Re: [PATCH] cpufreq/amd-pstate: Fix TOCTOU when changing driver mode via sysfs

From: K Prateek Nayak

Date: Thu Oct 01 2026 - 12:19:56 EST


Hello Mario

On 9/22/2026 7:53 AM, Mario Limonciello wrote:
> amd_pstate_update_status() evaluates mode_state_machine[cppc_state]
> [mode_idx] before taking amd_pstate_driver_lock, and then re-evaluates it
> again once the lock is held. cppc_state is global and only stable under
> the lock, so concurrent sysfs writes race:
>
> CPU 0 CPU 1
> ----- -----
> // cppc_state == A, mode == B
> if (mode_state_machine[A][B]) // sees non-NULL
> if (mode_state_machine[A][B])
> guard(&amd_pstate_driver_lock);
> mode_state_machine[A][B](B);
> cppc_state = B;
> guard(&amd_pstate_driver_lock);
> // cppc_state is now B
> mode_state_machine[B][B](B); // NULL -> NULL deref

Oof! Very interesting race that.

>
> The re-read under the lock can resolve to a self-transition (NULL
> pointer, immediate NULL deref) or to an unexpected transition that
> redundantly runs amd_pstate_driver_cleanup(), double-freeing
> current_pstate_driver->attr.
>
> Take the lock first, then read cppc_state and resolve the transition
> function exactly once into a local before calling it, so the check and
> the call observe the same state.
>
> Reported-by: Sashiko <sashiko-bot@xxxxxxxxxx>
> Closes: https://sashiko.dev/#/bug/linux-f86ff3a6-55df-4eef-8e4d-62ac270dba25
> Fixes: 6f0b13f16f7a ("cpufreq/amd-pstate: Overhaul locking")
> Signed-off-by: Mario Limonciello <mario.limonciello@xxxxxxx>

Feel free to include:

Reviewed-by: K Prateek Nayak <kprateek.nayak@xxxxxxx>
Tested-by: K Prateek Nayak <kprateek.nayak@xxxxxxx>

--
Thanks and Regards,
Prateek