Re: [PATCH RESEND v13 01/14] coresight: etm4x: read-back TRCSEQSTR at disabling and prohibit modifying seq_state while enabling.

From: sashiko-bot

Date: Fri Oct 02 2026 - 23:08:18 EST


Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [Medium] coresight: TOCTOU race in seq_state_store bypasses active-session guard
--

commit 750a64ecfab03057a253043e06b3def402bb7137
Author: Yeoreum Yun <yeoreum.yun@xxxxxxx>

coresight: etm4x: read-back TRCSEQSTR at disabling and prohibit modifying seq_state while enabling.

TRCSEQSTR can be changed by the ETM while a session is active. Its value
therefore needs to be preserved when a sysfs session is disabled so that
users can read the current sequence state after the session ends.

> diff --git a/drivers/hwtracing/coresight/coresight-etm4x-sysfs.c b/drivers/hwtracing/coresight/coresight-etm4x-sysfs.c
> --- a/drivers/hwtracing/coresight/coresight-etm4x-sysfs.c
> +++ b/drivers/hwtracing/coresight/coresight-etm4x-sysfs.c
> @@ -1435,6 +1435,8 @@ static ssize_t seq_state_store(struct device *dev,
>
> if (kstrtoul(buf, 16, &val))
> return -EINVAL;
> + if (IS_ERR_OR_NULL(drvdata->csdev) || coresight_get_mode(drvdata->csdev))
> + return -EBUSY;
> if (val >= drvdata->nrseqstate)
> return -EINVAL;
>
> config->seq_state = val;
^^^^^^^^^^^^^^^^^^^^^^^^

[Severity: Medium]
Could this active-session guard be bypassed due to a Time-of-Check to
Time-of-Use race?

If a user-space write to seq_state and an enable_source call occur
concurrently, is it possible for enable_source to succeed immediately
after this mode check passes?

If coresight_take_mode() succeeds in the racing enable_source call, it
would take drvdata->spinlock to copy the configuration for the active
session. This seq_state_store() write would then proceed without a lock,
modifying the configuration after it was already checked.

When the sysfs session is later disabled, wouldn't the old state read
from hardware overwrite the user's new value?

Should raw_spin_lock(&drvdata->spinlock) be taken around this mode check
and the configuration assignment?

--
Sashiko AI review · https://sashiko.dev/#/patchset/20261003-separate_etm_cfg_v2-v13-0-5d8a29aead95@xxxxxxx?part=1