Re: [PATCH 3/3] bootconfig: Skip internal tree sanity checks in kernel

From: Sang-Heon Jeon

Date: Thu Sep 10 2026 - 01:31:39 EST


On Thu, Sep 10, 2026 at 12:54 AM Masami Hiramatsu (Google)
<mhiramat@xxxxxxxxxx> wrote:
>
> From: Masami Hiramatsu (Google) <mhiramat@xxxxxxxxxx>
>
> In xbc_verify_tree(), the loop iterating through all nodes to check that
> xbc_nodes[i].next < xbc_node_num and xbc_nodes[i].child < xbc_node_num
> is a defensive sanity check against implementation regressions (such
> an out-of-bounds index cannot be produced by malformed input).
>
> Running this check in the kernel adds unnecessary boot-time overhead.
> Split this check out into xbc_sanity_check_tree() for userspace, so
> that it continues to run during userspace bootconfig validation (e.g.
> when applying or testing bootconfig with tools/bootconfig), but is
> omitted in the kernel to speed up initialization.
>
> Reported-by: Sang-Heon Jeon <ekffu200098@xxxxxxxxx>
> Closes: https://lore.kernel.org/all/20260905141637.1547429-1-ekffu200098@xxxxxxxxx/
> Signed-off-by: Masami Hiramatsu (Google) <mhiramat@xxxxxxxxxx>
> ---
> lib/bootconfig.c | 38 ++++++++++++++++++++++++++------------
> 1 file changed, 26 insertions(+), 12 deletions(-)
>
> diff --git a/lib/bootconfig.c b/lib/bootconfig.c
> index 0ec2874db9c7..884f186b1989 100644
> --- a/lib/bootconfig.c
> +++ b/lib/bootconfig.c
> @@ -1000,9 +1000,30 @@ static int __init xbc_close_brace(char **k, char *n)
> return __xbc_close_brace(n - 1);
> }
>
> +#ifndef __KERNEL__
> +/* Sanity check for regression: node indices must be within bounds */
> +static int __init xbc_sanity_check_tree(void)
> +{
> + int i;
> +
> + for (i = 0; i < xbc_node_num; i++) {
> + if (xbc_nodes[i].next >= xbc_node_num) {
> + return xbc_parse_error("No closing brace",
> + xbc_node_get_data(xbc_nodes + i));
> + }
> + if (xbc_nodes[i].child >= xbc_node_num) {
> + return xbc_parse_error("Broken child node",
> + xbc_node_get_data(xbc_nodes + i));
> + }
> + }
> +
> + return 0;
> +}
> +#endif
> +
> static int __init xbc_verify_tree(void)
> {
> - int i, depth;
> + int depth;
> size_t len, wlen;
> struct xbc_node *n, *m;
>
> @@ -1019,17 +1040,6 @@ static int __init xbc_verify_tree(void)
> return -ENOENT;
> }
>
> - for (i = 0; i < xbc_node_num; i++) {
> - if (xbc_nodes[i].next >= xbc_node_num) {
> - return xbc_parse_error("No closing brace",
> - xbc_node_get_data(xbc_nodes + i));
> - }
> - if (xbc_nodes[i].child >= xbc_node_num) {
> - return xbc_parse_error("Broken child node",
> - xbc_node_get_data(xbc_nodes + i));
> - }
> - }
> -
> /* Key tree limitation check */
> n = &xbc_nodes[0];
> depth = 1;
> @@ -1199,6 +1209,10 @@ int __init xbc_init(const char *data, size_t size, const char **emsg, int *epos)
> ret = xbc_parse_tree();
> if (!ret)
> ret = xbc_verify_tree();
> +#ifndef __KERNEL__
> + if (!ret)
> + ret = xbc_sanity_check_tree();
> +#endif
>
> if (ret < 0) {
> if (epos)
>

Thanks for doing this.

Reviewed-by: Sang-Heon Jeon <ekffu200098@xxxxxxxxx>