events-arch-x86: fix an uninitialized bank_type and an mce_priv leak - #267
Open
agenticode wants to merge 2 commits into
Open
agenticode wants to merge 2 commits into
agenticode wants to merge 2 commits into
Conversation
decode_smca_error() leaves bank_type untouched when the IPID matches no entry in smca_hwid_mcatypes[]. The test meant to catch that is "i >= MAX_NR_BANKS" (64), but the loop only runs to ARRAY_SIZE(smca_hwid_mcatypes), which is 37, so it can never be true. The uninitialized value then indexes smca_names[] and smca_mce_descs[]. An mce_record with an IPID that is not in the table decodes differently on every run; valgrind reports the uninitialized reads. Set bank_type to N_SMCA_BANK_TYPES up front so that case falls into the "Don't know how to decode this bank" check just below. The "i >= MAX_NR_BANKS" test stays: aecf33a ("rasdaemon: Enumerate memory on noncpu nodes") moved it off ARRAY_SIZE() so that non-CPU nodes without a table match keep SMCA_UMC_V2. Signed-off-by: Jongwon Lee <ai@linux.com>
ras_erst_init() allocates ras->mce_priv through init_mce_priv(), but x86-mce-erst registers no cleanup. The only free_mce_priv() caller is x86-mce-event's cleanup, and modules_cleanup_type() skips modules whose is_enabled is false, so nothing frees it if that module failed to initialize. Add the cleanup. free_mce_priv() clears ras->mce_priv, so having both modules call it is fine. With the allocation x86-mce-event needs made to fail, LeakSanitizer reports 96 bytes direct plus 560 indirect. Signed-off-by: Jongwon Lee <ai@linux.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Two x86 error-path fixes, one commit each.
mce-amd-smca:
bank_typeused uninitializeddecode_smca_error()only setsbank_typewhen the IPID matches an entry insmca_hwid_mcatypes[]. The no-match check isi >= MAX_NR_BANKS(64), but the loop stops atARRAY_SIZE(smca_hwid_mcatypes)(37), so it is never true and stack garbage indexessmca_names[]andsmca_mce_descs[].One mce_record with family 0x17 and IPID
0xffff0fff00000000(in no entry, not a non-CPU node), under valgrind:Outside valgrind the same record printed "Don't know how to decode this bank", so the result depends on what is on the stack. With the patch
bank_typestarts atN_SMCA_BANK_TYPESand that message is what you always get.I left the
i >= MAX_NR_BANKStest alone: aecf33a moved it offARRAY_SIZE()so that non-CPU nodes with no table match keepSMCA_UMC_V2.ras-erst:
mce_privleakras_erst_init()callsinit_mce_priv(), butx86-mce-ersthas no.cleanup. The onlyfree_mce_priv()caller is thex86-mce-eventcleanup, andmodules_cleanup_type()skips it when that module failed to init.Failing the allocation
x86-mce-eventneeds:free_mce_priv()clearsras->mce_priv, so both modules calling it is fine.Testing
Fedora 44, on top of d06e494:
meson test: 9/9 with both compilerspython3 tests/run.py: 140 tests, rc=0scripts/checkpatch.pl --no-tree --strict: no issues