From nobody Mon Sep 28 23:55:53 2026 Received: from mail-pl1-f182.google.com (mail-pl1-f182.google.com [209.85.214.182]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id BD71747012B for ; Fri, 14 Aug 2026 15:14:03 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.214.182 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786720445; cv=none; b=SHfQO8pOhrZZ48Pof1SWtj82WcQNVLCjLrvzRpD9NGH0tg+dqkscFdKPBNWuPYGWQ1K3mfrDuQ40BmswJOXzGs9OjVWUmOSR5EpjnWgJIFf3KfHWSrtn+FXCHULESIV5agLfIEyA5MaEC5k6JW1SrzVER4/TK0VtRzOBOvTvNAE= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786720445; c=relaxed/simple; bh=qpflxoDz4Q2LAuHcccN97A6fnIkF2G+PGjFWuzstZS0=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=gtaNeU0Dckf3D1DfITfPZGwk31N+uSI0AcFjXOeiewZ0UfsSXYcvNqn6DO6zFg/V1AHXks4nF0CjoLdqTGve6G9hb+4oYLWe15Z0YbJ1JJhVb40zrTZVJI0AevUBe+ztFwVE4jz5tz8jFoOzOnM+dGz/PRR7n8If79uZSPqKFyU= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=geFEbckE; arc=none smtp.client-ip=209.85.214.182 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="geFEbckE" Received: by mail-pl1-f182.google.com with SMTP id d9443c01a7336-2cc73e322dbso17861735ad.1 for ; Fri, 14 Aug 2026 08:14:03 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1786720443; x=1787325243; darn=vger.kernel.org; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :content-type:mime-version:subject:date:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=2AwaiBewPNb0w3Qz67JVI0ysWpkdHoufX6g1rsCJvXo=; b=geFEbckE4Lw56iKVwnojpRE74iHpkA0lJqcb6MN4Eywh7En/+adTRTIuPnmyJGPlPi 8nYMPCfCjQCrBy0N/Uc25/e9viWtj65NBFKccAGzca3bB5AJ/ZqWevDklFr4HsmPetgU amWNN0cEVd6qeWxHnWabfej8peHNhWVD7n7pGpMcepGvFqPf2DP7T60tdzzdO5BGuVVk QAYVth2VNi8fBk6ATNQp34iinUilhy3hR5CJQBsVKIci44oA4lBJut4auteJ9KBav9if aldjze7pr8FyhPPcRLuPAvKGHO/1JMpHGam4OuOfivp2GOLBPQ+4NmfFP1m/nvj5saCw anRA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1786720443; x=1787325243; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :content-type:mime-version:subject:date:from:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=2AwaiBewPNb0w3Qz67JVI0ysWpkdHoufX6g1rsCJvXo=; b=pTU/wr/YVPS3SGViFW8tf5azn3dlzQEI0aaFW+HZswL7ck5eWY8d979JmqocI89JnI 9QHt+xYQlLaORr8B46WryW5+3L+6eRCGaR5v4eiMKhfYwYaF0Fum3sm8yYJvqSFalGaI DXoR/Ri+b+EuSlWEFc+aJ0WSOmNYNuJyjnE5dAsjIH+ejtVcWDlpUCKxb4+Zh1FDeYlK 85BdUt1sVoFfogNYkvrgoaT2XeYiZGke+cvKc+aiMH/GcjRBolX2/Sf5X+46zIu4xiEF gmP4ocUUvYvIpLaBp/pMxZhJ+muze2msC1txRYraeMTEkaQqRNFQvl76cAqVdHX9dGEZ u9yw== X-Forwarded-Encrypted: i=1; AHgh+RoQ0HcVPQCgm4xTvwWeVZdy0zkiQM3SG/TP27AL3gl2rUE5OrIEqk7x4I7dlbUcfVppDhLffiYNbGRk0Jw=@vger.kernel.org X-Gm-Message-State: AOJu0Yz4eVLuxAhPwy8A/ABV4tD8gvkP1KbMYqrb0rHIvdB7q3hMDqhJ R7V1u5E1jrm7JE/T39XKB13gGljqSdZg4YmRWvN9Ay6P+2DOmkvmMqB9 X-Gm-Gg: AR+sD10bdF/0uReFNWm81o4vABX7ytzJcueiGSgFX3MsHlnFBM587ivsPBgGhgOmmXq plS4BternST5CJ9ZZTJYdvQ8D1w1kDyhnq4bTyCALC57ePQsqP6O2lK/J2IkC3pG52/x0oEFWnP Kc+lDj9EKHlNPzmJRiZ0HjBYZVOqmr9xU6o9vjtHPeJHF4xaMgHDBtcA7zTqdeLDLaLOrg5xYad sbQnX5wxDEXdvuFAIi0Qgh+NysZ2iOc3BgA8KLPuOR/mAAe+yVMq091LC58kew52fF36aMBLqbW OPrffb5S6Z9hrvIr7Tk6Wp6J0zCtW1nm2EWsXA1oWld9nGGRTpOLyCmufx6Gc9hkyo9WzQD/lNO c+oNcyvSKErSGaWZfmcNRn96+67VZW+yyZReWGbFI4Xh5kwh16LoIegKe13x8EIWVT7I4PvhUFz qWzhRmh28sJG+TfBXJcVtRrml2ViZehr2p1QVmeT7ZMw8CXz+CB12L8gEL2EQ= X-Received: by 2002:a17:902:fc4e:b0:2d5:2f49:b3de with SMTP id d9443c01a7336-2d52f49c24bmr37915325ad.0.1786720442919; Fri, 14 Aug 2026 08:14:02 -0700 (PDT) Received: from LAPTOP-N3B6U5LC.localdomain ([117.147.100.52]) by smtp.gmail.com with ESMTPSA id d9443c01a7336-2d3aec22f98sm11006395ad.84.2026.08.14.08.13.58 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Fri, 14 Aug 2026 08:14:02 -0700 (PDT) From: Zhenhao Wan Date: Fri, 14 Aug 2026 23:13:39 +0800 Subject: [PATCH 1/3] powerpc/spufs: fix gang->alive double-decrement on context creation Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260814-spufs-groupa-v1-1-f38f7549ce20@gmail.com> References: <20260814-spufs-groupa-v1-0-f38f7549ce20@gmail.com> In-Reply-To: <20260814-spufs-groupa-v1-0-f38f7549ce20@gmail.com> To: Madhavan Srinivasan , Michael Ellerman , Nicholas Piggin , "Christophe Leroy (CS GROUP)" , Al Viro , Paul Mackerras , Arnd Bergmann , Jeremy Kerr Cc: linuxppc-dev@lists.ozlabs.org, linux-kernel@vger.kernel.org, Junrui Luo , Zhenhao Wan , Yuhao Jiang , stable@vger.kernel.org X-Mailer: b4 0.15.2 X-Developer-Signature: v=1; a=ed25519-sha256; t=1786720431; l=1857; i=whi4ed0g@gmail.com; h=from:subject:message-id; bh=qpflxoDz4Q2LAuHcccN97A6fnIkF2G+PGjFWuzstZS0=; b=jOy/AYDd7EIMyxpncNLcvaCapZRp5eD3TFKXnXkKchB1tiySy2Lxb7xaouIDUj8swq8VvCdOl r2oHCGZedZqDRTjy8MjdP7EmQbMu6SA+ilnKvxfC4Uj5p9bBZZTcp9Z X-Developer-Key: i=whi4ed0g@gmail.com; a=ed25519; pk=zRTKlstE0LmilshGwJsFYEVjiT6RiXMBXK8Og6VmuVQ= spufs_create_context() takes a reference on the gang with gang->alive++ and is meant to hold it until the context directory is closed, at which point spufs_dir_close() -> unuse_gang() drops it again. The error epilogue instead reads: ret =3D spufs_context_open(&path); ... if (ret && gang) gang->alive--; // can't reach 0 spufs_context_open() returns a non-negative file descriptor on success, which is non-zero whenever the caller already holds an open fd. The condition therefore fires on the success path too, dropping the reference immediately; unuse_gang() then decrements it a second time at close. The unbalanced double decrement can drive gang->alive to zero prematurely, while contexts still reference the gang, triggering simple_recursive_removal() of the gang directory too early. Test the sign of the return value instead, so the reference is only released on actual failure -- matching the idiom already used by spufs_create_gang(), which calls unuse_gang() only on ret < 0. Fixes: c134deabf478 ("spufs: fix gang directory lifetimes") Reported-by: Yuhao Jiang Assisted-by: Claude:claude-opus-5 Cc: stable@vger.kernel.org Signed-off-by: Zhenhao Wan --- arch/powerpc/platforms/cell/spufs/inode.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/arch/powerpc/platforms/cell/spufs/inode.c b/arch/powerpc/platf= orms/cell/spufs/inode.c index 2b54afb31529..23619fbe0bd9 100644 --- a/arch/powerpc/platforms/cell/spufs/inode.c +++ b/arch/powerpc/platforms/cell/spufs/inode.c @@ -436,7 +436,7 @@ spufs_create_context(struct inode *inode, struct dentry= *dentry, out_aff_unlock: if (affinity) mutex_unlock(&gang->aff_mutex); - if (ret && gang) + if (ret < 0 && gang) gang->alive--; // can't reach 0 return ret; } --=20 2.34.1 From nobody Mon Sep 28 23:55:53 2026 Received: from mail-pl1-f175.google.com (mail-pl1-f175.google.com [209.85.214.175]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id C32F747FB1E for ; Fri, 14 Aug 2026 15:14:07 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.214.175 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786720449; cv=none; b=o4CBHOTBdY2X4GQlw95egSb6Uwllt7LXcI9ylJJe4lIV/Nwu2yu+EvB9kg3QEdqOT1cAwYLvPxShTr9G5jRDiw95/+at2F8Zn9AM9laRciTM64s28ygJ+U+P1vaheJYn0Jq+80CVEon8muj9YEHZEo3DvMuyjhs3YqglP062dZo= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786720449; c=relaxed/simple; bh=VFKeXyJTX5elzCK/iZOeCAqEbI268lQudBfzIl/EEBk=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=k7pSDppmUsOK6/9H5O9GnGjmdMb5/bUQh6NhH/u/4tXUWjnAIvkrn3WNpZ1eBob4sntVSce9fyu8CveVQltngI/XtvpvTWnU5N5/llVSIfEDXf3fCt/PyPYoDUJsWY+EwjZYEBI68CkZQo7Zz6bOvhtK+1AddZJXKzqFtSh8h3A= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=XTFfnkDV; arc=none smtp.client-ip=209.85.214.175 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="XTFfnkDV" Received: by mail-pl1-f175.google.com with SMTP id d9443c01a7336-2ce7d2adef4so19589335ad.3 for ; Fri, 14 Aug 2026 08:14:07 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1786720447; x=1787325247; darn=vger.kernel.org; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :content-type:mime-version:subject:date:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=evqg/wCVmloNStWe7p9zX457kvwkpQrapIFq3Q4j/Ts=; b=XTFfnkDVS4Zq1xZMqAGvvQVKsZUpNSOsAfhzWs9uNK/YIzXPscSuwncOB+nNyplbXy E7iNfOeYNqpz3IWezwX/TJedWjm5pKAaOWvK+hIZ3qouYIA4gs57KvBq/w2Gt1oB+96e YPGfcM8RGAdwCd3HwSLUiTWRlDcFA6i8OGimk0HbpVzTlVCJmZHguRfgMzvCImZSC2Il w8RpkR0RdMdztWAwMJIIQrdZnk0fm044N6495bZyflefAqImUFdn8Nd2cjz7uu4rc05Q mqaJtVuqaa68UTzogGemaL1c4/8yq3oTeyl+DdEEg8uQugK2YFXOl3hyPwRK+sWxyJx9 okaQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1786720447; x=1787325247; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :content-type:mime-version:subject:date:from:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=evqg/wCVmloNStWe7p9zX457kvwkpQrapIFq3Q4j/Ts=; b=lX5oMevZgnI2Fy8F7usmvdG4cDD5yJNjiMvdzPPfki6SrA5DGUNkPToZ7l60YnYFcP WrkCl1lRoZUlrI09guiIoVz6jaNUyaDGodXinSBGTvvrvB5Akn4gIISvCsQT95lWWIsc RzL1jXj+TGE9zwX7Tmn05KXzZs4ReY/RlqZsubG2hH3DLXnGj50Pee6gnqDj8aaOaFoD 1+Eu3LNX5ev4e3NT5LrKW4KEODgz/kMbrqJl1mNbmUKf3LCQELrKZ8MW933Yr49OXViN uGfMd2K1Xtz6/rQ2JSH3+weghMwJHjP9WnVuLzsAPZ9g48xNArGJgJXphIfk5c53I3nS 30ew== X-Forwarded-Encrypted: i=1; AHgh+RpzDHOnjrucwk/+MrO/W80QRZjYmvGdzEFI7cg71vvn+YJt5Oet7wGwsaNX29fz93ootzhHS0puC7FPZv4=@vger.kernel.org X-Gm-Message-State: AOJu0Yy+ZK0CqbL4UerdMbISN7qrYEm0qzwa4iJG94s3uXhzXwRKg4yG 9fcZlyOrZY5C/HvPpo4QGNqY9XPDL9Aaq5M/ZIU3A1XqEu6KoHIyYFlu X-Gm-Gg: AR+sD11fgg3jMe5yzH26VwFpoA+ZYQFrfKXDAYaOV5GgiKlb7m+CG0x7LXGbZbCkMgx e1aVRZVkLsj2icA53SWBy3zXnBpVk6uWlkY3qywJQAlN7T5JNnAiv4si2dneaZewbFKE9s8RFlu 4++/2Yd8i+MBbW0xO5UpJrmSx3cNJmyMKoEhyl8wDozLDINpp6GpMgumHb3JrnseL+ev9uUQxU0 FW4/9RQCg9XKIwFUDZsHrrCOZcp4g3C5aT8sF7TokmhcOzgOQ5UpGzv4u54q7qJDHqdHJNYZr5D FjUH9ZrUvZAbavvRk3O0n3WbU7vFFapEkkTSwcpQ6HYElY7QcKX268g3IuPJ1nsxC39MMjC7+PV 3ojasuh3G2vmnxfTZqLUYuUOltHENttO6p8N19Cyx3VBWL/f8UL9sPelobTNkdVQ5z6xtYznNid s1EN4iwGKJTkaUnT5h40qLfhztyu9Ta36xPJ0Ap6/cASqX799WXKcD/FXmWimt86wh X-Received: by 2002:a17:903:98b:b0:2d3:14c6:2372 with SMTP id d9443c01a7336-2d3b080bf23mr87501645ad.1.1786720446877; Fri, 14 Aug 2026 08:14:06 -0700 (PDT) Received: from LAPTOP-N3B6U5LC.localdomain ([117.147.100.52]) by smtp.gmail.com with ESMTPSA id d9443c01a7336-2d3aec22f98sm11006395ad.84.2026.08.14.08.14.03 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Fri, 14 Aug 2026 08:14:06 -0700 (PDT) From: Zhenhao Wan Date: Fri, 14 Aug 2026 23:13:40 +0800 Subject: [PATCH 2/3] powerpc/spufs: fix type confusion in cntl mmap fault handler Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260814-spufs-groupa-v1-2-f38f7549ce20@gmail.com> References: <20260814-spufs-groupa-v1-0-f38f7549ce20@gmail.com> In-Reply-To: <20260814-spufs-groupa-v1-0-f38f7549ce20@gmail.com> To: Madhavan Srinivasan , Michael Ellerman , Nicholas Piggin , "Christophe Leroy (CS GROUP)" , Al Viro , Paul Mackerras , Arnd Bergmann , Jeremy Kerr Cc: linuxppc-dev@lists.ozlabs.org, linux-kernel@vger.kernel.org, Junrui Luo , Zhenhao Wan , Yuhao Jiang , stable@vger.kernel.org X-Mailer: b4 0.15.2 X-Developer-Signature: v=1; a=ed25519-sha256; t=1786720431; l=2202; i=whi4ed0g@gmail.com; h=from:subject:message-id; bh=VFKeXyJTX5elzCK/iZOeCAqEbI268lQudBfzIl/EEBk=; b=AG14nyeb4IhnSCPWTjL4v8+rNjf0tPtUgxRKsImcMSuFPJsj0j8j4vy4E/bgRcAa0zpWN1tVF s751jK9hQFeDsWUorEwvFI2E+VYhX0W25tuCT9Ksr5+4vzAyq5HFQ9y X-Developer-Key: i=whi4ed0g@gmail.com; a=ed25519; pk=zRTKlstE0LmilshGwJsFYEVjiT6RiXMBXK8Og6VmuVQ= spufs_ps_fault() recovers the SPU context from the faulting file with struct spu_context *ctx =3D vmf->vma->vm_file->private_data; This is correct for most spufs files, whose ->open stores the context in file->private_data. The cntl file is the exception: spufs_cntl_open() sets file->private_data =3D ctx but then calls simple_attr_open(), which allocates a struct simple_attr and overwrites file->private_data with it so that simple_attr_read()/write() work. cntl is also the only such file that installs an mmap fault handler (spufs_cntl_mmap, on 4K-page configs). When that mapping is faulted, spufs_ps_fault() reads back the struct simple_attr as a struct spu_context and dereferences it (ctx->state, ctx->spu->problem_phys), feeding a bogus value into vmf_insert_pfn() -- a type confusion reachable by an unprivileged opener of the 0666 cntl file. Obtain the context from the inode instead, which always refers to the real spu_context regardless of what ->private_data holds, matching how coredump_next_context() and the affinity path already fetch it. This is equivalent for every other spufs_ps_fault() caller and removes cntl's dependence on a pointer that simple_attr_open() owns. Fixes: e1dbff2bafa8 ("[POWERPC] spufs: add support for read/write on cntl") Reported-by: Yuhao Jiang Assisted-by: Claude:claude-opus-5 Cc: stable@vger.kernel.org Signed-off-by: Zhenhao Wan --- arch/powerpc/platforms/cell/spufs/file.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/arch/powerpc/platforms/cell/spufs/file.c b/arch/powerpc/platfo= rms/cell/spufs/file.c index de7494748fec..8c7515140efb 100644 --- a/arch/powerpc/platforms/cell/spufs/file.c +++ b/arch/powerpc/platforms/cell/spufs/file.c @@ -313,7 +313,7 @@ static vm_fault_t spufs_ps_fault(struct vm_fault *vmf, unsigned long ps_offs, unsigned long ps_size) { - struct spu_context *ctx =3D vmf->vma->vm_file->private_data; + struct spu_context *ctx =3D SPUFS_I(file_inode(vmf->vma->vm_file))->i_ctx; unsigned long area, offset =3D vmf->pgoff << PAGE_SHIFT; int err =3D 0; vm_fault_t ret =3D VM_FAULT_NOPAGE; --=20 2.34.1 From nobody Mon Sep 28 23:55:53 2026 Received: from mail-pl1-f176.google.com (mail-pl1-f176.google.com [209.85.214.176]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 1656D47FB13 for ; Fri, 14 Aug 2026 15:14:11 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.214.176 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786720453; cv=none; b=HBH4eoOP/VQqGfJ8ndrvitaKYTFXR73h8RtWvDxmlYJjqxNnIL+v/XxVYmpNXeA1B/cjKr3En60baejF3uDWEuKq0P12iqpHw58xwI/ni5JAW8JJxQVEXbUoioiOWfE72IGGBDbuIDgb1pJNG5EWyiIcFVr57y2X3607wuBkQvA= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786720453; c=relaxed/simple; bh=kmE7rvL6rE2nTVpZ7i0QDNXuT7Q9+9BkFYard4CiRO8=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=I0qP+crGfUv3SyTiV9URPlQTtUEh4PPxzlsZ8xyOfm77+TMqEHNYAvHFyWUlQQBIUy6+xNuewbx5gjACOCITI2C9rDHHswkEG0qVC9Y0oTjWZY1fQB0K2E0WeNjOHaSGnc/yiTGOHJ80rweGihyoVyobdPp1EWQLe40PbAyoXGY= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=s+LiAZM6; arc=none smtp.client-ip=209.85.214.176 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="s+LiAZM6" Received: by mail-pl1-f176.google.com with SMTP id d9443c01a7336-2cf27856f9cso11253565ad.2 for ; Fri, 14 Aug 2026 08:14:11 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1786720451; x=1787325251; darn=vger.kernel.org; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :content-type:mime-version:subject:date:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=QwrpjQ4RLs0fxaL+2HIhI7tahvYcqYH+F4/hh3arkZI=; b=s+LiAZM6QYiz3kZzmDF8t60Y9uQ4lUIOwA8RKr5m8Qeq1S4n9fef5jzIsEuezIOowN rGSGTdZ9+iTI1oZamP+7vOz0axR9roBilxp6Ij/HE2Dsy42F+He3a8+28KzB1CY9QDqr zkGl1D8v43LPvB1cY7IQoslyUvCmCZeCsVduxd6koWW7uLQXErs1KLfkTR4JAcx2IJpV VZivPk5nB/jbOudadff1hk62kmvH5MMZrsgRG7OXZXzp/Sl/j2PkFNtokie8zgwx+EBX hL4Lj9YVrJSxM8LeKSuxSnnbirho+MLDF3CiNiyB7M/q59dlCu0NIXQ71AF9VfDhzgt2 YQIg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1786720451; x=1787325251; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :content-type:mime-version:subject:date:from:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=QwrpjQ4RLs0fxaL+2HIhI7tahvYcqYH+F4/hh3arkZI=; b=fWpEECtdz39BO5HwtfOW7ofIN1KtmwDzkXvNiIvFZkzN7/lzRO/zSTx44itTDZbW7J EBcL+kvXqIorT1NOL1uOEjbdBVkl1tDaaiPZ0pBH3gNs0Z0c5alSuDGccC/SL3ocPSNS O/guUkC8T2b4kTmAV7QMtqG4bvRzqZ3TA4U33xRVjt/3iu9oO1/uKcmRkTjccHhWju4x jTrNm/T8FZvA4MrBBGNdhGKV52eHg+o9UgZENWyBgZn+nrvjnyLNZN4dvktKWVqyLA41 faX1xxzkNKASBWaXXLXdJinraAN1aiHbYroLaPh7JaWpGhzvDFno0nA1k93gkFaK3PeT UP/g== X-Forwarded-Encrypted: i=1; AHgh+Rqv1AeYseWjgpWrAgQTW8RWSyYERqCzJtS9S7AUeq2eMSCGSPsAoDdNH5X6z7hSoWhSeacoHMItI15P9P0=@vger.kernel.org X-Gm-Message-State: AOJu0Yye/fscTDLh9dM3BkQnAWwgDPTzaAO/8XY+U6uiLuEk2ArsaRB8 rJ3b+6ZmWUX3OMmXUIA6pVoMly+sa32y6+9hig9qO6A74bffZwltJH71 X-Gm-Gg: AR+sD10jgHJgQhqEJEQpc0+XVd8I+JjcXl2x/SdbBOFkAs203izngxxGTVMiJfWfURR 1aYvv8EpwTTY97sEmbtd7fLpHPXuQJ1z4UMLkkyFrG50Xvz6H5Kf8NFq3J7R47SX/oQE8my1y4E Srk/QrX+S13begZkfx74iSSyUodoQ3Fwrb0zJceevXgSDM7p28KUK0LLXV93G99IgwVJuVtpOIn eCj+NwOFq32kEk+zmFYPr6Kl3oMZzdHNZSh684LfExtqwzY9ZhC2ljRBNU0SrDnOHm1gGf6udi8 1b/VArBxn9wK+ZaiJEHG+Zu8ezX1YA/r0Y7vlXTHOXX/5a3lvJC3MiLxgrqYg9lKyA0gGKhO23M U3/ZnDOCDDrznU0mdF4gvdJ6kFeuZDP3XPUpPIdZsFR3zlbaukMjyVPqJF/JvNclQooDQYrDff8 oVsOrPaFsH2l3psdpkTNPNvJ532VOIU7xX3K5BDJLOziO5iya5zp4UlaESfdDdznpdI/WQEA== X-Received: by 2002:a17:903:292:b0:2d5:276e:3e21 with SMTP id d9443c01a7336-2d5276e49b0mr56410185ad.23.1786720451133; Fri, 14 Aug 2026 08:14:11 -0700 (PDT) Received: from LAPTOP-N3B6U5LC.localdomain ([117.147.100.52]) by smtp.gmail.com with ESMTPSA id d9443c01a7336-2d3aec22f98sm11006395ad.84.2026.08.14.08.14.07 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Fri, 14 Aug 2026 08:14:10 -0700 (PDT) From: Zhenhao Wan Date: Fri, 14 Aug 2026 23:13:41 +0800 Subject: [PATCH 3/3] powerpc/spufs: fix backwards coredump skip from undersized notes Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260814-spufs-groupa-v1-3-f38f7549ce20@gmail.com> References: <20260814-spufs-groupa-v1-0-f38f7549ce20@gmail.com> In-Reply-To: <20260814-spufs-groupa-v1-0-f38f7549ce20@gmail.com> To: Madhavan Srinivasan , Michael Ellerman , Nicholas Piggin , "Christophe Leroy (CS GROUP)" , Al Viro , Paul Mackerras , Arnd Bergmann , Jeremy Kerr Cc: linuxppc-dev@lists.ozlabs.org, linux-kernel@vger.kernel.org, Junrui Luo , Zhenhao Wan , Yuhao Jiang , stable@vger.kernel.org X-Mailer: b4 0.15.2 X-Developer-Signature: v=1; a=ed25519-sha256; t=1786720431; l=3216; i=whi4ed0g@gmail.com; h=from:subject:message-id; bh=kmE7rvL6rE2nTVpZ7i0QDNXuT7Q9+9BkFYard4CiRO8=; b=ejsdnLFdgUK5znL13j1wUljuO6RMq2kZ8mUgFDOuS4cbOhUkMQm9bGTRz0kLkctS2m8wT13GK C1dMqOTe7oWD4oTXdnZrT50XHPTdlb9D01JY8wF4kfvqdKaqvp5IOyE X-Developer-Key: i=whi4ed0g@gmail.com; a=ed25519; pk=zRTKlstE0LmilshGwJsFYEVjiT6RiXMBXK8Og6VmuVQ= spufs_arch_write_note() positions the next coredump note with dump_skip_to(cprm, roundup(cprm->pos - ret + sz, 4)); where sz is the note's declared spufs_coredump_read[].size and ret is the number of bytes the dump callback actually emitted. It also stores sz in en.n_descsz and reserves roundup(sz, 4) bytes in spufs_ctx_note_size(). Three entries declare sizeof(u32) but their dump callbacks emit a u64: - "signal1"/"signal2" emit sizeof(ctx->csa.spu_chnldata_RW[n]), and spu_chnldata_RW is u64; - "ibox_info" emits sizeof(ctx->csa.priv2.puint_mb_R), and puint_mb_R is u64. The mismatch only bites when the dump emits data: each callback returns 0 unless a signal/mailbox entry is pending. When one is present ret (8) exceeds sz (4), so roundup(cprm->pos - ret + sz, 4) lands *before* cprm->pos and dump_skip_to() computes a size_t to_skip that underflows to nearly SIZE_MAX. The following dump_emit() then fails, truncating the core dump on a regular file (or, on a pipe, zero-filling up to RLIMIT_CORE before aborting). n_descsz is likewise understated, and spufs_ctx_note_size() under-reserves the note by four bytes. Declare these three notes as sizeof(u64) to match what the callbacks emit. For signal1/signal2 this is also what the runtime read returns; ibox_info's puint_mb_R is a genuine u64 field, so its 8-byte dump is in-bounds (its file exposes only the low u32). "mbox_info" (pu_mb_R, u32) and "wbox_info" (emits at most its declared 4 * sizeof(u32) and pads forward) are already consistent and left unchanged. Fixes: 5456ffdee666 ("powerpc/spufs: simplify spufs core dumping") Reported-by: Yuhao Jiang Assisted-by: Claude:claude-opus-5 Cc: stable@vger.kernel.org Signed-off-by: Zhenhao Wan --- arch/powerpc/platforms/cell/spufs/file.c | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/arch/powerpc/platforms/cell/spufs/file.c b/arch/powerpc/platfo= rms/cell/spufs/file.c index 8c7515140efb..7d8c733ccac0 100644 --- a/arch/powerpc/platforms/cell/spufs/file.c +++ b/arch/powerpc/platforms/cell/spufs/file.c @@ -2588,14 +2588,14 @@ const struct spufs_coredump_reader spufs_coredump_r= ead[] =3D { { "decr", NULL, spufs_decr_get, 19 }, { "decr_status", NULL, spufs_decr_status_get, 19 }, { "mem", spufs_mem_dump, NULL, LS_SIZE, }, - { "signal1", spufs_signal1_dump, NULL, sizeof(u32) }, + { "signal1", spufs_signal1_dump, NULL, sizeof(u64) }, { "signal1_type", NULL, spufs_signal1_type_get, 19 }, - { "signal2", spufs_signal2_dump, NULL, sizeof(u32) }, + { "signal2", spufs_signal2_dump, NULL, sizeof(u64) }, { "signal2_type", NULL, spufs_signal2_type_get, 19 }, { "event_mask", NULL, spufs_event_mask_get, 19 }, { "event_status", NULL, spufs_event_status_get, 19 }, { "mbox_info", spufs_mbox_info_dump, NULL, sizeof(u32) }, - { "ibox_info", spufs_ibox_info_dump, NULL, sizeof(u32) }, + { "ibox_info", spufs_ibox_info_dump, NULL, sizeof(u64) }, { "wbox_info", spufs_wbox_info_dump, NULL, 4 * sizeof(u32)}, { "dma_info", spufs_dma_info_dump, NULL, sizeof(struct spu_dma_info)}, { "proxydma_info", spufs_proxydma_info_dump, --=20 2.34.1