com. [103.229.16.4]) by smtp.gmail.com with ESMTPSA id d9443c01a7336-2d350fb0701sm7221715ad.15.2026.08.12.06.59.14 (version=TLS1_3 cipher=TLS_AES_128_GCM_SHA256 bits=128/128); Wed, 12 Aug 2026 06:59:16 -0700 (PDT) Message-ID: Date: Wed, 12 Aug 2026 21:59:13 +0800 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 User-Agent: Mozilla Thunderbird Subject: Re: [PATCH] cpufreq: acpi-cpufreq: Using cpufreq_for_each_entry() to iterate in extract_io() To: lirongqing , "Rafael J . Wysocki" , Viresh Kumar , linux-pm@vger.kernel.org References: <20260810061045.2397-1-lirongqing@baidu.com> <20260810061045.2397-3-lirongqing@baidu.com> Content-Language: en-US From: Zhongqiu Han Cc: zhongqiu.han@oss.qualcomm.com, "linux-kernel@vger.kernel.org" In-Reply-To: <20260810061045.2397-3-lirongqing@baidu.com> Content-Type: text/plain; charset=UTF-8; format=flowed Content-Transfer-Encoding: 7bit X-Proofpoint-GUID: 2LUdY-ijKgXfOQD3u2BwQRKxkC-XrlaO X-Proofpoint-Spam-Info: AW1haW4tMjYwODEyMDExNCBTYWx0ZWRfX2KLrvSCsj+D/ 5H9dV9TmELY25VbbqVe4v9/BJjGQqwq2T1YkYuCTZ6f+OwNNEIpbODSwYvNCPqflhBwreDOLGVU bOwzFim9FgLoHk9+bmIJZQuKRYceBkw= X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwODEyMDExNCBTYWx0ZWRfX9aiLbTDRFPyQ M6i9BfLKOcviPxVxVkScsHbidU5imLWXsZFNuwEIjkS07dhGuzP6GSlkGMsf5aALrLGqx3nuhp7 7lvasFhXsvV6I9TEfs5W1Ug1uMZjI8vZFvGezFPTzzPNNtgtKaWbSgpWduAszbZ12AlfonkgIdZ f1UlDHg+T4W8abE5lwhxXGGnDgfeO23ezQiO5K+4X+OWRpvY7MumRRrY/lL/qVTQXyerVa7dTuC qcCKQCg5mXeeNazurAfh5JKOnR/De6KkevDAHKFV6Qq42VP3hlQ7cBqYisRbPX7b7ZUFPSGwAdz fjKnxJkL/09pEJehr/wGpfqWikG6JDAO8K5FvHqU9imm+bOF7m0Re9pIuLjI8hCbx85wYW8Gtvk PXqOzFttpcXnTF/OJ0Lk1C22psqC7j2Ur8Q/XvSpKLVM0hSTofjgfAE9QUuSUXmqJxRiUa37tMQ bQvVkk97ppEKnhUcuhQ== X-Authority-Analysis: v=2.4 cv=Z7Dc2nRA c=1 sm=1 tr=0 ts=6a7c7c36 cx=c_pps a=JL+w9abYAAE89/QcEU+0QA==:117 a=nuhDOHQX5FNHPW3J6Bj6AA==:17 a=IkcTkHD0fZMA:10 a=Sv0fKeRqtYgA:10 a=s4-Qcg_JpJYA:10 a=VkNPw1HP01LnGYTKEx00:22 a=u7WPNUs3qKkmUXheDGA7:22 a=YMgV9FUhrdKAYTUUvYB2:22 a=zuLzuavZAAAA:8 a=VwQbUJbxAAAA:8 a=0a-dqdBBcCSYx8TJZcQA:9 a=QEXdDO2ut3YA:10 a=324X-CrmTo6CU4MGRt3R:22 X-Proofpoint-ORIG-GUID: 2LUdY-ijKgXfOQD3u2BwQRKxkC-XrlaO X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1176,Hydra:6.1.134,FMLib:17.12.100.49 definitions=2026-08-12_04,2026-08-12_01,2025-10-01_01 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 malwarescore=0 lowpriorityscore=0 adultscore=0 clxscore=1015 impostorscore=0 spamscore=0 priorityscore=1501 bulkscore=0 phishscore=0 suspectscore=0 classifier=typeunknown authscore=0 authtc= authcc= route=outbound adjust=0 reason=mlx scancount=1 engine=8.22.0-2606150000 definitions=main-2608120114 On 8/10/2026 2:10 PM, lirongqing wrote: > From: Li RongQing > > In extract_io(), the loop iterates up to perf->state_count. However, > when building policy->freq_table in acpi_cpufreq_cpu_init(), duplicate > frequency entries are skipped, making freq_table smaller than > perf->state_count. > > Iterating perf->state_count times directly over policy->freq_table[i] can > result in out-of-bounds array reads. Furthermore, policy->freq_table[i] There is no out-of-bounds access. The array has "state_count + 1" elements, so every index in "[0, state_count)" is inside the allocation. right? The changelog looks like a memory-safety fix, which it is not, and that wording alone would get the patch (mis)routed to stable and to CVE bots. > does not necessarily correspond to perf->states[i], as the original P-state > index is stored in freq_table[entry].driver_data. Yes, the real defect is the index space mismatch. Might be good to note the side effects of it, AFAICT freq_table[i] is not perf->states[i] once any _PSS entry has been skipped. The function can therefore return a frequency belonging to a different P-state, or 0 (zeroed tail entries), or CPUFREQ_TABLE_END (~1u) when "i == valid_states", i.e. 0xfffffffe kHz reported as a frequency. That last one is worth spelling out. > > Fix this by using cpufreq_for_each_entry() to iterate over > policy->freq_table, similar to extract_msr(). > Please add one Fixes tag here as well. > Signed-off-by: Li RongQing > --- > drivers/cpufreq/acpi-cpufreq.c | 9 ++++----- > 1 file changed, 4 insertions(+), 5 deletions(-) > > diff --git a/drivers/cpufreq/acpi-cpufreq.c b/drivers/cpufreq/acpi-cpufreq.c > index 21639d9..87e4923 100644 > --- a/drivers/cpufreq/acpi-cpufreq.c > +++ b/drivers/cpufreq/acpi-cpufreq.c > @@ -196,15 +196,14 @@ static int check_amd_hwpstate_cpu(unsigned int cpuid) > static unsigned extract_io(struct cpufreq_policy *policy, u32 value) > { > struct acpi_cpufreq_data *data = policy->driver_data; > + struct cpufreq_frequency_table *pos; > struct acpi_processor_performance *perf; > - int i; > > perf = to_perf_data(data); > > - for (i = 0; i < perf->state_count; i++) { > - if (value == perf->states[i].status) > - return policy->freq_table[i].frequency; > - } > + cpufreq_for_each_entry(pos, policy->freq_table) > + if (value == perf->states[pos->driver_data].status) > + return pos->frequency; > return 0; > } One more potential same issue is in func get_cur_freq_on_cpu() cached_freq = policy->freq_table[to_perf_data(data)->state].frequency; It is better to fix it as well. For v2, please use ./scripts/get_maintainer.pl to generate the CC list so linux-kernel@vger.kernel.org doesn't get missed. Thanks > -- Thx and BRs, Zhongqiu Han