From nobody Mon Sep 28 13:18:02 2026 Received: from va-1-113.ptr.blmpb.com (va-1-113.ptr.blmpb.com [209.127.230.113]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id F27AD466B0E for ; Fri, 21 Aug 2026 09:48:23 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.127.230.113 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787305709; cv=none; b=glccv0qKKQ94+KGvcE+fvBdq6iCAg1JFeIa4kP3Y6P3tLsUD7GFAErAfpY1StcalAMdMH+lihCklBwiCU6wczNpdUd+yiBFYnGV1FhwlnaLZ49GXziA6axkvzV+GN8uNHrpS92iTho2QjUwr/2fULh9wYJEXYh6ljLwRSz5lHTA= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787305709; c=relaxed/simple; bh=oofEVVxLr6mgzoTgOP7uIro06mlSNjfSVYpM0Jc4gVk=; h=From:In-Reply-To:Content-Type:Cc:Subject:Message-Id:References:To: Mime-Version:Date; b=B4btN5tqYe352h4Y9Ye3Qo2WAliRsfszLC2sWeOBRlty/N9ApIqijtSxy1u2IwQRk3HKhWyTMMs6n6SGrJjH7wPzz7+58kN7wQ0yJn4qyg6d8F3Tdyx+tIZd16pJte0rRcE1CUPZqdyu1qrB7UoL+tDxGqtuyHCxHgTxF2R/vWY= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=bytedance.com; spf=pass smtp.mailfrom=bytedance.com; dkim=pass (2048-bit key) header.d=bytedance.com header.i=@bytedance.com header.b=bMoDC9Ym; arc=none smtp.client-ip=209.127.230.113 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=bytedance.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=bytedance.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=bytedance.com header.i=@bytedance.com header.b="bMoDC9Ym" DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; s=2212171451; d=bytedance.com; t=1787305692; h=from:subject: mime-version:from:date:message-id:subject:to:cc:reply-to:content-type: mime-version:in-reply-to:message-id; bh=AXx9j9m8Lc8aO7XPmh5HBF1sx0KZ+TcvBSs6HuGDW/Q=; b=bMoDC9YmPcS64qTuCipdpEIWMXsw4bbbebej0ISIsBd20qpId6PN6ax+DL8XEkFGIbVX8F BbFj1W4GFPYlOkY+gB3/xf5uiJKmFAToRbAbqahog2hroeTEXNsnFR6AsLtVyoXZshxp9h N4IYrAliTZcTPRMBfMluASRvd8s6Uev4sVXY+gLxFm7yRXgJC4elZoODgQ40619Oq94c/L XZvagAyerwYb4lhpbGds1EdAMpiqQ2kifchuQSrhdA/Cv2GAOe+oFyTUhWh391t2mX60N0 bMlSAeRCrCpv8yfTNNvxnLy+DN30ttvElPCNZ7ZSVaYrAyBOUr3soFqWbVHavA== X-Lms-Return-Path: X-Original-From: Rui Qi Content-Transfer-Encoding: quoted-printable From: "Rui Qi" In-Reply-To: <20260821094748.145394-1-qirui.001@bytedance.com> Cc: , , , , "Rui Qi" Subject: [PATCH 1/4] RAS/amd/fmpm: Fix out-of-bounds read in for_each_fru macro Message-Id: <20260821094748.145394-2-qirui.001@bytedance.com> References: <20260821094748.145394-1-qirui.001@bytedance.com> To: Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 X-Mailer: git-send-email 2.20.1 Date: Fri, 21 Aug 2026 17:47:45 +0800 Content-Type: text/plain; charset="utf-8" The for_each_fru macro evaluates the array access "rec =3D fru_records[i]" before the bounds check "i < max_nr_fru" due to the comma operator's left-to-right evaluation order. When the loop terminates, i equals max_nr_fru, causing fru_records[max_nr_fru] to be read before the condition is checked. While the garbage pointer value assigned to rec is never dereferenced (the loop exits immediately), this is technically undefined behavior and would be flagged by UBSan and static analyzers. Fix by using short-circuit evaluation with && to check the bound first, only accessing the array when i is within range: for (i =3D 0; i < max_nr_fru && ((rec =3D fru_records[i]), 1); i++) Fixes: 6f15e617cc99 ("RAS: Introduce a FRU memory poison manager") Signed-off-by: Rui Qi --- drivers/ras/amd/fmpm.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/drivers/ras/amd/fmpm.c b/drivers/ras/amd/fmpm.c index 4ccaaf7b70bf..91c49080873e 100644 --- a/drivers/ras/amd/fmpm.c +++ b/drivers/ras/amd/fmpm.c @@ -169,7 +169,7 @@ static unsigned int spa_nr_entries; static DEFINE_MUTEX(fmpm_update_mutex); =20 #define for_each_fru(i, rec) \ - for (i =3D 0; rec =3D fru_records[i], i < max_nr_fru; i++) + for (i =3D 0; i < max_nr_fru && ((rec =3D fru_records[i]), 1); i++) =20 static inline u32 get_fmp_len(struct fru_rec *rec) { --=20 2.20.1 From nobody Mon Sep 28 13:18:02 2026 Received: from va-1-114.ptr.blmpb.com (va-1-114.ptr.blmpb.com [209.127.230.114]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 0A6EA46983A for ; Fri, 21 Aug 2026 09:48:26 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.127.230.114 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787305717; cv=none; b=G7dmBGshH6d8571BHfTmNxdzV7eROaNeqimeW0ApTmJ380PcEPGFWPIsmxXxoHgF2F+UhbIabJWKVrTziYmAdSSl2VsR1g52nAP9p/Cg1EyDrhk2U8C5tzq0dvFFDEuoBoYFBq4uAS2iw/bLUpUIYKdriqoEIiZuP7umZGKj0Pw= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787305717; c=relaxed/simple; bh=vveRqZFx/RxyQ7dvEOw79MWBmU54WLPqN/jhtgLsVig=; h=To:From:References:Content-Type:Cc:Subject:Date:Message-Id: Mime-Version:In-Reply-To; b=TMu3NHUa8q3VsTWgrB1/HoKSOcb7N8tnlj0YnBIDrjBxIReIUYOHQMq9wQBp5ZkWnL3nT8D8nmv5ynyTG0uufxs3E47k/IjPPhrpdIn58JX78ebt395rdUTLKkcnzAPjYvARdeKvmIKNMTFtLiyx8n5uhyo8eDDeEC0bcbqQspc= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=bytedance.com; spf=pass smtp.mailfrom=bytedance.com; dkim=pass (2048-bit key) header.d=bytedance.com header.i=@bytedance.com header.b=oRaJ9Vso; arc=none smtp.client-ip=209.127.230.114 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=bytedance.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=bytedance.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=bytedance.com header.i=@bytedance.com header.b="oRaJ9Vso" DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; s=2212171451; d=bytedance.com; t=1787305700; h=from:subject: mime-version:from:date:message-id:subject:to:cc:reply-to:content-type: mime-version:in-reply-to:message-id; bh=g/k1wLRcj/Ks0knWs5oR7rhnChhxNSotzVGGyLFePtM=; b=oRaJ9VsosHqSODZ2czZ7SdIzc5EXxwNipgnFO9Ftyt6SONoMa28tI2st4gpYgFZM/20U6u Mincol9Mn8KjYwSNIm5eFXLNndtKKvJGHKRjjM6AqsdKZt85NHAFT9O1Aw+DaVak9PuE1y /z4uUDQPHoB6DpD/jGeKxZZjf+V0Czn25hpEPPQQT+L5bcjCSttMMNq1a3dOPAeAJkK2/Y TCKEnpPfpt+SVELWGr0c48EyDUjI53kKEUDUx/MEvwjCbtbbD5y0NEMOFEUxQ0fJMhinBo ZgOvq1UuDGLdKdQLMUMhSR5QhLVs9snogPYKbwj403f6PkKriuQ7Gnhn+hMYhQ== To: From: "Rui Qi" X-Original-From: Rui Qi References: <20260821094748.145394-1-qirui.001@bytedance.com> X-Lms-Return-Path: Cc: , , , , "Rui Qi" Subject: [PATCH 2/4] RAS/amd/fmpm: Clear new records bitmap before rollback Date: Fri, 21 Aug 2026 17:47:46 +0800 Message-Id: <20260821094748.145394-3-qirui.001@bytedance.com> X-Mailer: git-send-email 2.20.1 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 Content-Transfer-Encoding: quoted-printable In-Reply-To: <20260821094748.145394-1-qirui.001@bytedance.com> Content-Type: text/plain; charset="utf-8" save_new_records() uses a stack bitmap to track which ERST records were created during the current initialization pass. If a later write fails, the rollback path tests this bitmap to decide which records should be removed again. DECLARE_BITMAP() does not initialize stack storage, so the rollback path can observe stale bits and attempt to clear records that were not created by this function. Clear the bitmap before it is used so that only records successfully written in the current pass are rolled back. Fixes: 6f15e617cc99 ("RAS: Introduce a FRU memory poison manager") Signed-off-by: Rui Qi --- drivers/ras/amd/fmpm.c | 2 ++ 1 file changed, 2 insertions(+) diff --git a/drivers/ras/amd/fmpm.c b/drivers/ras/amd/fmpm.c index 91c49080873e..0231163e2634 100644 --- a/drivers/ras/amd/fmpm.c +++ b/drivers/ras/amd/fmpm.c @@ -533,6 +533,8 @@ static int save_new_records(void) unsigned int i; int ret =3D 0; =20 + bitmap_zero(new_records, FMPM_MAX_NR_FRU); + for_each_fru(i, rec) { /* No need to update saved records that match the current record size. */ if (rec->hdr.record_length =3D=3D max_rec_len) --=20 2.20.1 From nobody Mon Sep 28 13:18:02 2026 Received: from va-1-115.ptr.blmpb.com (va-1-115.ptr.blmpb.com [209.127.230.115]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 1E79B470117 for ; Fri, 21 Aug 2026 09:48:39 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.127.230.115 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787305726; cv=none; b=qI+zzyipbfhi44HHKVYug+ojBtUmY7hd50mmBhQZw+MHZjGtlSPaawWYDDZtWROUc/FAYK716+aQxIKs3xUuuMvkWNp/8Nlb1Do1saSKiQj5hdB57uNW3JDQgXHA03Ndwo2+wqZ94I46WRfhdMBv0TnEct8V8dVGleekVp+2PHU= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787305726; c=relaxed/simple; bh=qhA5/94/QtNSz75LoIVzwHN2FusUrji5lvaCMQVOSSo=; h=Mime-Version:To:From:Date:In-Reply-To:Content-Type:Cc:Subject: Message-Id:References; b=KQd6dkiVZ1nBLadH0czn/kcRbIgb4eN/lN1JVoxXXPQejgngs4ABJMnsZk95R9HlRKtaMfbO9al+TPF88gaSkeaZvPn/2PbEVIzRPM8aU5sqpcpwUCTXOvsIIa+y4NvR5b2yXm5mhlcu8mF0StDEBXHyE3PNPkGSiJcEHtCwm1Y= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=bytedance.com; spf=pass smtp.mailfrom=bytedance.com; dkim=pass (2048-bit key) header.d=bytedance.com header.i=@bytedance.com header.b=pLcV71OT; arc=none smtp.client-ip=209.127.230.115 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=bytedance.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=bytedance.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=bytedance.com header.i=@bytedance.com header.b="pLcV71OT" DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; s=2212171451; d=bytedance.com; t=1787305716; h=from:subject: mime-version:from:date:message-id:subject:to:cc:reply-to:content-type: mime-version:in-reply-to:message-id; bh=r/wUl+7sOsBV6JsvoUp2DjG+HjTf0XUxdty+gSMEJw4=; b=pLcV71OTBppDC78KE/lpjTQz+O1bMydmv2saBuFBoEiT3QQDIC9gOboS8tC1BvghjjzCb+ j9PAtpY2RJYFRPRDm8Aax5rSj4UZLol0Tl7zN6cr/KE9T0aNpdBL53TRYRrDrDOLuqwSS6 1oZSKTvXCzeBStOtpHfLf/b3psVkGSGuEQHudVnCuLWl/rzGaJ19t46aNzPXwQgS+WvFUC IGARYZY8SBX28TTdGCyfNvbumf56AMVN/Ym/fc3phpG5wCny/CXIuucxwuJYlMxi6BiJj4 rsihfwTL0ZWQjzzz++7mPadng5PPKiMOD5YbrKoB1QlrTkIBU29TSHOaZPG6mg== Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-Mailer: git-send-email 2.20.1 X-Lms-Return-Path: To: From: "Rui Qi" Date: Fri, 21 Aug 2026 17:47:47 +0800 In-Reply-To: <20260821094748.145394-1-qirui.001@bytedance.com> X-Original-From: Rui Qi Cc: , , , , "Rui Qi" Subject: [PATCH 3/4] RAS/amd/fmpm: Make max_nr_entries read-only Message-Id: <20260821094748.145394-4-qirui.001@bytedance.com> References: <20260821094748.145394-1-qirui.001@bytedance.com> Content-Type: text/plain; charset="utf-8" max_nr_entries is used during module init to calculate max_rec_len. That length determines the size of each allocated FRU record and is not resized after init. Leaving the parameter writable lets a later sysfs write raise the runtime limit used by update_fru_record(), allowing entries beyond the allocated flexible array to be written. Expose the parameter as read-only so it can still be set at module load time, but cannot diverge from the allocation size afterwards. Fixes: 6f15e617cc99 ("RAS: Introduce a FRU memory poison manager") Signed-off-by: Rui Qi Reviewed-by: Yazen Ghannam --- drivers/ras/amd/fmpm.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/drivers/ras/amd/fmpm.c b/drivers/ras/amd/fmpm.c index 0231163e2634..14a103de9d62 100644 --- a/drivers/ras/amd/fmpm.c +++ b/drivers/ras/amd/fmpm.c @@ -138,7 +138,7 @@ static struct dentry *fmpm_dfs_entries; * No input or '0' will default to FMPM_DEFAULT_MAX_NR_ENTRIES. */ static u8 max_nr_entries; -module_param(max_nr_entries, byte, 0644); +module_param(max_nr_entries, byte, 0444); MODULE_PARM_DESC(max_nr_entries, "Maximum number of memory poison descriptor entries per FRU"); =20 --=20 2.20.1 From nobody Mon Sep 28 13:18:02 2026 Received: from va-1-115.ptr.blmpb.com (va-1-115.ptr.blmpb.com [209.127.230.115]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 6425F3B71BD for ; Fri, 21 Aug 2026 09:48:49 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.127.230.115 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787305736; cv=none; b=btwRV62fs3UPPUQp/W6/5dz4YuAK936GocYHyUEdGfPeX3vtyeDZGXxp/6j/ZJP0eLfxs/G2mYdWSlwriNKq14bt2/dZx/gqpD0TsVre27rXm2nLTsAud2b0pSvF/L3EnIKm5QyZzz+M9cqJsvFofLxqnZaALAwvfSHA94yaMt4= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787305736; c=relaxed/simple; bh=JFiLZpv6bNsWUBFWmW4Juu9Ple+T0UPfksCS7Y280MI=; h=Message-Id:Mime-Version:To:Date:References:Content-Type:Cc:From: Subject:In-Reply-To; b=l+12na01eu+vBgW0hPwCQvnAPR0yJJ+6L0PvvULXMx1/uT0No8nW8G487UUERIopdwE069uRim1V0+Rz7tEvKygr+lQQF3bB/4xljeXv3mjBeDWNe7gwWL0B8SjhhyfcZwyKCtLZlDPtPUbfTG5Xd339IJN8p0ZjYwAE6xcL96M= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=bytedance.com; spf=pass smtp.mailfrom=bytedance.com; dkim=pass (2048-bit key) header.d=bytedance.com header.i=@bytedance.com header.b=KWVOpvvw; arc=none smtp.client-ip=209.127.230.115 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=bytedance.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=bytedance.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=bytedance.com header.i=@bytedance.com header.b="KWVOpvvw" DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; s=2212171451; d=bytedance.com; t=1787305725; h=from:subject: mime-version:from:date:message-id:subject:to:cc:reply-to:content-type: mime-version:in-reply-to:message-id; bh=zyVrZJ5IZx0CCZ48i4+32zgz1kVSbJppEcwWzNCanuA=; b=KWVOpvvwHsmQLAgO1vi44oXNCIPz2owzRyg4R92wRpJ8T8A3/xTNw5w1L0bqTd9O/A6WUQ US659GtCSmVK3gHyfLVtsQH9Tfdunr+YiqfLEwZpszu59oDAZo2tOsb2JXZB+Jj69LoB93 kozm3T4ye7vifgnnncc1BAOCXs3D3XRzqlAqhOZZ+0AutTlHgcsqqbOt/HO3KAtmTiqqkV ItWoUAzwiBQ0cf1GMPtCKtzf+rfUmXf6OauFsB4vlrtgvfQ1pedz6fnXnR+R39R8Yj9k3X iF5qEjMl/Hh5K+VFVBneeq9was2WQ22h/cjtjPIB//uNmYbHSyz19aEKc3vWWQ== Message-Id: <20260821094748.145394-5-qirui.001@bytedance.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 X-Mailer: git-send-email 2.20.1 To: Date: Fri, 21 Aug 2026 17:47:48 +0800 References: <20260821094748.145394-1-qirui.001@bytedance.com> X-Lms-Return-Path: X-Original-From: Rui Qi Cc: , , , , "Rui Qi" From: "Rui Qi" Subject: [PATCH 4/4] RAS/amd/fmpm: Fix spurious BUG when ERST record enumeration fails In-Reply-To: <20260821094748.145394-1-qirui.001@bytedance.com> Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" When erst_get_record_id_begin() returns an error, get_saved_records() jumps to the out_end label which unconditionally calls erst_get_record_id_end(). This is wrong because: - If erst_disable is true, begin() returns -ENODEV without incrementing the refcount. Then end() hits BUG_ON(erst_disable) and panics. - If mutex_lock_interruptible() is interrupted, begin() returns -EINTR without incrementing the refcount. Then end() decrements refcount below zero, hitting BUG_ON(refcount < 0). The comment in erst_get_record_id_end() explicitly states that it should not be called when erst_get_record_id_begin() failed. Fix by adding a separate out_free label that only does kfree(), skipping the erst_get_record_id_end() call when begin() failed. Fixes: 6f15e617cc99 ("RAS: Introduce a FRU memory poison manager") Signed-off-by: Rui Qi --- drivers/ras/amd/fmpm.c | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/drivers/ras/amd/fmpm.c b/drivers/ras/amd/fmpm.c index 14a103de9d62..22627f6278c0 100644 --- a/drivers/ras/amd/fmpm.c +++ b/drivers/ras/amd/fmpm.c @@ -675,7 +675,7 @@ static int get_saved_records(void) =20 ret =3D erst_get_record_id_begin(&pos); if (ret < 0) - goto out_end; + goto out_free; =20 while (!erst_get_record_id_next(&pos, &record_id)) { if (record_id =3D=3D APEI_ERST_INVALID_RECORD_ID) @@ -716,6 +716,7 @@ static int get_saved_records(void) =20 out_end: erst_get_record_id_end(); +out_free: kfree(old); out: return ret; --=20 2.20.1