diff options
| author | Tejun Heo <tj@kernel.org> | 2026-07-13 22:18:42 -1000 |
|---|---|---|
| committer | Tejun Heo <tj@kernel.org> | 2026-07-13 22:18:42 -1000 |
| commit | 33ffb56e852cdb352d9ffeecfc2c7ffe0945c815 (patch) | |
| tree | 5f9eb7b51851cdabf9891fed0192564fe2a6eed3 /tools/perf/scripts/python/flamegraph.py | |
| parent | cc7c254c8fd71818b4bd2fbf3dddcd2ebc79e678 (diff) | |
sched_ext: Build the set_cmask scratch from trusted geometry
scx_call_op_set_cpumask() builds a per-cpu cmask in the set_cmask scratch,
which lives in BPF-writable arena. A scheduler can corrupt the scratch's
inline header (base, nr_cids, alloc_words) from another cpu, so sizing and
indexing the write from it risks an out-of-bounds write.
Drive the build from kernel-known geometry instead.
scx_cmask_ref_init_kern() imposes base and nr_cids rather than reading them,
and scx_cmask_ref_from_cpumask() fills the scratch from the ref. Neither
reads the header back.
Signed-off-by: Tejun Heo <tj@kernel.org>
Reviewed-by: Andrea Righi <arighi@nvidia.com>
Diffstat (limited to 'tools/perf/scripts/python/flamegraph.py')
0 files changed, 0 insertions, 0 deletions
