From 3a341cb3a2c2879732bc9cf006caa6a087b82241 Mon Sep 17 00:00:00 2001 From: Kaitao Cheng Date: Thu, 18 Jun 2026 19:06:40 +0800 Subject: lib/vsprintf: Make no_hash_pointers take effect early The no_hash_pointers boot parameter is now handled as an alias for hash_pointers=never. However, hash_pointers=never only records the selected mode during early parameter parsing, and no_hash_pointers is not updated until hash_pointers_finalize() runs later from SLUB init. This leaves a window during very early boot where %p output is still hashed even though the user explicitly requested unhashed pointers with no_hash_pointers or hash_pointers=never. Set no_hash_pointers as soon as the "never" mode is parsed. The later hash_pointers_finalize() call still keeps the final policy decision in one place, but explicit requests to disable pointer hashing now take effect for early boot users too. Signed-off-by: Kaitao Cheng Reviewed-by: Petr Mladek Link: https://patch.msgid.link/20260618110640.82749-1-kaitao.cheng@linux.dev Signed-off-by: Petr Mladek --- lib/vsprintf.c | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/lib/vsprintf.c b/lib/vsprintf.c index 2bc6ef483576..e285e8bc4712 100644 --- a/lib/vsprintf.c +++ b/lib/vsprintf.c @@ -2360,6 +2360,9 @@ void __init hash_pointers_finalize(bool slub_debug) static int __init hash_pointers_mode_parse(char *str) { + /* Avoid stale no_hash_pointers state when hash_pointers overrides it */ + no_hash_pointers = false; + if (!str) { pr_warn("Hash pointers mode empty; falling back to auto.\n"); hash_pointers_mode = HASH_PTR_AUTO; @@ -2369,6 +2372,7 @@ static int __init hash_pointers_mode_parse(char *str) } else if (strcmp(str, "never") == 0) { pr_info("Hash pointers mode set to never.\n"); hash_pointers_mode = HASH_PTR_NEVER; + no_hash_pointers = true; } else if (strcmp(str, "always") == 0) { pr_info("Hash pointers mode set to always.\n"); hash_pointers_mode = HASH_PTR_ALWAYS; -- cgit v1.2.3 From 36630cafbeede0b64c370edb2f7b4094327ee1e0 Mon Sep 17 00:00:00 2001 From: John Ogness Date: Fri, 3 Jul 2026 16:20:31 +0206 Subject: printk: Fix possible console use-after-free When emitting a record via legacy printing, it is possible that a handover to another legacy printing context occurs. When a context has performed a handover, the console SRCU read lock is released and the pointer to the console struct might now be invalid. Therefore, after calling nbcon_legacy_emit_next_record() or console_emit_next_record(), it is necessary to check if a handover occurred _before_ further @con usage. Sashiko pointed out that console_flush_one_record() was not doing this. In console_flush_one_record(), after emitting a record, move the further usage of @con after the handover check. Fixes: c158834b223f ("printk: nbcon: Use nbcon consoles in console_flush_all()") Reported-by: Sashiko Closes: https://lore.kernel.org/lkml/20260630170903.099D61F000E9@smtp.kernel.org Signed-off-by: John Ogness Reviewed-by: Petr Mladek Link: https://patch.msgid.link/20260703141521.202813-1-john.ogness@linutronix.de Signed-off-by: Petr Mladek --- kernel/printk/printk.c | 11 +++++++++-- 1 file changed, 9 insertions(+), 2 deletions(-) diff --git a/kernel/printk/printk.c b/kernel/printk/printk.c index 2fe9a963c823..6d363e42e2a0 100644 --- a/kernel/printk/printk.c +++ b/kernel/printk/printk.c @@ -3264,10 +3264,8 @@ static bool console_flush_one_record(bool do_cond_resched, u64 *next_seq, bool * if (flags & CON_NBCON) { progress = nbcon_legacy_emit_next_record(con, handover, cookie, !do_cond_resched); - printk_seq = nbcon_seq_read(con); } else { progress = console_emit_next_record(con, handover, cookie); - printk_seq = con->seq; } /* @@ -3277,6 +3275,15 @@ static bool console_flush_one_record(bool do_cond_resched, u64 *next_seq, bool * if (*handover) goto fail; + /* + * @con can be used here now that it is certain that this + * context is still holding the SRCU read lock. + */ + if (flags & CON_NBCON) + printk_seq = nbcon_seq_read(con); + else + printk_seq = con->seq; + /* Track the next of the highest seq flushed. */ if (printk_seq > *next_seq) *next_seq = printk_seq; -- cgit v1.2.3