From nobody Thu Oct 2 02:13:24 2025 Received: from mail-pl1-f175.google.com (mail-pl1-f175.google.com [209.85.214.175]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 4692E26D4FB for ; Tue, 30 Sep 2025 02:45:59 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.214.175 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1759200361; cv=none; b=YomjvIkLxGtk2oiGGAhPGZhQoJ5IV2PGN5bXnTrbDeexXCmFKrVe1o59PKzUlka2jCxFGJuRpQQYfXNd+gd5RDkJ05Uz/AnXlbIyiU79CQXfNi/pIcKKoPPe2LSGLmHFnU9t6wU/6lo8T5xx1sFr3OJuLKmnqMPKXtKL6OnR37s= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1759200361; c=relaxed/simple; bh=fxWJKkmTlJVGhf37wzDyuZOWELAg09qlFO66bjAfLB4=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=XPIdm8Jx8eJ6uwEuE+wLYlypVYywvryWkZHYh+NxPwRfo27Qh/8KXwctV7zRorhlYMnIVZmNNyrwU1mHqjumk35nAcZoCRB+Lrm2BmEhb/Z3bEM7BigfvWpxu7yPW4hULABTBkr9KPllnNpHIY6CnbfJdfarrU6bpXKqtqzhxy8= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=U8CNtn4R; arc=none smtp.client-ip=209.85.214.175 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="U8CNtn4R" Received: by mail-pl1-f175.google.com with SMTP id d9443c01a7336-28a5b8b12a1so16376975ad.0 for ; Mon, 29 Sep 2025 19:45:59 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20230601; t=1759200358; x=1759805158; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to; bh=wSXL/rVpDaFhkpWTVL2v5h6JspYJZAfxl9VpOD0Az0s=; b=U8CNtn4RlFwDL+Bu5RLENJnTv/cgcIZ1KYanSNGhHfhVeiWA5sn+4i4QC/y63JiFbd Z6UpeBaVFiySVJZ3eo8LLsh43/LEu9UQEcFQygbSyGabRKxrG1I2jHAwsv0B5UXRtp6C O6L+yA+nWDAfNWAj3b/vn+v9fAu4MgcIe3dO2UCgw0CfOi57uXlBvf76Yj7VULB+wI9+ L47GzsnCeXfH72g0ipzVRj1LhjKmvM0aZ8olFO7oTpVcSjFQzrK3t01ycsIxi1F9K2SG eq/QpqxDvWBwssAmMnpnDcmQZHp2SPuMKkOWC0toSSovuvuAQgs+SXtY7iBgvRx5tqqx 6S0w== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1759200358; x=1759805158; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-message-state:from:to:cc :subject:date:message-id:reply-to; bh=wSXL/rVpDaFhkpWTVL2v5h6JspYJZAfxl9VpOD0Az0s=; b=NBWNSxigE4iN6Wqhs/jXYsdVw+adCn1Pd4v4Tw+tN5W0LbWaINs4iMuZazgnuZmOLL ucuzI+djK+SJy2vAtrWDdRRMCyuXbXG9reLPcSAZNO+Jdik9FPt0oL1NyEFLXpzcE3ue T39U3W0+o/jSoGMIenysGPI8grEQEbRZabDzCCo2srcG6+Zk1phTWQSGlf8Q09mHb8fn 6DtSEpCn4AJWDBfwMNSWknxzAhw4MmNXFi+1+4mWksR5IXZ6iatD5tqvwIHlG6cxmXB9 muYd9He022IOBjN8Q382LXO40KHFpjHCrEa8yP4iYJEFoICUHymGIFvIhJq5GY1NDjF8 rTjw== X-Forwarded-Encrypted: i=1; AJvYcCWWZWDU8rCsi0cQqdBqVL1W6PvqKZPldZLECJYKQb3J2YM3HpKNbnVkHeRWkv0u1//RgmEdXup/dVT0roI=@vger.kernel.org X-Gm-Message-State: AOJu0YwTMXzWmb+LbeMHdyBpkjPFN2WoEZTKtLZvsdlQiqISHzKnrARA sSmB+gb3jyrEb6ag1WGAnNAT6PEX7Y4EBQx60GrdacDNBKWrFTrQ4KU/ X-Gm-Gg: ASbGncs42v0kDh+9hGOeg0ejyfeHpgVTQxLrmi8dayjtHT6EfQSs+HS68DLSY5m5qrG cekH1tReA8ouRcQrozv3CeForYb9KZGd7UWq+ubAP+1+ubbBkdDSzDkOUB43bW77ye3rIMHhCoX EjQ7ca5g4qTOJcOMcHw02S02VAA36CoG1fnecmLnw5UKjuZjzcOLznG8Gq9/hmluXCTHhWyNzXa M4hQ6I5VXWBUWyEetRfPTVTnLkvUeNWOnZ8iKP0b5BBfeP8R1zrH0LVJtBDyXjrIYZ16RBk6rH7 VWUTXbeKMaQAxwFq5XCRfJCu2XaxopWRBSTnrRObS/u5ggvVOgUb1iTS2kd5OB/QfuEk/eAVjWa H5o8mf+zNHurJwGbULJx4dtNbq9Esu1l1MtResb7EiiRGODW05XtZ0PqwnNILLk7vtw== X-Google-Smtp-Source: AGHT+IH6gM/KNPy+EKuwDpqrsR2PCtVeobdVuJ/I6iYU/PVMeQcdMhYmE/6vu80Fhzh9wbuUwcXL7Q== X-Received: by 2002:a17:903:19f0:b0:26c:e270:6dad with SMTP id d9443c01a7336-27ed4ae51c6mr173137795ad.60.1759200358349; Mon, 29 Sep 2025 19:45:58 -0700 (PDT) Received: from localhost ([45.142.167.196]) by smtp.gmail.com with ESMTPSA id d9443c01a7336-27ed69ba58csm144532905ad.121.2025.09.29.19.45.57 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 29 Sep 2025 19:45:57 -0700 (PDT) From: Jinchao Wang To: Andrew Morton , Masami Hiramatsu , Peter Zijlstra , Mike Rapoport , Alexander Potapenko , Randy Dunlap , Marco Elver , Jonathan Corbet , Thomas Gleixner , Ingo Molnar , Borislav Petkov , Dave Hansen , x86@kernel.org, "H. Peter Anvin" , Juri Lelli , Vincent Guittot , Dietmar Eggemann , Steven Rostedt , Ben Segall , Mel Gorman , Valentin Schneider , Arnaldo Carvalho de Melo , Namhyung Kim , Mark Rutland , Alexander Shishkin , Jiri Olsa , Ian Rogers , Adrian Hunter , "Liang, Kan" , David Hildenbrand , Lorenzo Stoakes , "Liam R. Howlett" , Vlastimil Babka , Suren Baghdasaryan , Michal Hocko , Nathan Chancellor , Nick Desaulniers , Bill Wendling , Justin Stitt , Kees Cook , Alice Ryhl , Sami Tolvanen , Miguel Ojeda , Masahiro Yamada , Rong Xu , Naveen N Rao , David Kaplan , Andrii Nakryiko , Jinjie Ruan , Nam Cao , workflows@vger.kernel.org, linux-doc@vger.kernel.org, linux-kernel@vger.kernel.org, linux-perf-users@vger.kernel.org, linux-mm@kvack.org, llvm@lists.linux.dev, Andrey Ryabinin , Andrey Konovalov , Dmitry Vyukov , Vincenzo Frascino , kasan-dev@googlegroups.com, "David S. Miller" , Mathieu Desnoyers , linux-trace-kernel@vger.kernel.org Cc: Jinchao Wang Subject: [PATCH v6 20/23] mm/ksw: add multi-thread corruption test cases Date: Tue, 30 Sep 2025 10:43:41 +0800 Message-ID: <20250930024402.1043776-21-wangjinchao600@gmail.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20250930024402.1043776-1-wangjinchao600@gmail.com> References: <20250930024402.1043776-1-wangjinchao600@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" These tests share a common structure and are grouped together. - buggy(): exposes the stack address to corrupting(); may omit waiting - corrupting(): reads the exposed pointer and modifies memory; if buggy() omits waiting, victim()'s buffer is corrupted - victim(): initializes a local buffer and later verifies it; reports an error if the buffer was unexpectedly modified buggy() and victim() run in worker() thread, with similar stack frame sizes to simplify testing. By adjusting fence_size in corrupting(), the test can trigger either silent corruption or overflow across threads. - Test 3: one worker, 20 loops, silent corruption - Test 4: 20 workers, one loop each, silent corruption - Test 5: one worker, one loop, overflow corruption Test 4 also exercises multiple watchpoint instances. Signed-off-by: Jinchao Wang --- mm/kstackwatch/test.c | 186 +++++++++++++++++++++++++++++++++++++++++- 1 file changed, 185 insertions(+), 1 deletion(-) diff --git a/mm/kstackwatch/test.c b/mm/kstackwatch/test.c index 203fff4bec92..2952efcc7738 100644 --- a/mm/kstackwatch/test.c +++ b/mm/kstackwatch/test.c @@ -20,6 +20,20 @@ static struct dentry *test_file; #define BUFFER_SIZE 32 #define MAX_DEPTH 6 =20 +struct work_node { + ulong *ptr; + u64 start_ns; + struct completion done; + struct list_head list; +}; + +static DECLARE_COMPLETION(work_res); +static DEFINE_MUTEX(work_mutex); +static LIST_HEAD(work_list); + +static int global_fence_size; +static int global_loop_count; + static void test_watch_fire(void) { u64 buffer[BUFFER_SIZE] =3D { 0 }; @@ -62,6 +76,164 @@ static void test_recursive_depth(int depth) pr_info("exit of %s depth:%d\n", __func__, depth); } =20 +static struct work_node *test_mthread_buggy(int thread_id, int seq_id) +{ + ulong buf[BUFFER_SIZE]; + struct work_node *node; + bool trigger; + + node =3D kmalloc(sizeof(*node), GFP_KERNEL); + if (!node) + return NULL; + + init_completion(&node->done); + node->ptr =3D buf; + node->start_ns =3D ktime_get_ns(); + mutex_lock(&work_mutex); + list_add(&node->list, &work_list); + mutex_unlock(&work_mutex); + complete(&work_res); + + trigger =3D (get_random_u32() % 100) < 10; + if (trigger) + return node; /* let the caller handle cleanup */ + + wait_for_completion(&node->done); + kfree(node); + return NULL; +} + +#define CORRUPTING_MINIOR_WAIT_NS (100000) +#define VICTIM_MINIOR_WAIT_NS (300000) + +static inline void silent_wait_us(u64 start_ns, u64 min_wait_us) +{ + u64 diff_ns, remain_us; + + diff_ns =3D ktime_get_ns() - start_ns; + if (diff_ns < min_wait_us * 1000ULL) { + remain_us =3D min_wait_us - (diff_ns >> 10); + usleep_range(remain_us, remain_us + 200); + } +} + +static void test_mthread_victim(int thread_id, int seq_id, u64 start_ns) +{ + ulong buf[BUFFER_SIZE]; + + for (int j =3D 0; j < BUFFER_SIZE; j++) + buf[j] =3D 0xdeadbeef + seq_id; + if (start_ns) + silent_wait_us(start_ns, VICTIM_MINIOR_WAIT_NS); + + for (int j =3D 0; j < BUFFER_SIZE; j++) { + if (buf[j] !=3D (0xdeadbeef + seq_id)) { + pr_warn("victim[%d][%d]: unhappy buf[%d]=3D0x%lx\n", + thread_id, seq_id, j, buf[j]); + return; + } + } + + pr_info("victim[%d][%d]: happy\n", thread_id, seq_id); +} + +static int test_mthread_corrupting(void *data) +{ + struct work_node *node; + int fence_size; + + while (!kthread_should_stop()) { + if (!wait_for_completion_timeout(&work_res, HZ)) + continue; + while (true) { + mutex_lock(&work_mutex); + node =3D list_first_entry_or_null(&work_list, + struct work_node, list); + if (node) + list_del(&node->list); + mutex_unlock(&work_mutex); + + if (!node) + break; /* no more nodes, exit inner loop */ + silent_wait_us(node->start_ns, + CORRUPTING_MINIOR_WAIT_NS); + + fence_size =3D READ_ONCE(global_fence_size); + for (int i =3D fence_size; i < BUFFER_SIZE - fence_size; + i++) + node->ptr[i] =3D 0xabcdabcd; + + complete(&node->done); + } + } + + return 0; +} + +static int test_mthread_worker(void *data) +{ + int thread_id =3D (long)data; + int loop_count; + struct work_node *node; + + loop_count =3D READ_ONCE(global_loop_count); + + for (int i =3D 0; i < loop_count; i++) { + node =3D test_mthread_buggy(thread_id, i); + + if (node) + test_mthread_victim(thread_id, i, node->start_ns); + else + test_mthread_victim(thread_id, i, 0); + if (node) { + wait_for_completion(&node->done); + kfree(node); + } + } + return 0; +} + +static void test_mthread_case(int num_workers, int loop_count, int fence_s= ize) +{ + static struct task_struct *corrupting; + static struct task_struct **workers; + + WRITE_ONCE(global_loop_count, loop_count); + WRITE_ONCE(global_fence_size, fence_size); + + init_completion(&work_res); + workers =3D kmalloc_array(num_workers, sizeof(void *), GFP_KERNEL); + memset(workers, 0, sizeof(struct task_struct *) * num_workers); + + corrupting =3D kthread_run(test_mthread_corrupting, NULL, "corrupting"); + if (IS_ERR(corrupting)) { + pr_err("failed to create corrupting thread\n"); + return; + } + + for (ulong i =3D 0; i < num_workers; i++) { + workers[i] =3D kthread_run(test_mthread_worker, (void *)i, + "worker_%ld", i); + if (IS_ERR(workers[i])) { + pr_err("failto create worker thread %ld", i); + workers[i] =3D NULL; + } + } + + for (ulong i =3D 0; i < num_workers; i++) { + if (workers[i] && workers[i]->__state !=3D TASK_DEAD) { + usleep_range(1000, 2000); + i--; + } + } + kfree(workers); + + if (corrupting && !IS_ERR(corrupting)) { + kthread_stop(corrupting); + corrupting =3D NULL; + } +} + static ssize_t test_dbgfs_write(struct file *file, const char __user *buff= er, size_t count, loff_t *pos) { @@ -90,6 +262,15 @@ static ssize_t test_dbgfs_write(struct file *file, cons= t char __user *buffer, case 2: test_recursive_depth(0); break; + case 3: + test_mthread_case(1, 20, BUFFER_SIZE / 4); + break; + case 4: + test_mthread_case(20, 1, BUFFER_SIZE / 4); + break; + case 5: + test_mthread_case(1, 1, -3); + break; default: pr_err("Unknown test number %d\n", test_num); return -EINVAL; @@ -112,7 +293,10 @@ static ssize_t test_dbgfs_read(struct file *file, char= __user *buffer, "echo test{i} > /sys/kernel/debug/kstackwatch/test\n" " test0 - test watch fire\n" " test1 - test canary overflow\n" - " test2 - test recursive func\n"; + " test2 - test recursive func\n" + " test3 - test silent corruption\n" + " test4 - test multiple silent corruption\n" + " test5 - test prologue corruption\n"; =20 return simple_read_from_buffer(buffer, count, ppos, usage, strlen(usage)); --=20 2.43.0